First published: Wed Nov 04 2020(Updated: )
** DISPUTED ** phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents."
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyAdmin phpMyAdmin | <=5.0.2 | |
<=5.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-22278 is a vulnerability in phpMyAdmin through version 5.0.2 that allows CSV injection via the Export Section feature.
CVE-2020-22278 has a severity score of 8.8, which is considered high.
phpMyAdmin version 5.0.2 and earlier are affected by CVE-2020-22278.
CVE-2020-22278 can be exploited through CSV injection via the Export Section feature of phpMyAdmin.
Yes, the vendor disputes CVE-2020-22278, claiming that the CSV file is accurately generated based on the database contents.