phpmyadmin is vulnerable to SQL injection. The vulnerability exists as the values of username
was not sanitized in libraries/classes/Server/Privileges.php
and libraries/classes/UserPassword.php
.
lists.opensuse.org/opensuse-security-announce/2020-03/msg00046.html
lists.opensuse.org/opensuse-security-announce/2020-03/msg00050.html
lists.opensuse.org/opensuse-security-announce/2020-11/msg00005.html
bugzilla.redhat.com/show_bug.cgi?id=1816097
github.com/phpmyadmin/phpmyadmin/commit/3258978c38bee8cb4b99f249dffac9c8aaea2d80
github.com/phpmyadmin/phpmyadmin/commit/89fbcd7c39e6b3979cdb2f64aa4cd5f4db27eaad
lists.fedoraproject.org/archives/list/[email protected]/message/AAVW3SUKWR5RF5LZ6SARCYOWBIFUIWOJ/
lists.fedoraproject.org/archives/list/[email protected]/message/BUG3IRITW2LUBGR5LSQMP7MVRTELHZJK/
lists.fedoraproject.org/archives/list/[email protected]/message/UZI6EQVRRIG252DY3MBT33BJVCSYDMQO/
www.phpmyadmin.net/security/PMASA-2020-2/