phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.js, libraries/classes/Operations.php, and sql.php.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/103936 | third party advisory vdb entry |
http://www.securitytracker.com/id/1040752 | third party advisory vdb entry |
https://www.phpmyadmin.net/security/PMASA-2018-2/ | vendor advisory |
https://www.exploit-db.com/exploits/44496/ | third party advisory vdb entry exploit |