CVE-2018-12613 is a critical Local File Inclusion (LFI) vulnerability affecting phpMyAdmin versions before 4.8.2, allowing authenticated attackers to view and potentially execute arbitrary files on the server. In specific configurations ($cfg['AllowArbitraryServer'] = true or $cfg['ServerDefault'] = 0), authentication can be bypassed, enabling unauthenticated remote code execution. With a CVSS score of 8.8 (High) and an EPSS score of 0.94294, this vulnerability presents a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Numerous public exploits exist, including Metasploit modules and Nuclei templates, and it has garnered substantial community discussion and media coverage, indicating widespread awareness and potential for active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.8.0, < 4.8.2CPE matchmatch criteria | cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.