Description
Cross-site scripting (XSS) vulnerability in the format function in libraries/sql-parser/src/Utils/Error.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted query.
Remediation
References
Related Vulnerabilities
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-1692)
WordPress Plugin Booking calendar, Appointment Booking System Security Bypass (2.2.2)
WordPress Plugin WP-UserOnline URL HTML Injection (2.62)
Oracle Database Server CVE-2015-4873 Vulnerability (CVE-2015-4873)
WordPress Plugin Video Lead Form 'errMsg' Parameter Cross-Site Scripting (0.5)