Candidate: CVE-2018-12581 PublicDate: 2018-06-21 20:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12581 https://www.phpmyadmin.net/security/PMASA-2018-3/ Description: An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature. Ubuntu-Description: It was discovered phpmyadmin incorrectly handled database names. An attacker could possibly use this to trigger an XSS attack. Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_phpmyadmin: upstream: https://github.com/phpmyadmin/phpmyadmin/commit/6943fff87324bd54c3a37a5160a5fb77498c355e upstream_phpmyadmin: released (4.8.2, 4:4.9.1+dfsg1-2) precise/esm_phpmyadmin: DNE trusty_phpmyadmin: not-affected (code not present) trusty/esm_phpmyadmin: not-affected (code not present) xenial_phpmyadmin: ignored (end of standard support, was needed) artful_phpmyadmin: ignored (reached end-of-life) bionic_phpmyadmin: needed cosmic_phpmyadmin: ignored (reached end-of-life) disco_phpmyadmin: ignored (reached end-of-life) eoan_phpmyadmin: DNE focal_phpmyadmin: not-affected (4:4.9.2+dfsg1-1) groovy_phpmyadmin: not-affected (4:4.9.2+dfsg1-1) hirsute_phpmyadmin: not-affected (4:4.9.2+dfsg1-1) impish_phpmyadmin: not-affected (4:4.9.2+dfsg1-1) jammy_phpmyadmin: not-affected (4:4.9.2+dfsg1-1) devel_phpmyadmin: not-affected (4:4.9.2+dfsg1-1)