PT-2020-12333 · Phpmyadmin+3 · Phpmyadmin+3
Hoangn144_Vcs
+1
·
Published
2020-03-22
·
Updated
2024-06-15
·
CVE-2020-10802
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
phpMyAdmin versions 4.x through 4.9.4
phpMyAdmin versions 5.x through 5.0.1
Description
A SQL injection issue has been found where certain parameters are not properly escaped when generating queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. This allows an attacker to create a crafted database or table name. The attack can occur when a user performs specific search operations on the malicious database or table.
Recommendations
For phpMyAdmin versions 4.x through 4.9.4, update to version 4.9.5 or later.
For phpMyAdmin versions 5.x through 5.0.1, update to version 5.0.2 or later.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Suse
Ubuntu
Phpmyadmin