RULE(RULE ID:324054)

Rule General Information
Release Date: 2020-01-17
Rule Name: phpMyAdmin Setup Server Removal Cross-Site Request Forgery Vulnerability (CVE-2019-12922)
Severity:
CVE ID:
Rule Protection Details
Description: A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
Impact: An attacker can launch a cross-site request forgery in the context of the affected software. Arbitrary script transmitted from a user that the software trusts can be executed in a successful exploit attempt.
Affected OS: Windows, Others
Reference: ExploitDB:47385
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00078.html
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00024.html
http://packetstormsecurity.com/files/154483/phpMyAdmin-4.9.0.1-Cross-Site-Request-Forgery.html
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.phpmyadmin.net/