First published: Fri Sep 13 2019(Updated: )
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyAdmin phpMyAdmin | <=4.9.0.1 | |
Fedoraproject Fedora | =29 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 | |
composer/phpmyadmin/phpmyadmin | <=4.9.0.1 | 4.9.1 |
<=4.9.0.1 | ||
=29 | ||
=30 | ||
=31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-12922 is medium with a CVSS score of 6.5.
CVE-2019-12922 allows deletion of any server in the Setup page of phpMyAdmin 4.9.0.1.
phpMyAdmin version 4.9.0.1 is affected by CVE-2019-12922.
Yes, Fedora versions 29, 30, and 31 are affected by CVE-2019-12922.
Upgrade phpMyAdmin to a version higher than 4.9.0.1.