Description
phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.
Remediation
References
Related Vulnerabilities
WordPress Plugin PayPal Digital Downloads Cross-Site Request Forgery (1.4)
WordPress Plugin WP Front-End Repository Manager Arbitrary File Upload (1.1)
WordPress Plugin DeMomentSomTres Subscribe Cross-Site Scripting (201909190900)
WordPress Plugin Auctions 'upload.php' Arbitrary File Upload (2.0.1.3)