CVE-2020-5504

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
09/01/2020
Last modified:
16/04/2025

Description

In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:* 4.0.0 (including) 4.9.4 (excluding)
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:* 5.0.0 (including) 5.0.1 (excluding)
cpe:2.3:o:suse:suse_linux_enterprise_server:12:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*