GHSA-g6xh-wrpf-v6j6

Suggest an improvement
Source
https://github.com/advisories/GHSA-g6xh-wrpf-v6j6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-g6xh-wrpf-v6j6/GHSA-g6xh-wrpf-v6j6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g6xh-wrpf-v6j6
Aliases
  • CVE-2025-60798
Published
2025-11-20T15:30:24Z
Modified
2025-11-21T19:15:52Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
phppgadmin contains a SQL injection vulnerability
Details

phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes user-controlled input from $_REQUEST['query'] directly to the browseQuery function without proper sanitization. An authenticated attacker can exploit this vulnerability to execute arbitrary SQL commands through malicious query manipulation, potentially leading to complete database compromise.

Database specific
{
    "github_reviewed_at": "2025-11-21T18:07:13Z",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-89"
    ],
    "nvd_published_at": "2025-11-20T15:17:38Z",
    "severity": "MODERATE"
}
References

Affected packages

Packagist / phppgadmin/phppgadmin

Package

Name
phppgadmin/phppgadmin
Purl
pkg:composer/phppgadmin/phppgadmin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
7.13.0