4.3
CVSSv2

CVE-2020-26934

Published: 10/10/2020 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

phpMyAdmin prior to 4.9.6 and 5.x prior to 5.0.3 allows XSS through the transformation feature via a crafted link.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin

opensuse leap 15.1

opensuse backports sle 15.0

opensuse leap 15.2

fedoraproject fedora 31

fedoraproject fedora 32

fedoraproject fedora 33

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #971999 phpmyadmin: CVE-2020-26934 Package: src:phpmyadmin; Maintainer for src:phpmyadmin is phpMyAdmin Packaging Team <team+phpmyadmin@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 11 Oct 2020 13:51:01 UTC Severity: important Tags: security, upstream ...