Description
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name that is improperly handled after presence in (a) the favorite list or (b) recent tables.
Remediation
References
Related Vulnerabilities
Atlassian Jira Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-39127)
Ruby Improper Input Validation Vulnerability (CVE-2015-7551)
Drupal Improper Access Control Vulnerability (CVE-2020-13677)
WordPress Plugin Custom Add User Cross-Site Scripting (2.0.2)
Oracle Database Server CVE-2011-0799 Vulnerability (CVE-2011-0799)