← Back

CVE-2020-10803

nvd nist
Published: Mar 22, 2020Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse tab) can trigger the XSS attack.

Affected (10)

Show all products
1 product
Phpmyadmin
1 product
Debian Linux
1 product
Fedora
2 products
Backports Sle
Leap
1 product
Package Hub
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Phpmyadmin
From 4.0.0 to 4.9.5
From 5.0.0 to 5.0.2
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 30
Version 31
Version 32
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 15.0
Version 15.0 sp1
Version 15.1
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Suse
Linux Enterprise
Version 12.0

References (16)

Source: cve@mitre.org
Broken LinkMailing ListThird Party Advisory
Source: cve@mitre.org
Broken LinkMailing ListThird Party Advisory
Source: cve@mitre.org
Broken LinkMailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.