7.5
CVSSv2

CVE-2020-26935

Published: 10/10/2020 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 670
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in SearchController in phpMyAdmin prior to 4.9.6 and 5.x prior to 5.0.3. A SQL injection vulnerability exists in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyadmin phpmyadmin

opensuse leap 15.1

opensuse backports sle 15.0

opensuse leap 15.2

fedoraproject fedora 31

fedoraproject fedora 32

fedoraproject fedora 33

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #972000 phpmyadmin: CVE-2020-26935 Package: src:phpmyadmin; Maintainer for src:phpmyadmin is phpMyAdmin Packaging Team <team+phpmyadmin@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 11 Oct 2020 13:54:02 UTC Severity: important Tags: security, upstream ...