phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| phpmyadmin/phpmyadmin(Packagist) | 4.7 | 4.7.7 | N/A |
CVSS Metrics