Vulnerability Description
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpmyadmin | Phpmyadmin | >= 5.0.0, < 5.2.0 |
Related Weaknesses (CWE)
References
- http://phpmyadmin.comVendor Advisory
- https://github.com/phpmyadmin/phpmyadmin/blob/master/ChangeLogThird Party Advisory
- https://github.com/phpmyadmin/phpmyadmin/issues/15898ExploitPatchThird Party Advisory
- https://github.com/phpmyadmin/phpmyadmin/pull/16004PatchThird Party Advisory
- http://phpmyadmin.comVendor Advisory
- https://github.com/phpmyadmin/phpmyadmin/blob/master/ChangeLogThird Party Advisory
- https://github.com/phpmyadmin/phpmyadmin/issues/15898ExploitPatchThird Party Advisory
- https://github.com/phpmyadmin/phpmyadmin/pull/16004PatchThird Party Advisory
FAQ
What is CVE-2020-22452?
CVE-2020-22452 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.
How severe is CVE-2020-22452?
CVE-2020-22452 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-22452?
Check the references section above for vendor advisories and patch information. Affected products include: Phpmyadmin Phpmyadmin.