Cross-site request forgery in phpMyAdmin - CVE-2018-19969
Published: December 12, 2018 / Updated: December 13, 2018
Vulnerability identifier: #VU16499
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-19969
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform CSRF attack.
The weakness exists due to insufficient CSRF protections. A remote attacker can create a specially crafted HTML page or URL, trick the victim into visiting it, gain access to the system and perform arbitrary actions.
Successful exploitation of the vulnerability may allow a remote attacker to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, updating user passwords, killing SQL processes, etc.
The weakness exists due to insufficient CSRF protections. A remote attacker can create a specially crafted HTML page or URL, trick the victim into visiting it, gain access to the system and perform arbitrary actions.
Successful exploitation of the vulnerability may allow a remote attacker to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, updating user passwords, killing SQL processes, etc.
Affected software
phpMyAdmin
Gentoo Linux
Opensuse
phpmyadmin (Alpine package)
SUSE Package Hub for SUSE Linux Enterprise
Gentoo Linux
Opensuse
phpmyadmin (Alpine package)
SUSE Package Hub for SUSE Linux Enterprise
How to mitigate CVE-2018-19969
Update to version 4.8.4.
phpMyAdmin - update to 4.8.4
phpmyadmin (Alpine package) - addressed in versions 4.8.4-r0, 4.8.5-r0
phpmyadmin (Alpine package) - addressed in versions 4.8.4-r0, 4.8.5-r0