A Cross-Site Scripting vulnerability was found in the file import feature, where an attacker can deliver a payload to a user through importing a specially-crafted file. phpMyAdmin versions prior to 4.8.3 are affected. Upstream patch: https://github.com/phpmyadmin/phpmyadmin/commit/00d90b3ae415b31338f76263359467a9fbebd0a1 References: https://www.phpmyadmin.net/security/PMASA-2018-5/
From what I can see, 4.4.15.10 (in EPEL 7) should be not affected. Could you please verify that?
Sorry, I cannot confirm that. The advisory claims all versions prior to 4.8.3. Please confirm with upstream if they can find the introducing commit.