CVE-2020-22452SQL Injection in Phpmyadmin

CWE-89SQL Injection5 documents4 sources
Severity
9.8CRITICALNVD
EPSS
3.2%
top 12.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 26

Description

SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

debiandebian/phpmyadmin< phpmyadmin 4:5.0.4+dfsg1-1 (bookworm)
NVDphpmyadmin/phpmyadmin5.0.05.2.0
Packagistphpmyadmin/phpmyadmin5.0.05.0.2
Debianphpmyadmin/phpmyadmin< 4:5.0.4+dfsg1-1+3

Patches

🔴Vulnerability Details

3
OSV
CVE-2020-22452: SQL Injection vulnerability in function getTableCreationQuery in CreateAddField2023-01-26
GHSA
phpmyadmin contains SQL Injection vulnerability2023-01-26
OSV
phpmyadmin contains SQL Injection vulnerability2023-01-26

📋Vendor Advisories

1
Debian
CVE-2020-22452: phpmyadmin - SQL Injection vulnerability in function getTableCreationQuery in CreateAddField....2020