CVE-2014-4955: XSS
Cross-site scripting (XSS) vulnerability in the PMATRIgetRowForList function in libraries/rte/rtelist.lib.php in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted trigger name that is improperly handled on the database triggers page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4955?
CVE-2014-4955 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2014-4955?
To fix CVE-2014-4955, upgrade phpMyAdmin to version 4.0.10.1 or later, 4.1.14.2 or later, or 4.2.6 or later.
Who is affected by CVE-2014-4955?
Remote authenticated users of phpMyAdmin versions prior to 4.0.10.1, 4.1.14.2, and 4.2.6 are affected by CVE-2014-4955.
What can attackers do with CVE-2014-4955?
Attackers can exploit CVE-2014-4955 to inject arbitrary web scripts or HTML into the phpMyAdmin interface.
When was CVE-2014-4955 disclosed?
CVE-2014-4955 was disclosed in August 2014.