Description
An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken <img> tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a payload (such as a specific INSERT or DELETE statement) to the victim.
Published: 2019-06-05
Score: 6.5 Medium
EPSS: 55.1% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-1821-1 phpmyadmin security update
Github GHSA Github GHSA GHSA-mfr9-pcm3-6mwc phpMyAdmin CSRF Vulnerability
Ubuntu USN Ubuntu USN USN-4639-1 phpMyAdmin vulnerabilities
Ubuntu USN Ubuntu USN USN-4843-1 phpMyAdmin vulnerabilities
History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.55745}

epss

{'score': 0.50644}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.62457}

epss

{'score': 0.55745}


Subscriptions

Phpmyadmin Phpmyadmin
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T23:24:39.192Z

Reserved: 2019-06-03T00:00:00.000Z

Link: CVE-2019-12616

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-06-05T05:29:00.510

Modified: 2024-11-21T04:23:11.647

Link: CVE-2019-12616

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses