phpMyAdmin: SQL injection An SQL injection vulnerability in phpMyAdmin may allow attackers to execute arbitrary SQL statements. phpmyadmin 2020-03-19 2020-03-19 701830 remote 4.9.2 4.9.2

phpMyAdmin is a web-based management tool for MySQL databases.

PhpMyAdmin was vulnerable to an SQL injection attack through the designer feature.

An authenticated remote attacker, by specifying a specially crafted database/table name, could trigger an SQL injection attack.

There is no known workaround at this time.

All phpMyAdmin users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-db/phpmyadmin-4.9.2"
CVE-2019-18622 PMASA-2019-5 whissi whissi