Description
In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.
Remediation
References
Related Vulnerabilities
IBM WebSEAL Improper Input Validation Vulnerability (CVE-2019-4036)
WordPress Plugin WP People 'wp-people-popup.php' SQL Injection (2.0)
WordPress Plugin GiveWP-Donation and Fundraising Platform Cross-Site Scripting (2.3.0)
WordPress Plugin Cart66 Lite::WordPress Ecommerce Multiple Vulnerabilities (1.5.3)