A critical security vulnerability has been reported in phpMyAdmin, one of the most popular applications for managing the database. The vulnerability is a cross-site request forgery (CSRF) attack and affects PHPMyAdmin versions 4.7.x. A video shows how a remote attacker can make database admins unknowingly delete an entire table from the database just by tricking them into clicking a specially crafted link. Administrators are highly recommended to update their installations as soon as possible. Developers have released a new version of the free and open source administration tool for MySQL and MariaDB.
Source: https://thehackernews.com/2018/01/phpmyadmin-hack.html

