Home Embedded Vulns General Vulns

CVE-2020-5504

HIGH 8.8

Our Analysis: General Purpose

Our model has classified this vulnerability as relevant to General Purpose Systems, helping your team prioritize efforts effectively.

Published Date January 9, 2020
Last Modified April 16, 2025
CVSS Vector Not Available

Description

In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.

Potentially Affected Vendors