FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

phpMyAdmin -- SQL injection

Affected packages
phpMyAdmin < 4.9.4
5.0.0 <= phpMyAdmin < 5.0.1
phpMyAdmin-php72 < 4.9.4
5.0.0 <= phpMyAdmin-php72 < 5.0.1
phpMyAdmin-php73 < 4.9.4
5.0.0 <= phpMyAdmin-php73 < 5.0.1
phpMyAdmin-php74 < 4.9.4
5.0.0 <= phpMyAdmin-php74 < 5.0.1
phpMyAdmin5 < 4.9.4
5.0.0 <= phpMyAdmin5 < 5.0.1
phpMyAdmin5-php72 < 4.9.4
5.0.0 <= phpMyAdmin5-php72 < 5.0.1
phpMyAdmin5-php73 < 4.9.4
5.0.0 <= phpMyAdmin5-php73 < 5.0.1
phpMyAdmin5-php74 < 4.9.4
5.0.0 <= phpMyAdmin5-php74 < 5.0.1

Details

VuXML ID 16aed7b7-344a-11ea-9cdb-001b217b3468
Discovery 2020-01-05
Entry 2020-01-11

The phpMyAdmin development team reports:

A SQL injection flaw has been discovered in the user accounts page

References

CVE Name CVE-2020-5504
URL https://www.phpmyadmin.net/security/PMASA-2020-1/