CVE-2019-11768: SQL Injection
Published Jun 5, 2019
·Updated
An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature.
Affected Software
2 affected componentsFixes available
composer/phpmyadmin/phpmyadmin<4.9.0.1
4.9.0.1
phpMyAdmin phpMyAdmin<4.9.0.1
Remediation
Patch Available
Event History
Jun 5, 2019
CVE Published
via MITRE·04:25 AM
Data Sourced
via MITRE·04:25 AM
Description
May 24, 2022
Advisory Published
via GitHub·04:47 PM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-11768.
2
What is the severity of CVE-2019-11768?
The severity of CVE-2019-11768 is critical, with a severity value of 9.8.
3
What is the affected software for CVE-2019-11768?
The affected software for CVE-2019-11768 is phpMyAdmin before version 4.9.0.1.
4
What is the potential impact of this vulnerability?
This vulnerability can be used to trigger an SQL injection attack through the designer feature in phpMyAdmin.
5
How can I fix CVE-2019-11768?
To fix CVE-2019-11768, update phpMyAdmin to version 4.9.0.1 or later.