QID 730123
Date Published: 2021-12-22
QID 730123: PhpMyAdmin Multiple Vulnerabilities (PMASA-2020-5,PMASA-2020-6)
PhpMyAdmin is a free software tool written in PHP and intended to handle the administration of MySQL over the Internet.
CVE-2020-26935: A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature.
CVE-2020-26934: A vulnerability was discovered where an attacker can cause an XSS attack through the transformation feature.
Affected Versions:
phpMyAdmin versions from 4.9.x prior to 4.9.6.
phpMyAdmin versions from 5.0.x prior to 5.0.3.
QID Detection Logic (unauthenticated):
Look for vulnerable version of phpmyadmin installed.
Successful exploitation allows remote attackers to inject and execute arbitrary SQL code or steal sensitive information.
Solution
Users are advised to upgrade to phpMyAdmin 4.9.6 or 5.0.3 or the latest version.
Vendor References
- PMASA-2020-5 -
www.phpmyadmin.net/security/PMASA-2020-5/ - PMASA-2020-6 -
www.phpmyadmin.net/security/PMASA-2020-6/
CVEs related to QID 730123
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PMASA-2020-5 |
|
||
| PMASA-2020-6 |
|