Lucene search

K
cvelistMitreCVELIST:CVE-2020-26935
HistoryOct 10, 2020 - 6:26 p.m.

CVE-2020-26935

2020-10-1018:26:53
mitre
www.cve.org
8
phpmyadmin
sql injection
search feature

AI Score

9.6

Confidence

High

EPSS

0.008

Percentile

82.2%

An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.