CVE-2014-4349: XSS
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name that is improperly handled after a (1) hide or (2) unhide action.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4349?
CVE-2014-4349 is classified as a moderate severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2014-4349?
To fix CVE-2014-4349, upgrade to phpMyAdmin version 4.1.14.1 or 4.2.4 or later.
Which versions of phpMyAdmin are affected by CVE-2014-4349?
CVE-2014-4349 affects phpMyAdmin versions 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4.
What types of attacks can exploit CVE-2014-4349?
CVE-2014-4349 can be exploited for cross-site scripting (XSS) attacks, allowing the injection of arbitrary web scripts or HTML.
Who is at risk from CVE-2014-4349?
Remote authenticated users of vulnerable phpMyAdmin versions are at risk from CVE-2014-4349.