PT-2018-5263 · Phpmyadmin+1 · Phpmyadmin+1

Ashutosh Barot

·

Published

2018-01-03

·

Updated

2024-06-15

·

CVE-2017-1000499

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpMyAdmin versions 4.7.x prior to 4.7.6.1/4.7.7
Description The issue allows an attacker to perform harmful database operations by deceiving a user into clicking on a crafted URL, potentially leading to actions such as deleting records or dropping/truncating tables.
Recommendations For phpMyAdmin versions 4.7.x prior to 4.7.6.1/4.7.7, update to version 4.7.6.1 or 4.7.7, or later, to resolve the issue. As a temporary workaround, consider restricting access to sensitive database operations until the update can be applied.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1087
CVE-2017-1000499
GHSA-F9HX-5JQ4-FGJM
OPENSUSE-SU-2018:0534-1
OPENSUSE-SU-2018:0536-1
OPENSUSE-SU-2024:11171-1

Affected Products

Alt Linux
Phpmyadmin