Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Mageia 7: 2020-0383 Moderate: phpMyAdmin XSS and SQL Issues

mageia
Calendar Grey October 16, 2020
Dist Mageia Esm H88
Mageia 2020-0383 addresses phpMyAdmin security issues, fixing XSS and SQL injection vulnerabilities.
A vulnerability was discovered where an attacker can cause an XSS attack through the transformation feature

Summary

A vulnerability was discovered where an attacker can cause an XSS attack through the transformation feature. If an attacker sends a crafted link to the victim with the malicious JavaScript, when the victim clicks on the link, the JavaScript will run and complete the instructions made by the attacker. (CVE-2020-26934)
An SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query. (CVE-2020-26935)

References

- https://bugs.mageia.org/show_bug.cgi?id=27379

- https://www.phpmyadmin.net/news/2020/10/10/phpmyadmin-496-and-503-are-released/

- https://www.phpmyadmin.net/security/PMASA-2020-5/

- https://www.phpmyadmin.net/security/PMASA-2020-6/

- https://www.cve.org/CVERecord?id=CVE-2020-26934

- https://www.cve.org/CVERecord?id=CVE-2020-26935

Resolution

SRPMS

- 7/core/phpmyadmin-4.9.6-1.mga7

Publication date: 16 Oct 2020
URL: https://advisories.mageia.org/MGASA-2020-0383.html
Type: security
CVE: CVE-2020-26934, CVE-2020-26935

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here