CVE-2025-24530: XSS
Published Jan 23, 2025
·Updated
An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the check tables feature. A crafted table or database name could be used for XSS.
Affected Software
2 affected componentsFixes available
composer/phpmyadmin/phpmyadmin>=5.0.0<5.2.2
5.2.2
phpMyAdmin phpMyAdmin<5.2.2
Event History
Jan 23, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:31 AM
Data Sourced
via GitHub·06:31 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-24530?
CVE-2025-24530 is classified as a high-severity XSS vulnerability.
2
How do I fix CVE-2025-24530?
To fix CVE-2025-24530, upgrade to phpMyAdmin version 5.2.2 or later.
3
What systems are affected by CVE-2025-24530?
CVE-2025-24530 affects phpMyAdmin versions prior to 5.2.2.
4
What kind of attack can occur due to CVE-2025-24530?
CVE-2025-24530 allows attackers to perform cross-site scripting (XSS) through crafted table or database names.
5
Is there a workaround for CVE-2025-24530?
There are no official workarounds for CVE-2025-24530; updating is the recommended action.