CVE-2020-10804
—CVSS 3.1
8.0 high
EPSS
2%p83
Published
()
Modified
Description
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious user with access to the server could create a crafted username, and then trick the victim into performing specific actions with that user account (such as editing its privileges).
- Vendors
- phpmyadminfedoraprojectopensusesuse
- Products
- phpmyadmin, fedora, backports sle, leap, package hub
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.