CVE-2020-10802

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
22/03/2020
Last modified:
07/11/2023

Description

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. An attacker can generate a crafted database or table name. The attack can be performed if a user attempts certain search operations on the malicious database or table.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:* 4.0.0 (including) 4.9.5 (excluding)
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:* 5.0.0 (including) 5.0.2 (excluding)
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
cpe:2.3:a:opensuse:backports_sle:15.0:-:*:*:*:*:*:*
cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
cpe:2.3:a:suse:package_hub:-:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise:12.0:*:*:*:*:*:*:*