GHSA-5pmg-qh2c-7j24

Suggest an improvement
Source
https://github.com/advisories/GHSA-5pmg-qh2c-7j24
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5pmg-qh2c-7j24/GHSA-5pmg-qh2c-7j24.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5pmg-qh2c-7j24
Aliases
Published
2022-05-17T03:25:30Z
Modified
2025-04-14T20:12:17.813675Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
phpMyAdmin allows remote attackers to spoof content via the url parameter
Details

The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.

Database specific
{
    "nvd_published_at": "2015-10-28T10:59:00Z",
    "cwe_ids": [
        "CWE-20",
        "CWE-79"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2025-04-14T19:47:12Z"
}
References

Affected packages

Packagist / phpmyadmin/phpmyadmin

Package

Name
phpmyadmin/phpmyadmin
Purl
pkg:composer/phpmyadmin/phpmyadmin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.4.0
Fixed
4.4.15.1

Packagist / phpmyadmin/phpmyadmin

Package

Name
phpmyadmin/phpmyadmin
Purl
pkg:composer/phpmyadmin/phpmyadmin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.5.0
Fixed
4.5.1