Description
Cross-site scripting (XSS) vulnerability in the SQL editor in phpMyAdmin 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a SQL query that triggers JSON data in a response.
Remediation
References
Related Vulnerabilities
Drupal Core Security Bypass (8.0.0 - 9.1.15)
WordPress Plugin YITH WooCommerce Ajax Search Security Bypass (1.6.9)
Apache Tomcat Improper Locking Vulnerability (CVE-2019-10072)
WordPress Plugin SEO Redirection-301 Redirect Manager Cross-Site Scripting (6.3)
Serendipity URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-5474)