In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.
| Software | From | Fixed in |
|---|---|---|
phpmyadmin / phpmyadmin
|
- | 4.9.11 |
phpmyadmin / phpmyadmin
|
5.0.0 | 5.2.1 |
phpmyadmin / phpmyadmin
|
4.3.0 | 4.9.11 |
phpmyadmin / phpmyadmin
|
5.0 | 5.2.1 |