cbcvebase.
CVE-2020-26935
published 2020-10-10

CVE-2020-26935: An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.

Affected

21 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianphpmyadmin< phpmyadmin 4:4.9.7+dfsg1-1 (bookworm)phpmyadmin 4:4.9.7+dfsg1-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
opensusebackports_sle
opensuseleap
opensuseleap
phpmyadminphpmyadmin>= 0 < 4:4.9.7+dfsg1-14:4.9.7+dfsg1-1
phpmyadminphpmyadmin>= 0 < 4:4.9.7+dfsg1-14:4.9.7+dfsg1-1
phpmyadminphpmyadmin>= 0 < 4:4.9.7+dfsg1-14:4.9.7+dfsg1-1
phpmyadminphpmyadmin>= 0 < 4:4.9.7+dfsg1-14:4.9.7+dfsg1-1
phpmyadminphpmyadmin>= 0 < 4:4.6.6-5ubuntu0.54:4.6.6-5ubuntu0.5
phpmyadminphpmyadmin>= 0 < 4:4.0.10-1ubuntu0.1+esm44:4.0.10-1ubuntu0.1+esm4
phpmyadminphpmyadmin>= 0 < 4:4.5.4.1-2ubuntu2.1+esm64:4.5.4.1-2ubuntu2.1+esm6
phpmyadminphpmyadmin>= 0 < 4:4.6.6-5ubuntu0.5+esm14:4.6.6-5ubuntu0.5+esm1
phpmyadminphpmyadmin>= 0 < 4:4.9.5+dfsg1-2ubuntu0.1~esm14:4.9.5+dfsg1-2ubuntu0.1~esm1
phpmyadminphpmyadmin>= 4.9.0 < 4.9.64.9.6
phpmyadminphpmyadmin>= 4.9.0 < 4.9.64.9.6
phpmyadminphpmyadmin>= 5.0.0 < 5.0.35.0.3
phpmyadminphpmyadmin>= 5.0.0 < 5.0.35.0.3

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL