phpMyAdmin version 4.8.2-CVE-2018-12613
NAME
phpMyAdmin – phpMyAdmin
- Platforms Affected:
phpMyAdmin - Risk Level:
high - CVE Type:
Improper authentication
DESCRIPTION
CVE-2018-12613 is an improper authentication vulnerability impacting phpMyAdmin versions 4.8.1 and earlier. A Metasploit module was observed in open source and an exploit was shared in the underground.
CVSS Information:
- CVSS 2.0 SCORE: 6.5
- CVSS 3.0 SCORE: 8.8
- Exploit Disclosed in the Public:
true - Exploit Weaponised:
true - PoC Link:
hXXps://www[.]exploit-db[.]com/exploits/50457
MITIGATION
phpMyAdmin addressed the vulnerability in a phpMyAdmin version 4.8.2.
- Reference Link:
https://www.phpmyadmin.net/files/4.8.2/ - Patch Available:
available
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.