CRLF Injection Vulnerability in phpMyAdmin by phpMyAdmin Team
CVE-2020-11441

6.1MEDIUM

Key Information:

Vendor
PHPmyadmin
Vendor
CVE Published:
31 March 2020

Summary

A CRLF injection vulnerability exists in phpMyAdmin 5.0.2, allowing malicious users to manipulate input fields in the login form. This can lead to unintended reflection of CRLF sequences on the error page, potentially enabling attackers to craft misleading responses. The vendor acknowledges the issue but has indicated that specific exploitable conditions are not evident. Proper validation and sanitization of user input are essential to mitigate this type of vulnerability.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.