SQL Injection Vulnerability in phpMyAdmin by phpMyAdmin
CVE-2020-22452
9.8CRITICAL
What is CVE-2020-22452?
An SQL Injection vulnerability exists in the getTableCreationQuery function within CreateAddField.php in phpMyAdmin versions 5.x prior to 5.2.0. Attackers can exploit this vulnerability using malformed tbl_storage_engine or tbl_collation parameters, potentially allowing unauthorized database access or manipulation. It is essential for users of affected versions to update to the latest release to mitigate this risk.