An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.
{
"github_reviewed_at": "2020-01-16T21:54:54Z",
"severity": "CRITICAL",
"github_reviewed": true,
"cwe_ids": [
"CWE-89"
],
"nvd_published_at": null
}