ZeroHour

CVE-2020-10803

CVSS 3.1
5.4 medium
EPSS
1%p70
Published
()
Modified
Description

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse tab) can trigger the XSS attack.

Vendors
phpmyadmindebianfedoraprojectopensusesuse
Products
phpmyadmin, debian linux, fedora, backports sle, leap, package hub
Weakness
CWE-79, CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.