First published: Tue Mar 31 2020(Updated: )
** DISPUTED ** phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable."
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyAdmin phpMyAdmin | =5.0.2 | |
=5.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-11441.
The title of the vulnerability is ** DISPUTED ** phpMyAdmin 5.0.2 allows CRLF injection as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page.
The affected software is phpMyAdmin version 5.0.2.
The severity of CVE-2020-11441 is medium with a CVSS score of 6.1.
No fix has been mentioned for this vulnerability.