CVE-2020-22452: SQL Injection
Published Jan 26, 2023
·Updated
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tblstorageengine or tblcollation parameters to tblcreate.php.
Affected Software
1 affected component
phpMyAdmin phpMyAdmin>=5.0.0<5.2.0
Remediation
Patch Available
Patch Available
Event History
Jan 26, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-22452?
The severity of CVE-2020-22452 is critical with a CVSS score of 9.8.
2
Which software is affected by CVE-2020-22452?
phpMyAdmin versions between 5.0.0 and 5.2.0 are affected by CVE-2020-22452.
3
How can I exploit the vulnerability in CVE-2020-22452?
To exploit the vulnerability in CVE-2020-22452, an attacker can use the tbl_storage_engine or tbl_collation parameters in tbl_create.php.
4
How can I fix CVE-2020-22452?
To fix CVE-2020-22452, it is recommended to upgrade phpMyAdmin to version 5.2.0 or newer.
5
Where can I find more information about CVE-2020-22452?
More information about CVE-2020-22452 can be found at phpmyadmin.com and the phpMyAdmin GitHub repository.