Description
phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.
Remediation
References
Related Vulnerabilities
WordPress Plugin Theme Check Cross-Site Request Forgery (20190208.1)
Oracle Application Server Other Vulnerability (CVE-2004-1774)
WordPress Plugin Video Lead Form 'errMsg' Parameter Cross-Site Scripting (0.5)
Drupal Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2017-6928)
WordPress 4.6.x Cross-Domain Flash Injection Vulnerability (4.6 - 4.6.9)