CVE-2023-25727

unknown
Published 2023-02-13 · Modified 2025-03-21
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v2
VIR risk

Description

In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2023-25727

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed4:5.2.1+dfsg-1
debian debianbullseyefixed4:5.0.4+dfsg2-2+deb11u2
debian debiansidfixed4:5.2.1+dfsg-1
debian debiantrixiefixed4:5.2.1+dfsg-1

Package impact

EcosystemPackageVulnerableFixed
php Packagistphpmyadmin/phpmyadmin>=4.3.0,<4.9.114.9.11
php Packagistphpmyadmin/phpmyadmin>=5.0,<5.2.15.2.1

References

Verify integrity in audit chain (admin only). AS-IS.