PatchSiren cyber security CVE debrief
CVE-2023-25727 Festo Didactic SE CVE debrief
CVE-2023-25727 is an authenticated cross-site scripting issue in phpMyAdmin’s drag-and-drop import flow. In the supplied advisory corpus, the CVE is associated with Festo Didactic SE MES PC deployments and a vendor replacement path for the affected XAMPP-based component. Organizations should treat this as a browser-side injection risk that can affect logged-in users who handle imports or administration tasks.
- Vendor
- Festo Didactic SE
- Product
- MES PC
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-02-27
- Original CVE updated
- 2026-01-27
- Advisory published
- 2024-02-27
- Advisory updated
- 2026-01-27
Who should care
Administrators and operators of Festo Didactic SE MES PC environments, especially where phpMyAdmin or a bundled XAMPP-based workflow is exposed to authenticated users. Security teams should also review any environment where users can upload .sql files through a drag-and-drop import interface.
Technical summary
The source description states that phpMyAdmin before 4.9.11 and 5.x before 5.2.1 allows an authenticated user to trigger XSS by uploading a crafted .sql file through the drag-and-drop interface. The supplied CSAF advisory links this CVE to Festo Didactic SE MES PC and identifies a vendor remediation path that replaces XAMPP with Factory Control Panel. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N, reflecting network reachability, required authentication, and user interaction.
Defensive priority
Medium. Prioritize if the affected import feature is reachable by multiple authenticated users or by privileged operators, since successful exploitation can hijack browser sessions or alter displayed content for other users.
Recommended defensive actions
- Update phpMyAdmin to 4.9.11 or later in the 4.9 line, or 5.2.1 or later in the 5.x line, wherever it is deployed.
- If the vulnerability applies through Festo MES PC, obtain and deploy the current Factory Control Panel version from Festo support as described in the advisory remediation.
- Restrict access to authenticated import and drag-and-drop upload features to the smallest possible user set.
- Review account privileges for users who can upload .sql files and enforce least privilege and strong authentication controls.
- Audit affected systems for unexpected import activity or browser-side anomalies tied to authenticated sessions.
- Use the vendor and CISA advisory references to confirm which installed component version is actually present before planning remediation.
Evidence notes
The supplied source corpus is a CISA CSAF advisory (ICSA-26-027-02) published on 2024-02-27, with later administrative revisions including a 2026 republication date; those later timestamps are not the CVE’s original publication date. The advisory text explicitly describes the phpMyAdmin .sql drag-and-drop XSS condition and lists a remediation that replaces XAMPP with Factory Control Panel for MES PCs. The corpus also provides the CVSS vector CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N, and no KEV or active-threat enrichment is supplied.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-25727 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-25727
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-25727 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-25727
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/vendor/festo/
Reference
-
Source reference
Unverified legacy reference
URL: https://festo.com/psirt
Reference
-
Source reference
Unverified legacy reference
URL: https://certvde.com/en/advisories/VDE-2023-065
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.