phpMyAdmin Setup Server Removal Cross-Site Request Forgery

Strike ID:
E19-7p0a1
CVSS:
6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
False Positive:
f
Variants:
4
Year:
2019

Description

This strike simulates a CSRF attack on phpMyAdmin. The flaw is a result of no anti-CSRF technique being employed in the setup page. A remote attacker may entice a phpMyAdmin user to make a request to a crefted URL, leading to removal of arbitray servers from the phpMyAdmin configuration.

CVE

References