Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

phpMyAdmin 4.0.x < 4.0.10.3, 4.1.x < 4.1.14.4, 4.2.x < 4.2.8.1 CSRF (PMASA-2014-10)

Medium

Synopsis

The remote web server contains a PHP application that is affected by a cross-site request forgery vulnerability.

Description

Versions of phpMyAdmin earlier than 4.0.10.3, 4.1.14.4, or 4.2.8.1 are unpatched for a DOM-based cross-site scripting vulnerability in the micro-history feature that could be leveraged for cross-site request forgery -- that is, by deceiving a logged-in user to click on a crafted URL, an attacker could perform remote code execution and in some cases, create a root account, via the user's account.

Solution

Either upgrade to phpMyAdmin 4.0.10.3, 4.1.14.4, 4.2.8.1 or later, or apply the patches from the referenced links.