CRITICAL
An issue was discovered in phpMyAdmin before 4.9.2
Published Nov 22, 2019
9.8
CRITICALCVSS 3.1
EPSS 2.24%
Description
An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.
Affected products
No data.
Configuration 1
- < 4.9.2
Configuration 2
OR
- 15.0
- 15.0
- 30
- 31
- 15.0
- 15.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00002.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00024.html vendor-advisoryx_refsource_SUSE
- https://github.com/advisories/GHSA-jgjc-332c-8cmc Advisory
- https://github.com/phpmyadmin/composer/commit/51acbf53564d9b52e78509a5688ec2b68976b5f7
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BA4DGF7KTQS6WA2DRNJSW66L43WB7LRV/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W5GW4KEMNCBQYZCIXEJYC42OEBBN2NSH/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BA4DGF7KTQS6WA2DRNJSW66L43WB7LRV/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W5GW4KEMNCBQYZCIXEJYC42OEBBN2NSH/
- https://nvd.nist.gov/vuln/detail/CVE-2019-18622
- https://security.gentoo.org/glsa/202003-39 vendor-advisoryx_refsource_GENTOO
- https://www.phpmyadmin.net/security/PMASA-2019-5/ x_refsource_CONFIRMPatchVendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 22, 2019
Updated Aug 5, 2024
Reserved Oct 29, 2019
Link CVE-2019-18622
CISA Vulnrichment
GHSA-JGJC-332C-8CMC Updated n/a