phpMyAdmin 4.8 – Cross-Site Request Forgery Vulnerability

0

phpMyAdmin developmnet team is putting a lot of effort to make the appliaction as secure as possible.

But still web application phpMyAdmin can be vulnerable to a number of attacks and new ways to exploit are stille being explored.

An issue was discovered in phpMyAdmin before 4.9.0. A vulnerabiliti was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken tag pointing at the victim’s phpMyAdmin database, and the attacker can pontentially deliver a payload suc as specific INSERT or DELETE statement to the victim.

LEAVE A REPLY

Please enter your comment!
Please enter your name here