UBUNTU-CVE-2019-12616
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-12616
UBUNTU-CVE-2019-12616
Summary:
Details: An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken <img> tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a payload (such as a specific INSERT or DELETE statement) to the victim.
References: https://ubuntu.com/security/CVE-2019-12616, https://www.phpmyadmin.net/security/PMASA-2019-4/, https://github.com/phpmyadmin/phpmyadmin/commit/015c404038c44279d95b6430ee5a0dddc97691ec, https://www.phpmyadmin.net/security/, https://ubuntu.com/security/notices/USN-4639-1, https://www.cve.org/CVERecord?id=CVE-2019-12616, https://ubuntu.com/security/notices/USN-4843-1
Affected packages
Package
Name: phpmyadmin
Purl: pkg:deb/ubuntu/phpmyadmin@4:4.0.10-1ubuntu0.1+esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
