CVE-2019-12922: CSRF
Published Sep 13, 2019
·Updated
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
Affected Software
5 affected componentsFixes available
composer/phpmyadmin/phpmyadmin<=4.9.0.1
4.9.1
phpMyAdmin phpMyAdmin<=4.9.0.1
fedoraproject fedora=29
fedoraproject fedora=30
fedoraproject fedora=31
Remediation
Event History
Sep 13, 2019
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
Description
May 24, 2022
Advisory Published
via GitHub·10:00 PM
Frequently Asked Questions
1
What is the severity of CVE-2019-12922?
The severity of CVE-2019-12922 is medium with a CVSS score of 6.5.
2
How does CVE-2019-12922 affect phpMyAdmin?
CVE-2019-12922 allows deletion of any server in the Setup page of phpMyAdmin 4.9.0.1.
3
Which versions of phpMyAdmin are affected by CVE-2019-12922?
phpMyAdmin version 4.9.0.1 is affected by CVE-2019-12922.
4
Is Fedora affected by CVE-2019-12922?
Yes, Fedora versions 29, 30, and 31 are affected by CVE-2019-12922.
5
How can I fix CVE-2019-12922 in phpMyAdmin?
Upgrade phpMyAdmin to a version higher than 4.9.0.1.