CVE-2020-5504: Debian Linux

High severity, CVSS 8.8. EPSS: 38.8% chance of exploitation in the next 30 days.

In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.

Affected products

  • Debian Debian Linux: version 8.0 only
  • phpMyAdmin phpMyAdmin: from 4.0.0, before 4.9.4 (fixed in 4.9.4); from 5.0.0, before 5.0.1 (fixed in 5.0.1)
  • Suse Suse Linux Enterprise Server: version 12 only

Published 2020-01-09. Last modified 2026-06-17.