QID 730306

Date Published: 2021-12-22

QID 730306: PhpMyAdmin Cross-Site Request Forgery (CSRF) Vulnerability (PMASA-2019-4)

PhpMyAdmin is a free software tool written in PHP and intended to handle the administration of MySQL over the Internet.

CVE-2019-12616: A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user.

Affected Versions:
phpMyAdmin versions prior to 4.9.0.

QID Detection Logic (unauthenticated):
Look for vulnerable version of phpmyadmin installed.

Successful exploitation of this vulnerability may allows remote attackers to trick user to perform unintended actions on attackers behalf.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Users are advised to upgrade to phpMyAdmin 4.9.0 or the latest version.
    Vendor References

    CVEs related to QID 730306

    Software Advisories
    Advisory ID Software Component Link
    PMASA-2019-4 URL Logo www.phpmyadmin.net/security/PMASA-2019-4/