CVE-2011-4107

MEDIUM6.5EPSS 12.4%

phpMyAdmin vulnerable to XML external entity (XXE) injection attack

Published: 5/17/2022Modified: 5/7/2026
Also known as:GHSA-q4mm-89q2-xffgDEBIAN-CVE-2011-4107

Description

The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7.1 and 3.3.x before 3.3.10.5 allows remote authenticated users to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

References (19)