CVE-2018-19970: XSS
In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-19970?
CVE-2018-19970 is an XSS vulnerability in phpMyAdmin before version 4.8.4 that allows an attacker to deliver a payload through a crafted database/table name.
How severe is CVE-2018-19970?
CVE-2018-19970 has a severity rating of 6.1 (medium).
What software versions are affected by CVE-2018-19970?
phpMyAdmin versions between 4.0.0 and 4.8.4, as well as Debian Linux version 8.0, are affected by CVE-2018-19970.
How can I fix CVE-2018-19970?
To fix CVE-2018-19970, update phpMyAdmin to version 4.8.4 or later.
Where can I find more information about CVE-2018-19970?
For more information about CVE-2018-19970, you can refer to the following references: [SecurityFocus](http://www.securityfocus.com/bid/106181), [Debian LTS Announce](https://lists.debian.org/debian-lts-announce/2019/02/msg00003.html), [Gentoo GLSA](https://security.gentoo.org/glsa/201904-16).