GHSA-xwf2-53mc-r8hx

Suggest an improvement
Source
https://github.com/advisories/GHSA-xwf2-53mc-r8hx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xwf2-53mc-r8hx/GHSA-xwf2-53mc-r8hx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xwf2-53mc-r8hx
Aliases
Published
2022-05-14T01:09:10Z
Modified
2024-02-17T05:29:24.083159Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
phpMyAdmin CSRF Vulnerability
Details

phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, updating user passwords, killing SQL processes, etc.

Database specific
{
    "nvd_published_at": "2018-12-11T17:29:00Z",
    "cwe_ids": [
        "CWE-352"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2023-07-24T19:28:59Z"
}
References

Affected packages

Packagist / phpmyadmin/phpmyadmin

Package

Name
phpmyadmin/phpmyadmin
Purl
pkg:composer/phpmyadmin/phpmyadmin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.8
Fixed
4.8.4

Affected versions

4.*

4.8.0
4.8.0.1
4.8.1
4.8.2
4.8.3

Packagist / phpmyadmin/phpmyadmin

Package

Name
phpmyadmin/phpmyadmin
Purl
pkg:composer/phpmyadmin/phpmyadmin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.7
Last affected
4.7.6

Affected versions

4.*

4.7.0
4.7.1
4.7.2
4.7.3
4.7.4
4.7.5
4.7.6