phpmyadmin/phpmyadmin is vulnerable to SQL injection. A remote attacker is able to inject and execute arbitrary SQL statements to insert malicious values containing Javascript into the database. When displayed in a user’s browser, the Javascript executes in the context of the user.
lists.opensuse.org/opensuse-security-announce/2020-03/msg00046.html
lists.opensuse.org/opensuse-security-announce/2020-03/msg00050.html
lists.opensuse.org/opensuse-security-announce/2020-11/msg00005.html
lists.debian.org/debian-lts-announce/2020/03/msg00028.html
lists.fedoraproject.org/archives/list/[email protected]/message/AAVW3SUKWR5RF5LZ6SARCYOWBIFUIWOJ/
lists.fedoraproject.org/archives/list/[email protected]/message/BUG3IRITW2LUBGR5LSQMP7MVRTELHZJK/
lists.fedoraproject.org/archives/list/[email protected]/message/UZI6EQVRRIG252DY3MBT33BJVCSYDMQO/
www.phpmyadmin.net/security/PMASA-2020-4/