CVE-2022-23808

medium

Description

An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

References

https://www.phpmyadmin.net/security/PMASA-2022-2/

https://security.gentoo.org/glsa/202311-17

https://infosecwriteups.com/exploit-cve-2022-23808-85041c6e5b97

Details

Source: Mitre, NVD

Published: 2022-01-22

Updated: 2023-11-26

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Severity: Medium