cbcvebase.
CVE-2020-26934
published 2020-10-10

CVE-2020-26934: phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.

Affected

21 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianphpmyadmin< phpmyadmin 4:4.9.7+dfsg1-1 (bookworm)phpmyadmin 4:4.9.7+dfsg1-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
opensusebackports_sle
opensuseleap
opensuseleap
phpmyadminphpmyadmin>= 0 < 4:4.9.7+dfsg1-14:4.9.7+dfsg1-1
phpmyadminphpmyadmin>= 0 < 4:4.9.7+dfsg1-14:4.9.7+dfsg1-1
phpmyadminphpmyadmin>= 0 < 4:4.9.7+dfsg1-14:4.9.7+dfsg1-1
phpmyadminphpmyadmin>= 0 < 4:4.9.7+dfsg1-14:4.9.7+dfsg1-1
phpmyadminphpmyadmin>= 0 < 4:4.6.6-5ubuntu0.54:4.6.6-5ubuntu0.5
phpmyadminphpmyadmin>= 0 < 4:4.0.10-1ubuntu0.1+esm44:4.0.10-1ubuntu0.1+esm4
phpmyadminphpmyadmin>= 0 < 4:4.5.4.1-2ubuntu2.1+esm64:4.5.4.1-2ubuntu2.1+esm6
phpmyadminphpmyadmin>= 0 < 4:4.6.6-5ubuntu0.5+esm14:4.6.6-5ubuntu0.5+esm1
phpmyadminphpmyadmin>= 0 < 4:4.9.5+dfsg1-2ubuntu0.1~esm14:4.9.5+dfsg1-2ubuntu0.1~esm1
phpmyadminphpmyadmin>= 4.9.0 < 4.9.64.9.6
phpmyadminphpmyadmin>= 4.9.0 < 4.9.64.9.6
phpmyadminphpmyadmin>= 5.0.0 < 5.0.35.0.3
phpmyadminphpmyadmin>= 5.0.0 < 5.0.35.0.3

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.5MEDIUM