Advisories ยป MGASA-2019-0200

Updated phpmyadmin packages fix security vulnerabilities

Publication date: 21 Jun 2019
Modification date: 21 Jun 2019
Type: security
Affected Mageia releases : 6
CVE: CVE-2019-11768 , CVE-2019-12616

Description

Updated phpmyadmin packages fix security vulnerabilities:

A vulnerability was reported where a specially crafted database name can
be used to trigger an SQL injection attack through the designer feature.
(CVE-2019-11768, PMASA-2019-3)

A vulnerability was found that allows an attacker to trigger a CSRF attack
against a phpMyAdmin user. The attacker can trick the user, for instance
through a broken  tag pointing at the victim's phpMyAdmin database,
and the attacker can potentially deliver a payload (such as a specific
INSERT or DELETE statement) through the victim. (CVE-2019-12616,
PMASA-2019-4)
                

References

SRPMS

6/core