CVE-2020-5504
HIGH 8.8EPSS 38.8%
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P - EPSS
- 38.78% chance of exploitation in the next 30 days, 98th percentile
- Published
- 2020-01-09
- Updated
- 2025-04-16
Proof-of-concept exploits (3)
- whale-baby/exploitation-of-vulnerability0★ · 2021-01-18
- xMohamed0/CVE-2020-5504-phpMyAdmin1★ · 2021-11-14
- CerberusMrXi/phpMyAdmin-CVE-2020-5504-Exploit