ALT-PU-2018-1972-1
Package phpMyAdmin updated to version 4.8.2-alt0.M80P.1 for branch p8 in task 207257.
Closed vulnerabilities
Published: 2018-06-21
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2018-12581
An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature.
Severity: MEDIUM (6.1)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References: