High severity8.8NVD Advisory· Published Nov 4, 2020· Updated Jun 17, 2026
CVE-2020-22278
CVE-2020-22278
Description
phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.
Affected products
4cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*range: <=5.0.2
- (no CPE)range: <=5.0.2
- phpMyAdmin/phpMyAdmindescription
Patches
Vulnerability mechanics
References
2- mega.nz/file/ySQnlQSRnvdExploitThird Party Advisory
- cert.ikiu.ac.ir/public-files/news/document/CVE-99/CVE-2020-22278.pdfnvdBroken LinkThird Party Advisory
News mentions
0No linked articles in our index yet.