PMASA-2017-9
Announcement-ID: PMASA-2017-9
Date: 2017-12-20
Updated: 2018-01-03
Summary
XSRF/CSRF vulnerability in phpMyAdmin
Description
By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.
Severity
We consider this vulnerability to be critical.
Affected Versions
Versions 4.7.x (prior to 4.7.7) are affected.
Unaffected Versions
Versions older than 4.7.0 are not affected.
Solution
Upgrade to phpMyAdmin 4.7.7 or newer or apply patch listed below.
References
Thanks to Ashutosh Barot for reporting the vulnerability.
Assigned CVE IDs: CVE-2017-1000499
Patches
The following commits have been made on the 4.7 branch to fix this issue:
The following commits have been made on the 4.8 branch to fix this issue:
More information
For further information and in case of questions, please contact the phpMyAdmin security team at security@phpmyadmin.net.