CVE-2018-19969: CSRF
phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, updating user passwords, killing SQL processes, etc.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19969?
The severity of CVE-2018-19969 is high with a severity value of 8.8.
How does CVE-2018-19969 affect phpMyAdmin?
CVE-2018-19969 affects phpMyAdmin versions 4.7.x and 4.8.x prior to 4.8.4.
How can an attacker exploit CVE-2018-19969?
An attacker can exploit CVE-2018-19969 by deceiving a user into clicking on a crafted URL, which allows them to perform harmful SQL operations.
What are the potential consequences of CVE-2018-19969?
The potential consequences of CVE-2018-19969 include renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, and more.
How can I mitigate the CSRF flaws in phpMyAdmin?
To mitigate the CSRF flaws in phpMyAdmin, update to version 4.8.4 or later.