Description
In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.
Remediation
References
Related Vulnerabilities
Ruby Improper Input Validation Vulnerability (CVE-2011-4815)
WordPress Plugin Code Insert Manager (Q2W3 Inc Manager) ZeroClipboard Cross-Site Scripting (2.3.1)
WordPress Plugin WordPress Appointment Schedule Booking System Cross-Site Scripting (1.0)
WordPress Plugin FV Flowplayer Video Player Cross-Site Scripting (7.5.18.727)