Blog | G5 Cyber Security

CSRF Vulnerability in phpMyAdmin allows attackers to perform DROP TABLE with a single click!

The development team ofphpMyAdmin has fixed a CSRF vulnerability in phpMyAdmin that could be exploited by attackers for removing items from shopping cart. The vulnerability is ranked as Medium severity because its exploitation needs the user interaction. An attacker can create a crafted URL and trick the victims having an active session into performing dangerous operations without their knowledge. The attack worked even when the user was authenticated in cPanel and PHPMyAdmin was closed after use. Users must update their installations or apply the following patches to fix the vulnerability.”]

Source: http://securityaffairs.co/wordpress/67243/hacking/phpmyadmin-csrf-vulnerability.html

Exit mobile version