{"id":"CVE-2020-11441","details":"phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states \"I don't see anything specifically exploitable.","aliases":["BIT-phpmyadmin-2020-11441"],"modified":"2026-08-18T13:48:35.922138Z","published":"2020-03-31T17:15:26.497Z","references":[{"type":"REPORT","url":"https://github.com/phpmyadmin/phpmyadmin/issues/16056"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/phpmyadmin/phpmyadmin","events":[{"introduced":"4520c9d17291007bc2da9f71836ac8c72fc9a7e5"},{"last_affected":"4520c9d17291007bc2da9f71836ac8c72fc9a7e5"}],"database_specific":{"cpe":"cpe:2.3:a:phpmyadmin:phpmyadmin:5.0.2:*:*:*:*:*:*:*","extracted_events":[{"introduced":"5.0.2"},{"last_affected":"5.0.2"}],"source":"CPE_STRING"}}],"versions":["5.0.2","RELEASE_5_0_2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-11441.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}