-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The commit diff shows the vulnerability was patched by adding encodeURI() to the 'db' parameter in the URL construction within move.js. The original code in Load_page dynamically built a link without proper escaping, making it susceptible to XSS when a malicious database name is injected. The explicit addition of URI encoding in the fix confirms this was the vulnerable point.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| phpmyadmin/phpmyadmin | composer | < 4.8.2 | 4.8.2 |
Ongoing coverage of React2Shell