A moderate severity Cross-Site Scripting (XSS) vulnerability has been identified in phpMyAdmin , a widely used open-source tool for managing MySQL databases .
See also: QNAP patches six Rsync vulnerabilities in NAS app

This flaw, tracked as CVE-2025-24530, affects 5.x versions prior to 5.2.2 and is linked to the “Check tables” feature.
The vulnerability allows malicious users to exploit poorly sanitized table or database names to execute malicious JavaScript in the victim's browser. The issue arises from incomplete input validation in the "Check tables" function of phpMyAdmin.
By creating a malicious table or database, an attacker can inject JavaScript code that executes when a user interacts with the affected feature.
See also: Cisco fixes critical vulnerability in Meeting Management
This XSS attack could lead to unauthorized actions, session hijacking, or data theft, compromising the integrity and confidentiality of the database.

The issue concerns improper input neutralization during web page generation. The flaw has been rated as moderately severe due to the potential impact on security and user accounts.
While the exploit requires some level of user interaction (e.g. accessing the “Check tables” function), the attack can be executed remotely. This makes it particularly dangerous for publicly accessible phpMyAdmin installations.
The phpMyAdmin team has credited “bluebird” for reporting this vulnerability and has provided detailed instructions on how to apply the patch. This vulnerability affects all phpMyAdmin versions in the 5.x series prior to 5.2.2. Users running these versions are advised to update immediately.
See also: OpenVPN Easy-RSA vulnerability enables Bruteforce
Cross-Site Scripting (XSS) attacks are a type of web security vulnerability where malicious code is executed within another website. This occurs when an attacker injects malicious JavaScript or other script into a vulnerable application, which is executed by the victim's browser. This can lead to cookie theft, login information interception, changing the content of the website, or even installing malware. XSS attacks are divided into three main types: stored, reflected, and DOM-based, with each type exploiting different vulnerabilities in an application. To avoid them, it is critical to implement best practices such as avoiding raw user input and using mechanisms such as content security policies (CSP).
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
