ASA-2019-00036 – phpMyAdmin: SQL injection in Designer feature


Allele Security Alert

ASA-2019-00036

Identifier(s)

ASA-2019-00036, PMASA-2019-2, CVE-2019-6798

Title

SQL injection in Designer feature

Vendor(s)

The phpMyAdmin Project

Product(s)

phpMyAdmin

Affected version(s)

phpMyAdmin versions from 4.5.0 through 4.8.4

Fixed version(s)

phpMyAdmin 4.8.5

Proof of concept

Unknown

Description

A vulnerability was reported where a specially crafted username can be used to trigger an SQL injection attack through the designer feature.

Technical details

Unknown

Credits

YU-HSIANG HUANG, YUNG-HAO TSENG and Eddie TC CHANG

Reference(s)

phpMyAdmin – Security – PMASA-2019-2
https://www.phpmyadmin.net/security/PMASA-2019-2/

Issue phpmyadmin-security/267 SQL injection in Designer feature
https://github.com/phpmyadmin/phpmyadmin/commit/469934cf7d3bd19a839eb78670590f7511399435

CVE-2019-6798
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6798

CVE-2019-6798
https://nvd.nist.gov/vuln/detail/CVE-2019-6798

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: June 2, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.