Bug ID 1160456
Summary VUL-0: CVE-2020-5504: phpMyAdmin: SQL injection in user accounts page
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.1
Hardware Other
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee security-team@suse.de
Reporter chris@computersalat.de
QA Contact qa-bugs@suse.de
Found By ---
Blocker ---

CVE-2020-5504

A SQL injection flaw has been discovered in the user accounts page. A malicious
user could inject custom SQL in place of their own username when creating
queries to this page. An attacker must have a valid MySQL account to access the
server.

Affected Versions
phpMyAdmin 4.x versions prior to 4.9.4 are affected, at least as old as 4.0.0.
phpMyAdmin 5.x version 5.0.0 is affected.

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-5504
https://www.phpmyadmin.net/security/PMASA-2020-1/


You are receiving this mail because: