CVE-2020-26935 is a critical SQL injection vulnerability in phpMyAdmin versions before 4.9.6 and 5.x before 5.0.3, affecting products like Debian, Fedora, and openSUSE. This flaw allows an unauthenticated attacker to inject malicious SQL queries through the search feature. With a CVSS score of 9.8 (Critical), successful exploitation can lead to full compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, Nuclei templates exist for this vulnerability, indicating public exploit code availability, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.9.0, < 4.9.6CPE matchmatch criteria | cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.0.3CPE matchmatch criteria | cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:-:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.