XSS on a Designer component
A logged-in user can be subject of cross site scripting attack via the pmd_pdf.php script.
We consider this vulnerability to be serious.
For 2.11.x: versions before 18.104.22.168.
For 3.0.x: versions before 22.214.171.124.
Upgrade to phpMyAdmin 126.96.36.199 or 188.8.131.52.
Assigned CVE ids: CVE-2008-4775
The following commits have been made to fix this issue:
The following commits have been made on the 2.11 branch to fix this issue:
For further information and in case of questions, please contact the phpMyAdmin team. Our website is phpmyadmin.net.