VDB

CVE-2020-10803

CVE-2020-10803 PUBLISHED

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse tab) can trigger the XSS attack.

EPSS 2.71% · 86.2th percentile

Risk Scores

EPSS Score
2.71%
86.2th percentile

Affected Products

VendorProductVersions
Bitnamiphpmyadmin4.0.0, 5.0.0
Bitnamiphpmyadmin4.0.0, 5.0.0

Timeline

  • Mar 22, 2020 CVE Published
  • Nov 2, 2020 CVE Updated
  • Apr 14, 2021 EPSS Score
  • Jun 22, 2021 EPSS Score
  • Oct 25, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 27, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 2, 2022 EPSS Score
  • Nov 5, 2022 EPSS Score
  • Jan 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›