Upstream information
Description
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.4, 4.1.x before 4.1.14.5, and 4.2.x before 4.2.9.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted ENUM value that is improperly handled during rendering of the (1) table search or (2) table structure page, related to libraries/TableSearch.class.php and libraries/Util.class.php.SUSE information
Overall state of this security issue: Does not affect SUSE products
This issue is currently not rated by SUSE as it is not affecting the SUSE Enterprise products.
| CVSS detail | National Vulnerability Database | 
|---|---|
| Base Score | 3.5 | 
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N | 
| Access Vector | Network | 
| Access Complexity | Medium | 
| Authentication | Single | 
| Confidentiality Impact | None | 
| Integrity Impact | Partial | 
| Availability Impact | None | 
SUSE Security Advisories:
- openSUSE-SU-2014:1280-1
List of released packages
| Product(s) | Fixed package version(s) | References | 
|---|---|---|
| openSUSE Tumbleweed | 
 | Patchnames: openSUSE-Tumbleweed-2024-10054 | 
SUSE Timeline for this CVE
CVE page created: Thu Oct 2 02:16:40 2014CVE page last modified: Mon Oct 6 18:21:20 2025
