CVE-2018-19969: phpMyAdmin
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, updating user passwords, killing SQL processes, etc.
Affected products
- phpMyAdmin phpMyAdmin: from 4.7.0, up to and including 4.7.6; from 4.8.0, before 4.8.4 (fixed in 4.8.4)
Published 2018-12-11. Last modified 2026-06-17.