CVE-2019-10784 — Cross-Site Request Forgery in Phppgadmin
Severity
9.6CRITICALNVD
EPSS
0.4%
top 37.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 4
Latest updateMay 24
Description
phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, "database.php" does not verify the source of an HTTP request. This can be leveraged by a remote attacker to trick a logged-in administrator to visit a malicious page with a CSRF exploit and execute arbitrary system commands on the server.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 2.8 | Impact: 6.0
Affected Packages4 packages
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2019-10784: phppgadmin - phppgadmin through 7.12.1 allows sensitive actions to be performed without valid...↗2019
💬Community
3Bugzilla▶
CVE-2019-10784 phpPgAdmin: database.php does not verify the source of an HTTP request which could lead to a CSRF exploit [epel-all]↗2020-03-23
Bugzilla▶
CVE-2019-10784 phppgadmin: database.php does not verify the source of an HTTP request which could lead to a CSRF exploit↗2020-03-23
Bugzilla▶
CVE-2019-10784 phpPgAdmin: database.php does not verify the source of an HTTP request which could lead to a CSRF exploit [fedora-all]↗2020-03-23