A Cross-Site Scripting vulnerability was found in the file import feature, where an attacker can deliver a payload to a user through importing a specially-crafted file. phpMyAdmin versions prior to 4.8.3 are affected.
From what I can see, 220.127.116.11 (in EPEL 7) should be not affected. Could you
please verify that?
Sorry, I cannot confirm that.
The advisory claims all versions prior to 4.8.3. Please confirm with upstream if they can find the introducing commit.