Bug 1594407 (CVE-2018-12581)

Summary: CVE-2018-12581 phpMyAdmin: XSS when the database is referenced from the Designer feature
Product: [Other] Security Response Reporter: Laura Pardo <lpardo>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED UPSTREAM QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: fedora, imlinux+fedora, lpardo, redhat-bugzilla
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: phpMyAdmin 4.8.2 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-10 10:29:57 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1594416, 1594417    
Bug Blocks:    

Description Laura Pardo 2018-06-22 21:05:53 UTC
An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted database name to trigger an XSS attack when that database is referenced from the Designer feature.


References:
https://www.phpmyadmin.net/security/PMASA-2018-3/

Comment 1 Laura Pardo 2018-06-22 21:32:30 UTC
Created phpMyAdmin tracking bugs for this issue:

Affects: epel-all [bug 1594417]
Affects: fedora-all [bug 1594416]

Comment 2 Robert Scheck 2018-06-22 22:34:20 UTC
Laura, can you see if this really affects phpMyAdmin 4.0.10.20 and 4.4.15.10
as shipped by EPEL 6 and 7?

Comment 3 Laura Pardo 2018-06-25 13:19:00 UTC
Hi Robert,

The affected code was introduced in this commit:
https://github.com/phpmyadmin/phpmyadmin/commit/f4026f60a4b557cbcc61e11f26167a2759ad94af

Therefore versions shipped in EPEL are not affected

Comment 4 Fedora Update System 2018-07-01 22:34:51 UTC
phpMyAdmin-4.8.2-1.fc28 has been pushed to the Fedora 28 stable repository. If problems still persist, please make note of it in this bug report.

Comment 5 Product Security DevOps Team 2019-06-10 10:29:57 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.