CVE-2025-2946: Cross-Site Vulnerability(XSS) due to arbitrary HTML/JavaScript gets executed while query result rendering in Query Tool and View/Edit Data Tool of pgAdmin 4
Published Apr 3, 2025
·Updated
pgAdmin <= 9.1 is affected by a security vulnerability with Cross-Site Scripting(XSS). If attackers execute any arbitrary HTML/JavaScript in a user's browser through query result rendering, then HTML/JavaScript runs on the browser.
Affected Software
3 affected componentsFixes available
PostgreSQL pgAdmin 4<=9.1
pip/pgadmin4<9.2
9.2
pgAdmin Pgadmin 4 Postgresql<=9.1
Event History
Apr 3, 2025
CVE Published
via MITRE·12:23 PM
Data Sourced
via MITRE·12:23 PM
DescriptionSeverity
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
Affected Software
Advisory Published
via GitHub·03:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-2946?
CVE-2025-2946 is categorized as a medium severity vulnerability due to its potential for Cross-Site Scripting attacks.
2
Who is affected by CVE-2025-2946?
CVE-2025-2946 affects users of pgAdmin versions up to and including 9.1.
3
How do I fix CVE-2025-2946?
To fix CVE-2025-2946, upgrade pgAdmin to a version later than 9.1 where the vulnerability is addressed.
4
What types of attacks are possible with CVE-2025-2946?
CVE-2025-2946 allows attackers to execute arbitrary HTML and JavaScript in a user's browser through XSS.
5
What is the impact of CVE-2025-2946?
The impact of CVE-2025-2946 includes potential data theft, session hijacking, and manipulation of the user's session.