CVE-2020-22452
Critical · CVSS 9.8phpMyAdmin — SQL Injection
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-89, CWE-89
Description
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.
Search profile — drives PoC discovery
Symbols getTableCreationQueryCreateAddField.phptbl_create.phptbl_storage_enginetbl_collation
Keywords CVE-2020-22452phpMyAdmin SQL InjectiongetTableCreationQueryCreateAddField.phptbl_storage_enginetbl_collationtbl_create.phpphpmyadmin 5.x SQLiphpMyAdmin 5.2.0
Versions: 5.x before 5.2.0
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0cyb3r-w0lf/nuclei-template-collection needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
Affected packages
| Bitnami | phpmyadmin | 5.0.0 → 5.2.0 |
| Packagist | phpmyadmin/phpmyadmin | 5.0.0 → 5.0.2 |
References
- https://github.com/phpmyadmin/phpmyadmin/blob/master/ChangeLog
- https://github.com/phpmyadmin/phpmyadmin/issues/15898
- https://github.com/phpmyadmin/phpmyadmin/pull/16004
- http://phpmyadmin.com
- https://github.com/phpmyadmin/phpmyadmin/blob/master/ChangeLog
- https://github.com/phpmyadmin/phpmyadmin/issues/15898
- https://github.com/phpmyadmin/phpmyadmin/pull/16004
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z