CVE-2020-11441: CRLF Injection
Published Mar 31, 2020
·Updated
DISPUTED phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable."
Affected Software
1 affected component
phpMyAdmin phpMyAdmin=5.0.2
Event History
Mar 31, 2020
CVE Published
via MITRE·04:50 PM
Data Sourced
via MITRE·04:50 PM
Description
Disputed
05:15 PM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-11441.
2
What is the title of the vulnerability?
The title of the vulnerability is ** DISPUTED ** phpMyAdmin 5.0.2 allows CRLF injection as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page.
3
What is the affected software?
The affected software is phpMyAdmin version 5.0.2.
4
What is the severity of CVE-2020-11441?
The severity of CVE-2020-11441 is medium with a CVSS score of 6.1.
5
Is there a fix for this vulnerability?
No fix has been mentioned for this vulnerability.