{"id":"GHSA-p632-5w74-x8xx","summary":"phpMyAdmin Cross-site scripting (XSS) vulnerability via pageNumber value ","details":"Cross-site scripting (XSS) vulnerability in `libraries/schema/Export_Relation_Schema.class.php` in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted pageNumber value to schema_export.php.","aliases":["CVE-2013-5002"],"modified":"2024-12-06T05:40:26.934081Z","published":"2022-05-17T03:12:55Z","database_specific":{"nvd_published_at":"2013-07-31T13:20:00Z","cwe_ids":["CWE-79"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2023-08-29T18:15:52Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-5002"},{"type":"WEB","url":"http://www.phpmyadmin.net/home_page/security/PMASA-2013-14.php"}],"affected":[{"package":{"name":"phpmyadmin/phpmyadmin","ecosystem":"Packagist","purl":"pkg:composer/phpmyadmin/phpmyadmin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.5"},{"fixed":"3.5.8.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-p632-5w74-x8xx/GHSA-p632-5w74-x8xx.json"}},{"package":{"name":"phpmyadmin/phpmyadmin","ecosystem":"Packagist","purl":"pkg:composer/phpmyadmin/phpmyadmin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0"},{"fixed":"4.0.4.2"}]}],"versions":["4.0.0","4.0.1","4.0.2","4.0.3","4.0.4","4.0.4.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-p632-5w74-x8xx/GHSA-p632-5w74-x8xx.json"}}],"schema_version":"1.9.0"}