First published: Tue Dec 11 2018(Updated: )
In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyAdmin phpMyAdmin | >=4.0.0<4.8.4 | |
Debian Debian Linux | =8.0 | |
composer/phpmyadmin/phpmyadmin | >=4.0<4.8.4 | 4.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19970 is an XSS vulnerability in phpMyAdmin before version 4.8.4 that allows an attacker to deliver a payload through a crafted database/table name.
CVE-2018-19970 has a severity rating of 6.1 (medium).
phpMyAdmin versions between 4.0.0 and 4.8.4, as well as Debian Linux version 8.0, are affected by CVE-2018-19970.
To fix CVE-2018-19970, update phpMyAdmin to version 4.8.4 or later.
For more information about CVE-2018-19970, you can refer to the following references: [SecurityFocus](http://www.securityfocus.com/bid/106181), [Debian LTS Announce](https://lists.debian.org/debian-lts-announce/2019/02/msg00003.html), [Gentoo GLSA](https://security.gentoo.org/glsa/201904-16).