Lucene search

K
osvGoogleOSV:GHSA-7FF4-CV53-4CJQ
HistoryMay 24, 2022 - 5:30 p.m.

phpMyAdmin SQL injection vulnerability

2022-05-2417:30:27
Google
osv.dev
10
phpmyadmin
sql injection
searchcontroller
4.9.6
5.0.3
sql statements
search feature
software
attacker
malicious sql
query

AI Score

7.4

Confidence

Low

EPSS

0.008

Percentile

82.2%

An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.