Description
phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable.
Remediation
References
Related Vulnerabilities
WordPress Plugin MailArchiver Cross-Site Scripting (2.10.1)
Oracle HTTP Server Out-of-bounds Write Vulnerability (CVE-2022-23943)
Liferay Portal Improper Restriction of XML External Entity Reference Vulnerability (CVE-2024-25606)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2016-2157)