{"api_version":"1","generated_at":"2026-05-02T09:20:54+00:00","cve":"CVE-2018-19968","urls":{"html":"https://cve.report/CVE-2018-19968","api":"https://cve.report/api/cve/CVE-2018-19968.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-19968","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-19968"},"summary":{"title":"CVE-2018-19968","description":"An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-12-11 17:29:00","updated_at":"2019-04-23 12:36:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://www.phpmyadmin.net/security/PMASA-2018-6/","name":"https://www.phpmyadmin.net/security/PMASA-2018-6/","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"phpMyAdmin - Security - PMASA-2018-6","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2019/02/msg00003.html","name":"[debian-lts-announce] 20190201 [SECURITY] [DLA 1658-1] phpmyadmin security update","refsource":"MLIST","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] [DLA 1658-1] phpmyadmin security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/106178","name":"106178","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"phpMyAdmin CVE-2018-19968 Local File Include Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://security.gentoo.org/glsa/201904-16","name":"GLSA-201904-16","refsource":"GENTOO","tags":["Third Party Advisory"],"title":"phpMyAdmin: Multiple vulnerabilities (GLSA 201904-16) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-19968","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-19968","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"19968","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"19968","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"19968","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyadmin","cpe5":"phpmyadmin","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"19968","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyadmin","cpe5":"phpmyadmin","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2018-19968","qid":"501152","title":"Alpine Linux Security Update for phpmyadmin"},{"cve":"CVE-2018-19968","qid":"710168","title":"Gentoo Linux phpMyAdmin Multiple vulnerabilities (GLSA 201904-16)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-19968","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"106178","refsource":"BID","url":"http://www.securityfocus.com/bid/106178"},{"name":"https://www.phpmyadmin.net/security/PMASA-2018-6/","refsource":"CONFIRM","url":"https://www.phpmyadmin.net/security/PMASA-2018-6/"},{"name":"[debian-lts-announce] 20190201 [SECURITY] [DLA 1658-1] phpmyadmin security update","refsource":"MLIST","url":"https://lists.debian.org/debian-lts-announce/2019/02/msg00003.html"},{"refsource":"GENTOO","name":"GLSA-201904-16","url":"https://security.gentoo.org/glsa/201904-16"}]}},"nvd":{"publishedDate":"2018-12-11 17:29:00","lastModifiedDate":"2019-04-23 12:36:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0.0","versionEndExcluding":"4.8.4","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"19968","Ordinal":"138816","Title":"CVE-2018-19968","CVE":"CVE-2018-19968","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"19968","Ordinal":"1","NoteData":"An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"19968","Ordinal":"2","NoteData":"2018-12-11","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"19968","Ordinal":"3","NoteData":"2019-04-15","Type":"Other","Title":"Modified"}]}}}