CVE-2018-10188: CSRF
Published Apr 19, 2018
·Updated
phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/dboperations.js, js/tbloperations.js, libraries/classes/Operations.php, and sql.php.
Affected Software
2 affected componentsFixes available
composer/phpmyadmin/phpmyadmin>=4.8<4.8.0.1
4.8.0.1
phpMyAdmin phpMyAdmin=4.8.0
Event History
Apr 19, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·03:22 AM
Frequently Asked Questions
1
What is CVE-2018-10188?
CVE-2018-10188 is a vulnerability in phpMyAdmin version 4.8.0 that allows an attacker to execute arbitrary SQL statements.
2
How severe is CVE-2018-10188?
CVE-2018-10188 has a severity score of 8.8, which is considered high.
3
How can an attacker exploit CVE-2018-10188?
An attacker can exploit CVE-2018-10188 by performing a Cross-Site Request Forgery (CSRF) attack to execute arbitrary SQL statements.
4
Which software versions are affected by CVE-2018-10188?
phpMyAdmin version 4.8.0 is affected by CVE-2018-10188.
5
Are there any known exploits for CVE-2018-10188?
Yes, there are known exploits for CVE-2018-10188 available on exploit-db.com.