CVE-2017-1000499: CSRF
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-1000499?
CVE-2017-1000499 is a vulnerability in phpMyAdmin versions 4.7.x that allows an attacker to perform harmful database operations by deceiving a user into clicking on a crafted URL.
How severe is CVE-2017-1000499?
CVE-2017-1000499 has a severity rating of high, with a severity value of 8.8 out of 10.
What software versions are affected by CVE-2017-1000499?
phpMyAdmin versions 4.7.x prior to 4.7.6.1/4.7.7 are affected by CVE-2017-1000499.
How can an attacker exploit CVE-2017-1000499?
An attacker can exploit CVE-2017-1000499 by deceiving a user into clicking on a crafted URL, which allows them to perform harmful database operations.
Is there a fix for CVE-2017-1000499?
Yes, the fix for CVE-2017-1000499 is to upgrade to phpMyAdmin version 4.7.6.1 or 4.7.7.