An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature. CREATE(Triage):(User=admin) CVE-2019-18622 (https://nvd.nist.gov/vuln/detail/CVE-2019-18622)