PT-2019-18357 · Php+4 · Phpmyadmin+4

Eddie Tc Chang

+2

·

Published

2019-01-26

·

Updated

2024-06-15

·

CVE-2019-6798

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpMyAdmin versions prior to 4.8.5
Description A SQL injection attack can be triggered through the designer feature by using a specially crafted username. This allows for potential exploitation.
Recommendations For versions prior to 4.8.5, update to version 4.8.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the designer feature until a patch is applied. Avoid using specially crafted usernames in the affected feature to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1296
CVE-2019-6798
GHSA-F732-FXH6-G4QJ
OPENSUSE-SU-2019:0194-1
OPENSUSE-SU-2019_0194-1
OPENSUSE-SU-2024:11171-1
USN-4639-1
USN-4843-1

Affected Products

Alt Linux
Linuxmint
Suse
Ubuntu
Phpmyadmin