CVE-2018-15605
openSUSE Security Advisory - openSUSE-SU-2018:2525-2
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to manipulate an authenticated user who loads that file through the import feature.
Se ha descubierto un problema en versiones anteriores a la 4.8.3 de phpMyAdmin. Se ha encontrado una vulnerabilidad de Cross-Site Scripting (XSS) en la que un atacante puede emplear un archivo manipulado para manipular un usuario autenticado que cargue ese archivo mediante la característica de importación.
An update that fixes one vulnerability is now available. This update for phpMyAdmin to version 4.8.3 addresses multiple issues. Vulnerability in the file import feature allowed cross-site scripting via importing a specially-crafted file This update also contains a number of upstream bug fixes in the UI and behavior.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-08-21 CVE Reserved
- 2018-08-24 CVE Published
- 2024-08-05 CVE Updated
- 2025-06-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/105168 | Third Party Advisory | |
http://www.securitytracker.com/id/1041548 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/phpmyadmin/phpmyadmin/commit/00d90b3ae415b31338f76263359467a9fbebd0a1 | 2018-10-26 | |
https://www.phpmyadmin.net/security/PMASA-2018-5 | 2018-10-26 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Phpmyadmin Search vendor "Phpmyadmin" | Phpmyadmin Search vendor "Phpmyadmin" for product "Phpmyadmin" | < 4.8.3 Search vendor "Phpmyadmin" for product "Phpmyadmin" and version " < 4.8.3" | - |
Affected
|