QID 730306
Date Published: 2021-12-22
QID 730306: PhpMyAdmin Cross-Site Request Forgery (CSRF) Vulnerability (PMASA-2019-4)
PhpMyAdmin is a free software tool written in PHP and intended to handle the administration of MySQL over the Internet.
CVE-2019-12616: A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user.
Affected Versions:
phpMyAdmin versions prior to 4.9.0.
QID Detection Logic (unauthenticated):
Look for vulnerable version of phpmyadmin installed.
Successful exploitation of this vulnerability may allows remote attackers to trick user to perform unintended actions on attackers behalf.
Solution
Users are advised to upgrade to phpMyAdmin 4.9.0 or the latest version.
Vendor References
- PMASA-2019-4 -
www.phpmyadmin.net/security/PMASA-2019-4/
CVEs related to QID 730306
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PMASA-2019-4 |
|