PublicDateAtUSN: 2020-03-22 05:15:00 UTC Candidate: CVE-2020-10802 PublicDate: 2020-03-22 05:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10802 https://www.phpmyadmin.net/security/PMASA-2020-3/ https://github.com/phpmyadmin/phpmyadmin/commit/a8acd7a42cf743186528b0453f90aaa32bfefabe https://lists.debian.org/debian-lts-announce/2020/03/msg00028.html https://ubuntu.com/security/notices/USN-4639-1 Description: In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. An attacker can generate a crafted database or table name. The attack can be performed if a user attempts certain search operations on the malicious database or table. Ubuntu-Description: It was discovered that phpMyAdmin failed to sanitize certain input. An attacker could use this vulnerability to execute an SQL injection attack via a specially crafted database or table name. Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=954665 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H [8.0 HIGH] Patches_phpmyadmin: upstream_phpmyadmin: released (4:4.2.12-2+deb8u9, 4:4.6.6-4+deb9u1, 4:4.9.5+dfsg1-1) precise/esm_phpmyadmin: DNE trusty_phpmyadmin: ignored (out of standard support) trusty/esm_phpmyadmin: needed xenial_phpmyadmin: ignored (end of standard support, was needed) bionic_phpmyadmin: released (4:4.6.6-5ubuntu0.5) eoan_phpmyadmin: DNE focal_phpmyadmin: not-affected (4:4.9.5+dfsg1-1ubuntu1) groovy_phpmyadmin: not-affected (4:4.9.5+dfsg1-1ubuntu1) hirsute_phpmyadmin: not-affected (4:4.9.5+dfsg1-1ubuntu1) impish_phpmyadmin: not-affected (4:4.9.5+dfsg1-1ubuntu1) jammy_phpmyadmin: not-affected (4:4.9.5+dfsg1-1ubuntu1) devel_phpmyadmin: not-affected (4:4.9.5+dfsg1-1ubuntu1)