CVE-2020-26934: XSS
phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.
Other sources
XSS relating to the transformation feature
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-26934?
CVE-2020-26934 is a vulnerability in phpMyAdmin before 4.9.6 and 5.x before 5.0.3 that allows XSS (cross-site scripting) attacks through the transformation feature via a crafted link.
What is the severity of CVE-2020-26934?
The severity of CVE-2020-26934 is medium with a CVSS score of 6.1.
Which software versions are affected by CVE-2020-26934?
phpMyAdmin versions 4.9.0 to 4.9.6 and 5.0.0 to 5.0.3 are affected by CVE-2020-26934. Additionally, openSUSE Backports SLE 15.0, openSUSE Backports SLE 15.0 SP1, openSUSE Backports SLE 15.0 SP2, openSUSE Leap 15.1, openSUSE Leap 15.2, Fedoraproject Fedora 31, Fedoraproject Fedora 32, Fedoraproject Fedora 33, and Debian Debian Linux 9.0 are also affected.
How can I exploit CVE-2020-26934?
To exploit CVE-2020-26934, an attacker can construct a malicious link that, when clicked by a victim, executes arbitrary JavaScript in the context of the phpMyAdmin user interface.
How do I fix CVE-2020-26934?
To fix CVE-2020-26934, it is recommended to update phpMyAdmin to version 4.9.6 or 5.0.3. Alternatively, apply the patches or updates provided by the software vendor for the affected versions.