Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

openSUSE: 2025:0081-1 important: phpMyAdmin XSS and update

opensuse
Calendar Grey March 3, 2025
Dist Opensuse Esm H88
This maintenance patch for Fedora tackles severe PostgreSQL vulnerabilities with necessary corrections. Discover the details today!
An update that fixes four vulnerabilities is now available

Description

This update for phpMyAdmin fixes the following issues:

Update to version 5.2.2:

- CVE-2025-24530: XSS in the "Check Tables" feature (bsc#1236312).

- CVE-2025-24529: XSS in the "Insert" tab (bsc#1236311).

- CVE-2024-2961: glibc/iconv: out-of-bounds writes when writing escape

sequences (bsc#1222992).

- CVE-2023-30536: slim/psr7: improper header validation (bsc#1238159).

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP6:

zypper in -t patch openSUSE-2025-81=1

Package List

- openSUSE Backports SLE-15-SP6 (noarch):

phpMyAdmin-5.2.2-bp156.4.3.1

phpMyAdmin-apache-5.2.2-bp156.4.3.1

phpMyAdmin-lang-5.2.2-bp156.4.3.1

References

https://www.suse.com/security/cve/CVE-2023-30536.html

https://www.suse.com/security/cve/CVE-2024-2961.html

https://www.suse.com/security/cve/CVE-2025-24529.html

https://www.suse.com/security/cve/CVE-2025-24530.html

https://bugzilla.suse.com/1222992

https://bugzilla.suse.com/1236311

https://bugzilla.suse.com/1236312

https://bugzilla.suse.com/1238159

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2025:0081-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP6 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here