CRITICAL · 9.8

CVE-2020-26935

An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search featu...

Vulnerability Description

An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
PhpmyadminPhpmyadmin>= 4.9.0, < 4.9.6
OpensuseBackports Sle15.0
OpensuseLeap15.1
FedoraprojectFedora31
DebianDebian Linux9.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-26935?

CVE-2020-26935 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search featu...

How severe is CVE-2020-26935?

CVE-2020-26935 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2020-26935?

Check the references section above for vendor advisories and patch information. Affected products include: Phpmyadmin Phpmyadmin, Opensuse Backports Sle, Opensuse Leap, Fedoraproject Fedora, Debian Debian Linux.