First published: Thu Jan 26 2023(Updated: )
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PhpMyAdmin | >=5.0.0<5.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-22452 is critical with a CVSS score of 9.8.
phpMyAdmin versions between 5.0.0 and 5.2.0 are affected by CVE-2020-22452.
To exploit the vulnerability in CVE-2020-22452, an attacker can use the tbl_storage_engine or tbl_collation parameters in tbl_create.php.
To fix CVE-2020-22452, it is recommended to upgrade phpMyAdmin to version 5.2.0 or newer.
More information about CVE-2020-22452 can be found at phpmyadmin.com and the phpMyAdmin GitHub repository.