First published: Wed Jan 03 2018(Updated: )
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/phpmyadmin/phpmyadmin | >=4.7<4.7.7 | 4.7.7 |
PhpMyAdmin | >=4.7.0<4.7.7 |
http://cyberworldmirror.com/vulnerability-phpmyadmin-lets-attacker-perform-drop-table-single-click/
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000499 is a vulnerability in phpMyAdmin versions 4.7.x that allows an attacker to perform harmful database operations by deceiving a user into clicking on a crafted URL.
CVE-2017-1000499 has a severity rating of high, with a severity value of 8.8 out of 10.
phpMyAdmin versions 4.7.x prior to 4.7.6.1/4.7.7 are affected by CVE-2017-1000499.
An attacker can exploit CVE-2017-1000499 by deceiving a user into clicking on a crafted URL, which allows them to perform harmful database operations.
Yes, the fix for CVE-2017-1000499 is to upgrade to phpMyAdmin version 4.7.6.1 or 4.7.7.