CVE detail
CVE-2020-5504 — CVE-2020-5504
Published 2020-01-09 · Modified 2026-06-17 · Vendor phpmyadmin · Product phpmyadmin · Source nvd
HIGH
severity
CVSS-derived band
0.3878
EPSS probability
exploitation probability, 30d
98.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References