PT-2020-12610 · Phpmyadmin+2 · Phpmyadmin+2

Oldkingcone

·

Published

2020-03-31

·

Updated

2024-08-04

·

CVE-2020-11441

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions phpMyAdmin version 5.0.2
Description The issue allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. The vendor states that they do not see anything specifically exploitable.
Recommendations For phpMyAdmin version 5.0.2, as a temporary workaround, consider restricting access to the login form fields to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3037
BIT-PHPMYADMIN-2020-11441
CVE-2020-11441

Affected Products

Alt Linux
Debian
Phpmyadmin