Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2.11.7.1 allows remote attackers to perform unauthorized actions via a link or IMG tag to (1) the db parameter in the "Creating a Database" functionality (db_create.php), and (2) the convcharset and collation_connection parameters related to an unspecified program that modifies the connection character set.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade phpmyadmin | Jul 30, 2024 | Jul 16, 2008 |
| Phpmyadmin | — | Upgrade phpMyAdmin to the latest version | May 4, 2017 | Jul 16, 2008 |
| Suse | — | Upgrade phpmyadmin | Feb 17, 2015 | Jul 16, 2008 |
| Ubuntu | — | Upgrade phpmyadmin | Nov 19, 2024 | Jul 16, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub