PT-2020-9136 · Unknown · Phppgadmin

Published

2020-02-04

·

Updated

2022-07-25

·

CVE-2019-10784

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phppgadmin versions prior to 7.12.1
Description The issue allows sensitive actions to be performed without validating the request origin, which can be exploited by a remote attacker to trick a logged-in administrator into visiting a malicious page. This can lead to the execution of arbitrary system commands on the server. The "database.php" area does not verify the source of an HTTP request, making it vulnerable to CSRF exploits.
Recommendations For versions prior to 7.12.1, update to version 7.12.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the "database.php" page to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10784
MGASA-2021-0074
OPENSUSE-SU-2022:10065-1
OPENSUSE-SU-2024:12194-1
SNYK-PHP-PHPPGADMINPHPPGADMIN-543885

Affected Products

Phppgadmin