|
|
Subscribe / Log in / New account

Arch Linux alert ASA-201802-11 (phpmyadmin)

From:  Levente Polyak <anthraxx@archlinux.org>
To:  arch-security@archlinux.org
Subject:  [ASA-201802-11] phpmyadmin: cross-site scripting
Date:  Sat, 24 Feb 2018 01:44:25 +0100
Message-ID:  <bf8e9942-aa61-d5ce-2d5b-ddf70b301134@archlinux.org>

Arch Linux Security Advisory ASA-201802-11 ========================================== Severity: Medium Date : 2018-02-23 CVE-ID : CVE-2018-7260 Package : phpmyadmin Type : cross-site scripting Remote : Yes Link : https://security.archlinux.org/AVG-630 Summary ======= The package phpmyadmin before version 4.7.8-1 is vulnerable to cross- site scripting. Resolution ========== Upgrade to 4.7.8-1. # pacman -Syu "phpmyadmin>=4.7.8-1" The problem has been fixed upstream in version 4.7.8. Workaround ========== None. Description =========== Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. Impact ====== A remote authenticated attacker is able to inject arbitrary javascript via a crafted URL. References ========== https://udiniya.wordpress.com/2018/02/21/a-tale-of-steali... https://www.phpmyadmin.net/security/PMASA-2018-1/ https://github.com/phpmyadmin/phpmyadmin/commit/d2886a3e8... https://security.archlinux.org/CVE-2018-7260


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds