CVE-2018-19968
phpmyadmin - security update
6.5
MEDIUM
CVSS 3.1
EPSS 2.4%
Description
An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.
How to fix CVE-2018-19968
To remediate CVE-2018-19968, upgrade the affected package to a fixed version below.
- —upgrade to 4:4.9.1+dfsg1-2 or later
- —upgrade to 4:4.2.12-2+deb8u4 or later
- —upgrade to 4.8.4 or later
Is CVE-2018-19968 being exploited?
Low — EPSS is 2.4%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 4:4.9.1+dfsg1-2
- from 0, < 4:4.2.12-2+deb8u4
- from 0, < 4.8.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |