CVE-2019-12616

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken <img> tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a payload (such as a specific INSERT or DELETE statement) to the victim.

References

http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00005.html

http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00017.html

http://packetstormsecurity.com/files/153251/phpMyAdmin-4.8-Cross-Site-Request-Forgery.html

http://www.securityfocus.com/bid/108619

https://lists.debian.org/debian-lts-announce/2019/06/msg00009.html

https://lists.fedoraproject.org/archives/list/[email protected]/message/II4HC4QO6WUL2IRSQKCB66UBJOLLI5OV/

https://lists.fedoraproject.org/archives/list/[email protected]/message/ZKJMYVXEDXGEGRO42T6H6VOEZJ65QPQ7/

https://www.phpmyadmin.net/security/

https://www.phpmyadmin.net/security/PMASA-2019-4/

Details

Source: MITRE

Published: 2019-06-05

Updated: 2019-06-14

Type: CWE-352

Risk Information

CVSS v2

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Impact Score: 3.6

Exploitability Score: 2.8

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*

Tenable Plugins

View all (7 total)

IDNameProductFamilySeverity
143119Ubuntu 18.04 LTS : phpMyAdmin vulnerabilities (USN-4639-1)NessusUbuntu Local Security Checks
critical
126490openSUSE Security Update : phpMyAdmin (openSUSE-2019-1689)NessusSuSE Local Security Checks
critical
125957Debian DLA-1821-1 : phpmyadmin security updateNessusDebian Local Security Checks
high
125936FreeBSD : phpMyAdmin -- CSRF vulnerability in login form (a5681027-8e03-11e9-85f4-6805ca0b3d42)NessusFreeBSD Local Security Checks
medium
125907Fedora 29 : php-phpmyadmin-sql-parser / phpMyAdmin (2019-33649e2e64)NessusFedora Local Security Checks
critical
125906Fedora 30 : php-phpmyadmin-sql-parser / phpMyAdmin (2019-13d2ba0aed)NessusFedora Local Security Checks
critical
125856phpMyAdmin 4.x < 4.9.0 CSRF vulnerablity (PMASA-2019-4)NessusCGI abuses
medium