2023-02-07
ALT-BU-2023-2460-1
Branch sisyphus_e2k update bulletin.
Package phpMyAdmin updated to version 5.2.0-alt2 for branch sisyphus_e2k.
Closed vulnerabilities
Published: 2023-01-27
Modified: 2025-04-01
Modified: 2025-04-01
CVE-2020-22452
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.
Severity: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- http://phpmyadmin.com
- http://phpmyadmin.com
- https://github.com/phpmyadmin/phpmyadmin/blob/master/ChangeLog
- https://github.com/phpmyadmin/phpmyadmin/blob/master/ChangeLog
- https://github.com/phpmyadmin/phpmyadmin/issues/15898
- https://github.com/phpmyadmin/phpmyadmin/issues/15898
- https://github.com/phpmyadmin/phpmyadmin/pull/16004
- https://github.com/phpmyadmin/phpmyadmin/pull/16004