QID 730124

Date Published: 2021-12-22

QID 730124: PhpMyAdmin Multiple SQL Injection Vulnerabilities (PMASA-2020-2,PMASA-2020-3,PMASA-2020-4)

PhpMyAdmin is a free software tool written in PHP and intended to handle the administration of MySQL over the Internet.

CVE-2020-10804: An SQL injection vulnerability was found in how phpMyAdmin retrieves the current username.
CVE-2020-10803: An SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results.
CVE-2020-10802: An SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions within phpMyAdmin.

Affected Versions:
phpMyAdmin versions from 4.9.x prior to 4.9.5.
phpMyAdmin versions from 5.0.x prior to 5.0.2.
QID Detection Logic (unauthenticated):
Look for vulnerable version of phpmyadmin installed.

Successful exploitation of these vulnerabilities may allows remote attackers to inject and execute arbitrary SQL code on the targeted server.

  • CVSS V3 rated as High - 8 severity.
  • CVSS V2 rated as High - 6 severity.
  • Solution
    Users are advised to upgrade to phpMyAdmin 4.9.5 or 5.0.2 or the latest version.

    CVEs related to QID 730124

    Software Advisories
    Advisory ID Software Component Link
    PMASA-2020-2 URL Logo www.phpmyadmin.net/security/PMASA-2020-2/
    PMASA-2020-3 URL Logo www.phpmyadmin.net/security/PMASA-2020-3/
    PMASA-2020-4 URL Logo www.phpmyadmin.net/security/PMASA-2020-4/