CVE-2020-26935: SQL Injection
An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.
Other sources
SQL injection vulnerability in SearchController
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-26935?
CVE-2020-26935 is a SQL injection vulnerability in the SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3.
How does the SQL injection vulnerability in SearchController work?
The SQL injection vulnerability allows an attacker to inject malicious SQL into a query processed by phpMyAdmin's search feature.
What is the severity of CVE-2020-26935?
The severity of CVE-2020-26935 is critical with a CVSS score of 9.8.
What software versions are affected by CVE-2020-26935?
Versions of phpMyAdmin before 4.9.6 and 5.x before 5.0.3 are affected.
How can I fix the SQL injection vulnerability in SearchController?
To fix the vulnerability, it is recommended to upgrade phpMyAdmin to version 4.9.6 or higher for 4.x versions, and version 5.0.3 or higher for 5.x versions.