CVE-2020-10803

unknown
Published 2022-05-24 · Modified 2024-04-24
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v2
VIR risk

Description

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse tab) can trigger the XSS attack.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-10803

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed4:4.9.5+dfsg1-1
debian debianbullseyefixed4:4.9.5+dfsg1-1
debian debiansidfixed4:4.9.5+dfsg1-1
debian debiantrixiefixed4:4.9.5+dfsg1-1

Package impact

EcosystemPackageVulnerableFixed
php Packagistphpmyadmin/phpmyadmin>=3.4,<4.9.54.9.5
php Packagistphpmyadmin/phpmyadmin>=5.0.0,<5.0.25.0.2

References

Verify integrity in audit chain (admin only). AS-IS.