Description
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name that is improperly handled after presence in (a) the favorite list or (b) recent tables.
Remediation
References
Related Vulnerabilities
Drupal Core 5.x HTTP Response Splitting (5.0 - 5.2)
WordPress Plugin Fancy Product Designer-WooCommerce SQL Injection (4.7.4)
WordPress Plugin Oi Yandex.Maps for WordPress Cross-Site Scripting (3.2.7)
WordPress Plugin All in One Webmaster Cross-Site Request Forgery (8.2.3)
Microsoft SQL Server CVE-2023-32025 Vulnerability (CVE-2023-32025)