{"id":"GHSA-6q2j-8h8q-46mr","summary":"phpMyAdmin vulnerable to Cross-site Scripting","details":"Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) server-privileges certificate data fields on the user privileges page, (2) an \"invalid JSON\" error message in the error console, (3) a database name in the central columns implementation, (4) a group name, or (5) a search name in the bookmarks implementation.","aliases":["CVE-2016-5705"],"modified":"2025-04-14T22:13:25.504173Z","published":"2022-05-14T02:08:58Z","database_specific":{"github_reviewed_at":"2025-04-14T21:32:57Z","nvd_published_at":"2016-07-03T01:59:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-5705"},{"type":"WEB","url":"https://github.com/phpmyadmin/phpmyadmin/commit/03f73d48369703e0d3584699b08e24891c3295b8"},{"type":"WEB","url":"https://github.com/phpmyadmin/phpmyadmin/commit/0b7416c5f4439ed3f11c023785f2d4c49a1b09fc"},{"type":"WEB","url":"https://github.com/phpmyadmin/phpmyadmin/commit/364732e309cccb3fb56c938ed8d8bc0e04a3ca98"},{"type":"WEB","url":"https://github.com/phpmyadmin/phpmyadmin/commit/36df83a97a7f140fdb008b727a94f882847c6a6f"},{"type":"WEB","url":"https://github.com/phpmyadmin/phpmyadmin/commit/57ae483bad33059a885366d5445b7e1f6f29860a"},{"type":"PACKAGE","url":"https://github.com/phpmyadmin/phpmyadmin"},{"type":"WEB","url":"https://security.gentoo.org/glsa/201701-32"},{"type":"WEB","url":"https://web.archive.org/web/20200227223416/http://www.securityfocus.com/bid/91378"},{"type":"WEB","url":"https://www.phpmyadmin.net/security/PMASA-2016-21"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-updates/2016-06/msg00113.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-updates/2016-06/msg00114.html"},{"type":"WEB","url":"http://www.debian.org/security/2016/dsa-3627"}],"affected":[{"package":{"name":"phpmyadmin/phpmyadmin","ecosystem":"Packagist","purl":"pkg:composer/phpmyadmin/phpmyadmin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.4.0"},{"fixed":"4.4.15.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-6q2j-8h8q-46mr/GHSA-6q2j-8h8q-46mr.json"}},{"package":{"name":"phpmyadmin/phpmyadmin","ecosystem":"Packagist","purl":"pkg:composer/phpmyadmin/phpmyadmin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.6.0"},{"fixed":"4.6.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-6q2j-8h8q-46mr/GHSA-6q2j-8h8q-46mr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}