Updated phpmyadmin packages fix security vulnerability
Publication date: 11 Jan 2020Modification date: 11 Jan 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-5504
Description
Updated phpmyadmin package fix security vulnerability: A SQL injection flaw has been discovered in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server (CVE-2020-5504).
References
SRPMS
7/core
- phpmyadmin-4.9.4-1.mga7