PT-2025-47581 · Unknown · Phppgadmin

CVE-2025-60796

·

Published

2025-11-17

·

Updated

2025-11-21

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions phpPgAdmin versions prior to 7.13.0
Description The software contains multiple cross-site scripting (XSS) issues across various components. User-supplied input from $ REQUEST parameters is reflected in HTML output without proper encoding or sanitization. Specifically, the issue is present in files including sequences.php, indexes.php, and admin.php. An attacker can exploit these issues to execute arbitrary JavaScript in a victim’s browser, potentially leading to session hijacking or credential theft.
Recommendations Update to a version newer than 7.13.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14877
CVE-2025-60796
GHSA-H369-CPJJ-QFFF

Affected Products

Phppgadmin