PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-25727 Festo Didactic SE CVE debrief

CVE-2023-25727 is an authenticated cross-site scripting issue in phpMyAdmin’s drag-and-drop import flow. In the supplied advisory corpus, the CVE is associated with Festo Didactic SE MES PC deployments and a vendor replacement path for the affected XAMPP-based component. Organizations should treat this as a browser-side injection risk that can affect logged-in users who handle imports or administration tasks.

Vendor
Festo Didactic SE
Product
MES PC
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-27
Original CVE updated
2026-01-27
Advisory published
2024-02-27
Advisory updated
2026-01-27

Who should care

Administrators and operators of Festo Didactic SE MES PC environments, especially where phpMyAdmin or a bundled XAMPP-based workflow is exposed to authenticated users. Security teams should also review any environment where users can upload .sql files through a drag-and-drop import interface.

Technical summary

The source description states that phpMyAdmin before 4.9.11 and 5.x before 5.2.1 allows an authenticated user to trigger XSS by uploading a crafted .sql file through the drag-and-drop interface. The supplied CSAF advisory links this CVE to Festo Didactic SE MES PC and identifies a vendor remediation path that replaces XAMPP with Factory Control Panel. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N, reflecting network reachability, required authentication, and user interaction.

Defensive priority

Medium. Prioritize if the affected import feature is reachable by multiple authenticated users or by privileged operators, since successful exploitation can hijack browser sessions or alter displayed content for other users.

Recommended defensive actions

  • Update phpMyAdmin to 4.9.11 or later in the 4.9 line, or 5.2.1 or later in the 5.x line, wherever it is deployed.
  • If the vulnerability applies through Festo MES PC, obtain and deploy the current Factory Control Panel version from Festo support as described in the advisory remediation.
  • Restrict access to authenticated import and drag-and-drop upload features to the smallest possible user set.
  • Review account privileges for users who can upload .sql files and enforce least privilege and strong authentication controls.
  • Audit affected systems for unexpected import activity or browser-side anomalies tied to authenticated sessions.
  • Use the vendor and CISA advisory references to confirm which installed component version is actually present before planning remediation.

Evidence notes

The supplied source corpus is a CISA CSAF advisory (ICSA-26-027-02) published on 2024-02-27, with later administrative revisions including a 2026 republication date; those later timestamps are not the CVE’s original publication date. The advisory text explicitly describes the phpMyAdmin .sql drag-and-drop XSS condition and lists a remediation that replaces XAMPP with Factory Control Panel for MES PCs. The corpus also provides the CVSS vector CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N, and no KEV or active-threat enrichment is supplied.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-25727 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-25727

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-25727 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-25727

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-027-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://festo.csaf-tp.certvde.com/.well-known/csaf/white/2024/fsa-202402.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/vendor/festo/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://festo.com/psirt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://certvde.com/en/advisories/VDE-2023-065

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-027-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.