In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.
{ "binaries": [ { "binary_version": "4:4.0.10-1ubuntu0.1+esm4", "binary_name": "phpmyadmin" } ] }
{ "binaries": [ { "binary_version": "4:4.5.4.1-2ubuntu2.1+esm6", "binary_name": "phpmyadmin" } ] }
{ "binaries": [ { "binary_version": "4:4.6.6-5ubuntu0.5+esm1", "binary_name": "phpmyadmin" } ] }
{ "binaries": [ { "binary_version": "4:4.9.5+dfsg1-2ubuntu0.1~esm1", "binary_name": "phpmyadmin" } ] }
{ "binaries": [ { "binary_version": "4:5.1.1+dfsg1-5ubuntu1", "binary_name": "phpmyadmin" } ] }
{ "binaries": [ { "binary_version": "4:5.2.1+dfsg-3", "binary_name": "phpmyadmin" } ] }
{ "binaries": [ { "binary_version": "4:5.2.2-really5.2.2+20250121+dfsg-1", "binary_name": "phpmyadmin" } ] }