PT-2020-12333 · Phpmyadmin+3 · Phpmyadmin+3

Hoangn144_Vcs

+1

·

Published

2020-03-22

·

Updated

2024-06-15

·

CVE-2020-10802

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpMyAdmin versions 4.x through 4.9.4 phpMyAdmin versions 5.x through 5.0.1
Description A SQL injection issue has been found where certain parameters are not properly escaped when generating queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. This allows an attacker to create a crafted database or table name. The attack can occur when a user performs specific search operations on the malicious database or table.
Recommendations For phpMyAdmin versions 4.x through 4.9.4, update to version 4.9.5 or later. For phpMyAdmin versions 5.x through 5.0.1, update to version 5.0.2 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2100
ALT-PU-2020-3212
ALT-PU-2021-3657
BIT-PHPMYADMIN-2020-10802
CVE-2020-10802
DLA-2154-1
GHSA-F4CR-3XMC-2WPM
MGASA-2020-0150
OPENSUSE-SU-2020:0405-1
OPENSUSE-SU-2020:0427-1
OPENSUSE-SU-2020:1806-1
OPENSUSE-SU-2020_0405-1
OPENSUSE-SU-2020_1806-1
OPENSUSE-SU-2024:11171-1
USN-4639-1

Affected Products

Alt Linux
Suse
Ubuntu
Phpmyadmin