Updated phpmyadmin packages fix security vulnerabilities
Publication date: 21 Jun 2019Modification date: 21 Jun 2019
Type: security
Affected Mageia releases : 6
CVE: CVE-2019-11768 , CVE-2019-12616
Description
Updated phpmyadmin packages fix security vulnerabilities: A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature. (CVE-2019-11768, PMASA-2019-3) A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a payload (such as a specific INSERT or DELETE statement) through the victim. (CVE-2019-12616, PMASA-2019-4)
References
SRPMS
6/core
- phpmyadmin-4.7.8-5.mga6