CVE-2020-10804: Fedoraproject Fedora

High severity, CVSS 8.0. EPSS: 2.4% chance of exploitation in the next 30 days.

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious user with access to the server could create a crafted username, and then trick the victim into performing specific actions with that user account (such as editing its privileges).

Affected products

  • Fedoraproject Fedora: version 30 only; version 31 only; version 32 only
  • Opensuse Backports Sle: version 15.0 only
  • Opensuse Leap: version 15.1 only
  • phpMyAdmin phpMyAdmin: from 4.0.0, before 4.9.5 (fixed in 4.9.5); from 5.0.0, before 5.0.2 (fixed in 5.0.2)
  • Suse Package Hub: affected versions not specified

Published 2020-03-22. Last modified 2026-06-17.