PMASA-2018-2
Announcement-ID: PMASA-2018-2
Date: 2018-04-17
Summary
CSRF vulnerability allowing arbitrary SQL execution
Description
By deceiving a user to click on a crafted URL, it is possible for an attacker to execute arbitrary SQL commands.
Severity
We consider this vulnerability to be critical.
Affected Versions
Version 4.8.0 is affected
Solution
Upgrade to phpMyAdmin 4.8.0-1 or newer or apply patch listed below.
References
Assigned CVE IDs: CVE-2018-10188
CWE IDs: CWE-661
Patches
The following commits have been made on the 4.8 branch to fix this issue:
More information
For further information and in case of questions, please contact the phpMyAdmin security team at security@phpmyadmin.net.