CVE-2019-12616: CSRF
An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken <img> tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a payload (such as a specific INSERT or DELETE statement) to the victim.
Other sources
An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken <img> tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a payload (such as a specific INSERT or DELETE statement) to the victim.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-12616.
What is the severity of CVE-2019-12616?
The severity of CVE-2019-12616 is medium with a CVSS score of 6.5.
What is the affected software version of CVE-2019-12616?
The affected software version of CVE-2019-12616 is phpMyAdmin before version 4.9.0.
What is the impact of CVE-2019-12616?
CVE-2019-12616 allows an attacker to trigger a CSRF attack against a phpMyAdmin user.
How can I fix CVE-2019-12616?
To fix CVE-2019-12616, update phpMyAdmin to version 4.9.0 or later.