QID 730307

Date Published: 2021-12-22

QID 730307: PhpMyAdmin SQL Injection Vulnerability (PMASA-2019-3)

PhpMyAdmin is a free software tool written in PHP and intended to handle the administration of MySQL over the Internet.

CVE-2019-11768: An SQL injection vulnerability was found in phpMyAdmin designer feature.

Affected Versions:
phpMyAdmin versions prior to 4.8.6.

QID Detection Logic (unauthenticated):
Look for vulnerable version of phpmyadmin installed.

Successful exploitation of these vulnerabilities may allows remote attackers to inject and execute arbitrary SQL code on the targeted server.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Users are advised to upgrade to phpMyAdmin 4.8.6 or the latest version.
    Vendor References

    CVEs related to QID 730307

    Software Advisories
    Advisory ID Software Component Link
    PMASA-2019-3 URL Logo www.phpmyadmin.net/security/PMASA-2019-3/