Record summary

CVE-2020-11441 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMphpMyAdmin 5.0.2 - CRLF InjectionCVSS 6.1

phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable.

Impact

Unauthenticated attackers can read arbitrary files from the server including configuration files and credentials, potentially leading to complete system compromise.

Remediation

Upgrade to a patched version of the ESPCMS or apply vendor-provided security updates.

WeaknessesCWE-93
Authorsritikchaddha
Template tagscvecrlfphpmyadmincve2020vuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:phpmyadmin:phpmyadmin:5.0.2:*:*:*:*:*:*:*
Shodan: title:"phpmyadmin"
FOFA: title="phpmyadmin"

Source: ProjectDiscovery

References

2