PublicDateAtUSN: 2020-03-22 05:15:00 UTC Candidate: CVE-2020-10803 PublicDate: 2020-03-22 05:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10803 https://www.phpmyadmin.net/security/PMASA-2020-4/ https://github.com/phpmyadmin/phpmyadmin/commit/46a7aa7cd4ff2be0eeb23721fbf71567bebe69a5 https://github.com/phpmyadmin/phpmyadmin/commit/6b9b2601d8af916659cde8aefd3a6eaadd10284a https://lists.debian.org/debian-lts-announce/2020/03/msg00028.html https://ubuntu.com/security/notices/USN-4639-1 Description: In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse tab) can trigger the XSS attack. Ubuntu-Description: It was discovered that phpMyAdmin did not properly handle data from the database when displaying it. If an attacker were to insert specially-crafted data into certain database tables, the attacker could execute a cross-site scripting (XSS) attack. Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=954666 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N [5.4 MEDIUM] Patches_phpmyadmin: upstream_phpmyadmin: released (4:4.6.6-4+deb9u1, 4:4.9.5+dfsg1-1) precise/esm_phpmyadmin: DNE trusty_phpmyadmin: ignored (out of standard support) trusty/esm_phpmyadmin: needed xenial_phpmyadmin: ignored (end of standard support, was needed) bionic_phpmyadmin: released (4:4.6.6-5ubuntu0.5) eoan_phpmyadmin: DNE focal_phpmyadmin: not-affected (4:4.9.5+dfsg1-1ubuntu1) groovy_phpmyadmin: not-affected (4:4.9.5+dfsg1-1ubuntu1) hirsute_phpmyadmin: not-affected (4:4.9.5+dfsg1-1ubuntu1) impish_phpmyadmin: not-affected (4:4.9.5+dfsg1-1ubuntu1) jammy_phpmyadmin: not-affected (4:4.9.5+dfsg1-1ubuntu1) devel_phpmyadmin: not-affected (4:4.9.5+dfsg1-1ubuntu1)