First published: Thu Apr 19 2018(Updated: )
phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.js, libraries/classes/Operations.php, and sql.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyAdmin phpMyAdmin | =4.8.0 | |
composer/phpmyadmin/phpmyadmin | >=4.8<4.8.0.1 | 4.8.0.1 |
=4.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10188 is a vulnerability in phpMyAdmin version 4.8.0 that allows an attacker to execute arbitrary SQL statements.
CVE-2018-10188 has a severity score of 8.8, which is considered high.
An attacker can exploit CVE-2018-10188 by performing a Cross-Site Request Forgery (CSRF) attack to execute arbitrary SQL statements.
phpMyAdmin version 4.8.0 is affected by CVE-2018-10188.
Yes, there are known exploits for CVE-2018-10188 available on exploit-db.com.