Cross-site scripting in phpMyAdmin - CVE-2020-26934
Published: October 10, 2020 / Updated: October 16, 2020
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data within the transformation feature. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Gentoo Linux
SUSE Linux
Opensuse
Ubuntu
Fedora
SUSE Package Hub for SUSE Linux Enterprise
phpmyadmin (Ubuntu package)
phpMyAdmin
How to mitigate CVE-2020-26934
phpmyadmin (Ubuntu package) - update to 4:4.6.6-5ubuntu0.5
phpMyAdmin - addressed in versions 5.0.3-1.fc31, 5.0.3-1.fc32, 5.0.3-1.fc33
External References
Related Security Bulletins
- Multiple vulnerabilities in phpMyAdmin
- OpenSUSE Linux update for phpMyAdmin
- OpenSUSE Linux update for phpMyAdmin
- OpenSUSE Linux update for phpMyAdmin
- OpenSUSE Linux update for phpMyAdmin
- Gentoo update for phpMyAdmin
- Ubuntu update for phpmyadmin
- Fedora 31 update for phpMyAdmin
- Fedora 33 update for phpMyAdmin
- Fedora 32 update for phpMyAdmin