This update for phpMyAdmin fixes the following issues:
Update to version 5.2.2:
- CVE-2025-24530: XSS in the "Check Tables" feature (bsc#1236312).
- CVE-2025-24529: XSS in the "Insert" tab (bsc#1236311).
- CVE-2024-2961: glibc/iconv: out-of-bounds writes when writing escape
sequences (bsc#1222992).
- CVE-2023-30536: slim/psr7: improper header validation (bsc#1238159).
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP6:
zypper in -t patch openSUSE-2025-81=1
- openSUSE Backports SLE-15-SP6 (noarch):
phpMyAdmin-5.2.2-bp156.4.3.1
phpMyAdmin-apache-5.2.2-bp156.4.3.1
phpMyAdmin-lang-5.2.2-bp156.4.3.1
https://www.suse.com/security/cve/CVE-2023-30536.html
https://www.suse.com/security/cve/CVE-2024-2961.html
https://www.suse.com/security/cve/CVE-2025-24529.html
https://www.suse.com/security/cve/CVE-2025-24530.html
https://bugzilla.suse.com/1222992
https://bugzilla.suse.com/1236311
https://bugzilla.suse.com/1236312
https://bugzilla.suse.com/1238159
Get the latest Linux and open source security news straight to your inbox.