ZeroHour

CVE-2020-10804

CVSS 3.1
8.0 high
EPSS
2%p83
Published
()
Modified
Description

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious user with access to the server could create a crafted username, and then trick the victim into performing specific actions with that user account (such as editing its privileges).

Vendors
phpmyadminfedoraprojectopensusesuse
Products
phpmyadmin, fedora, backports sle, leap, package hub
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.