Vulnerability Description
phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpmyadmin | Phpmyadmin | <= 5.0.2 |
Related Weaknesses (CWE)
References
- https://cert.ikiu.ac.ir/public-files/news/document/CVE-99/CVE-2020-22278.pdfBroken LinkThird Party Advisory
- https://mega.nz/file/ySQnlQSR#vXzY46mgf0CE2ysYpWpbE4O6T_g37--rtaL8pqdHcQsExploitThird Party Advisory
- https://cert.ikiu.ac.ir/public-files/news/document/CVE-99/CVE-2020-22278.pdfBroken LinkThird Party Advisory
- https://mega.nz/file/ySQnlQSR#vXzY46mgf0CE2ysYpWpbE4O6T_g37--rtaL8pqdHcQsExploitThird Party Advisory
FAQ
What is CVE-2020-22278?
CVE-2020-22278 is a vulnerability with a CVSS score of 8.8 (HIGH). phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.
How severe is CVE-2020-22278?
CVE-2020-22278 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-22278?
Check the references section above for vendor advisories and patch information. Affected products include: Phpmyadmin Phpmyadmin.