ALT-PU-2023-1600-2
Package phpMyAdmin updated to version 5.2.1-alt1 for branch p10 in task 318182.
Closed vulnerabilities
Modified: 2024-09-03
BDU:2023-07577
Уязвимость веб-приложения для администрирования cистем управления базами данных phpMyAdmin, существующая из-за непринятия мер по защите структуры веб-страницы, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)
Modified: 2025-04-01
CVE-2020-22452
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.
- http://phpmyadmin.com
- https://github.com/phpmyadmin/phpmyadmin/blob/master/ChangeLog
- https://github.com/phpmyadmin/phpmyadmin/issues/15898
- https://github.com/phpmyadmin/phpmyadmin/pull/16004
- http://phpmyadmin.com
- https://github.com/phpmyadmin/phpmyadmin/blob/master/ChangeLog
- https://github.com/phpmyadmin/phpmyadmin/issues/15898
- https://github.com/phpmyadmin/phpmyadmin/pull/16004
Modified: 2025-11-03
CVE-2023-25727
In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.
Modified: 2025-03-21
GHSA-6hr3-44gx-g6wh
Cross-site Scripting vulnerability in drag-and-drop upload of phpMyAdmin
- https://nvd.nist.gov/vuln/detail/CVE-2023-25727
- https://github.com/phpmyadmin/phpmyadmin/commit/53f70fd7f3b388639922e6cc1ca51fbe890c91cc
- https://github.com/phpmyadmin/phpmyadmin/commit/efa2406695551667f726497750d3db91fb6f662e
- https://github.com/phpmyadmin/composer
- https://www.phpmyadmin.net/security/PMASA-2023-1
Modified: 2023-02-03
GHSA-prcg-mc23-hgjh
phpmyadmin contains SQL Injection vulnerability
