CVE-2020-22278: High severity phpmyadmin vulnerability
Published Nov 4, 2020
·Updated
DISPUTED phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents."
Affected Software
1 affected component
phpMyAdmin phpMyAdmin<=5.0.2
Event History
Nov 4, 2020
CVE Published
via MITRE·04:52 PM
Data Sourced
via MITRE·04:52 PM
Description
Disputed
05:15 PM
Frequently Asked Questions
1
What is CVE-2020-22278?
CVE-2020-22278 is a vulnerability in phpMyAdmin through version 5.0.2 that allows CSV injection via the Export Section feature.
2
How severe is CVE-2020-22278?
CVE-2020-22278 has a severity score of 8.8, which is considered high.
3
What software is affected by CVE-2020-22278?
phpMyAdmin version 5.0.2 and earlier are affected by CVE-2020-22278.
4
How can CVE-2020-22278 be exploited?
CVE-2020-22278 can be exploited through CSV injection via the Export Section feature of phpMyAdmin.
5
Is the vendor disputing CVE-2020-22278?
Yes, the vendor disputes CVE-2020-22278, claiming that the CSV file is accurately generated based on the database contents.