Lucene search

K
osvGoogleOSV:CVE-2020-26935
HistoryOct 10, 2020 - 7:15 p.m.

CVE-2020-26935

2020-10-1019:15:12
Google
osv.dev
10
phpmyadmin
sql injection
searchcontroller
cve-2020-26935
software vulnerability

AI Score

7.4

Confidence

Low

EPSS

0.008

Percentile

82.2%

An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.