Candidate: CVE-2019-18622 PublicDate: 2019-11-22 21:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18622 https://www.phpmyadmin.net/security/PMASA-2019-5/ Description: An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=945349 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_phpmyadmin: upstream: https://github.com/phpmyadmin/phpmyadmin/commit/ff541af95d7155d8dd326f331b5e248fea8e7111 upstream_phpmyadmin: released (4:4.9.2+dfsg1-1) precise/esm_phpmyadmin: DNE trusty_phpmyadmin: ignored (out of standard support) trusty/esm_phpmyadmin: not-affected (code not present) xenial_phpmyadmin: not-affected (code not present) bionic_phpmyadmin: not-affected (code not present) disco_phpmyadmin: not-affected (code not present) eoan_phpmyadmin: DNE devel_phpmyadmin: released (4:4.9.2+dfsg1-1)