CVE detail
CVE-2020-10802 — CVE-2020-10802
Published 2020-03-22 · Modified 2026-06-17 · Vendor phpmyadmin · Product phpmyadmin · Source nvd
HIGH
severity
CVSS-derived band
0.0182
EPSS probability
exploitation probability, 30d
77.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. An attacker can generate a crafted database or table name. The attack can be performed if a user attempts certain search operations on the malicious database or table.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References