QID 730123

Date Published: 2021-12-22

QID 730123: PhpMyAdmin Multiple Vulnerabilities (PMASA-2020-5,PMASA-2020-6)

PhpMyAdmin is a free software tool written in PHP and intended to handle the administration of MySQL over the Internet.

CVE-2020-26935: A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature.
CVE-2020-26934: A vulnerability was discovered where an attacker can cause an XSS attack through the transformation feature.

Affected Versions:
phpMyAdmin versions from 4.9.x prior to 4.9.6.
phpMyAdmin versions from 5.0.x prior to 5.0.3.
QID Detection Logic (unauthenticated):
Look for vulnerable version of phpmyadmin installed.

Successful exploitation allows remote attackers to inject and execute arbitrary SQL code or steal sensitive information.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Users are advised to upgrade to phpMyAdmin 4.9.6 or 5.0.3 or the latest version.

    CVEs related to QID 730123

    Software Advisories
    Advisory ID Software Component Link
    PMASA-2020-5 URL Logo www.phpmyadmin.net/security/PMASA-2020-5/
    PMASA-2020-6 URL Logo www.phpmyadmin.net/security/PMASA-2020-6/