CVE-2017-1000499: phpMyAdmin

High severity, CVSS 8.8. EPSS: 8.5% chance of exploitation in the next 30 days.

phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.

Affected products

  • phpMyAdmin phpMyAdmin: from 4.7.0, before 4.7.7 (fixed in 4.7.7)

Published 2018-01-03. Last modified 2026-06-17.