Announcement-ID: PMASA-2017-9
Date: 2017-12-20
Updated: 2018-01-03
XSRF/CSRF vulnerability in phpMyAdmin
By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.
We consider this vulnerability to be critical.
Versions 4.7.x (prior to 4.7.7) are affected.
Versions older than 4.7.0 are not affected.
Upgrade to phpMyAdmin 4.7.7 or newer or apply patch listed below.
Thanks to Ashutosh Barot for reporting the vulnerability.
Assigned CVE ids: CVE-2017-1000499
The following commits have been made on the 4.7 branch to fix this issue:
The following commits have been made on the 4.8 branch to fix this issue:
For further information and in case of questions, please contact the phpMyAdmin team. Our website is phpmyadmin.net.