Description
pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1871 | pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload |
Github GHSA |
GHSA-xv64-8p4r-94gq | pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload |
References
History
Fri, 19 Sep 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fedoraproject
Fedoraproject fedora Pgadmin Pgadmin pgadmin 4 |
|
| CPEs | cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:* cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fedoraproject
Fedoraproject fedora Pgadmin Pgadmin pgadmin 4 |
Thu, 13 Feb 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end. | pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end. |
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2025-02-13T17:53:31.153Z
Reserved: 2024-04-25T20:53:44.444Z
Link: CVE-2024-4216
Updated: 2024-08-01T20:33:52.902Z
Status : Analyzed
Published: 2024-05-02T18:15:07.757
Modified: 2025-09-19T13:27:28.723
Link: CVE-2024-4216
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA