{"id":"CVE-2020-5504","aliases":["BIT-phpmyadmin-2020-5504","GHSA-fgj8-93xx-f6g6"],"url":"https://o3.security/vulnerability/CVE-2020-5504","summary":"phpMyAdmin SQL injection in user accounts page","details":"In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.","published":"2020-01-09T22:15:13.863Z","modified":"2026-07-08T05:56:46.449581273Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Packagist","name":"phpmyadmin/phpmyadmin","fixedVersion":"4.9.4"},{"ecosystem":"Packagist","name":"phpmyadmin/phpmyadmin","fixedVersion":"5.0.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2020-5504.md"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00024.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2020/01/msg00011.html"},{"type":"FIX","url":"https://www.phpmyadmin.net/security/PMASA-2020-1/"},{"type":"EVIDENCE","url":"https://cybersecurityworks.com/zerodays/cve-2020-5504-phpmyadmin.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:56:46.449581273Z"}}