CRITICAL
An issue was discovered in phpMyAdmin before 4.9.0.1
Published Jun 5, 2019
9.8
CRITICALCVSS 3.0
EPSS 4.08%
Description
An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature.
Affected products
No data.
- < 4.9.0.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00005.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00017.html vendor-advisoryx_refsource_SUSE
- http://www.securityfocus.com/bid/108617 vdb-entryx_refsource_BID
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5693 Advisory
- https://github.com/advisories/GHSA-x37v-98f9-mj32 Advisory
- https://github.com/phpmyadmin/phpmyadmin/commit/c1ecafc38319e8f768c9259d4d580e42acd5ee86
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/II4HC4QO6WUL2IRSQKCB66UBJOLLI5OV/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKJMYVXEDXGEGRO42T6H6VOEZJ65QPQ7/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-11768
- https://www.phpmyadmin.net/security/PMASA-2019-3/ x_refsource_CONFIRMPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00005.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00017.html | vendor-advisoryx_refsource_SUSE | |
| http://www.securityfocus.com/bid/108617 | vdb-entryx_refsource_BID | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5693 | Advisory | |
| https://github.com/advisories/GHSA-x37v-98f9-mj32 | Advisory | |
| https://github.com/phpmyadmin/phpmyadmin/commit/c1ecafc38319e8f768c9259d4d580e42acd5ee86 | ||
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/II4HC4QO6WUL2IRSQKCB66UBJOLLI5OV/ | vendor-advisoryx_refsource_FEDORA | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKJMYVXEDXGEGRO42T6H6VOEZJ65QPQ7/ | vendor-advisoryx_refsource_FEDORA | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-11768 | ||
| https://www.phpmyadmin.net/security/PMASA-2019-3/ | x_refsource_CONFIRMPatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 5, 2019
Updated Aug 4, 2024
Reserved May 6, 2019
Link CVE-2019-11768
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-5693 GHSA-X37V-98F9-MJ32 Assigner mitre
Published Jun 5, 2019
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2022-5693