First published: Wed Feb 21 2018(Updated: )
Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyAdmin phpMyAdmin | <4.7.8 | |
composer/phpmyadmin/phpmyadmin | <4.7.8 | 4.7.8 |
<4.7.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7260 is a cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before version 4.7.8.
CVE-2018-7260 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVE-2018-7260 has a severity value of 5.4, which is considered medium.
To fix CVE-2018-7260, you should update phpMyAdmin to version 4.7.8 or later.
Yes, you can refer to the following links for more information: [1] http://www.securityfocus.com/bid/103099 [2] https://github.com/phpmyadmin/phpmyadmin/commit/d2886a3 [3] https://udiniya.wordpress.com/2018/02/21/a-tale-of-stealing-session-cookie-in-phpmyadmin/