#VU26289 SQL injection in phpMyAdmin - CVE-2020-10802
Published: March 21, 2020 / Updated: March 23, 2020
phpMyAdmin
phpMyAdmin
Description
The vulnerability allows a remote user to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of database and table names during search operations. A remote user can send a specially crafted database or table, trick the victim into searching that table and execute arbitrary SQL commands in database.