PT-2018-1938 · Phpmyadmin+2 · Phpmyadmin+2

Henry Huang

·

Published

2018-06-19

·

Updated

2025-12-15

·

CVE-2018-12613

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions phpMyAdmin versions 4.8.0 through 4.8.1
Description An issue was discovered in phpMyAdmin where an attacker can include and potentially execute files on the server due to improper testing for whitelisted pages during page redirection and loading within phpMyAdmin. The attacker must be authenticated, except in cases where $cfg['AllowArbitraryServer'] = true or $cfg['ServerDefault'] = 0, which can bypass login requirements or allow arbitrary code execution.
Recommendations For phpMyAdmin versions 4.8.0 through 4.8.1, update to version 4.8.2 or later to resolve the issue. As a temporary workaround, consider disabling the $cfg['AllowArbitraryServer'] and $cfg['ServerDefault'] = 0 configurations to minimize the risk of exploitation. Restrict access to sensitive files and directories on the server to prevent potential execution by an attacker.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1925
BDU:2018-01545
CVE-2018-12613
GHSA-X394-G9J8-X7MF
OPENSUSE-SU-2018_1806-1
OPENSUSE-SU-2024:11171-1

Affected Products

Alt Linux
Suse
Phpmyadmin