Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-12922

40
FAUCET Score

CVE-2019-12922 is a Cross-Site Request Forgery (CSRF) vulnerability in phpMyAdmin version 4.9.0.1, allowing an attacker to delete any server listed on the Setup page. This medium-severity vulnerability has a CVSS score of 6.5, indicating it can be exploited remotely with low attack complexity, requiring user interaction, and resulting in high integrity impact (data deletion) without affecting confidentiality or availability. While there is no evidence of active exploitation or KEV listing, a public exploit is available on ExploitDB, though community discussion and media coverage are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
<= 4.9.0.1CPE matchmatch criteria
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*
29CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
30CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
31CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
10.18%
Probability of exploitation in next 30 days
EPSS Percentile
95.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
ExploitDB: EDB-47385 · Sep 13, 2019
This CVE's current EPSS score of 0.1018 is in the 98th percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

composerpatch availablevia ghsa
Product: phpmyadmin/phpmyadminFixed in: 4.9.1
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-4c9q-64gq-xhx4medium

phpMyAdmin Cross-Site Request Forgery (CSRF)

May 24, 2022

References

lists.opensuse.org / opensuse-security-announce/2019-09/msg00078.html
Broken Link
lists.opensuse.org / opensuse-security-announce/2020-01/msg00024.html
Mailing ListThird Party Advisory
packetstormsecurity.com / files/154483/phpMyAdmin-4.9.0.1-Cross-Site-Request-Forgery.html
ExploitThird Party AdvisoryVDB Entry
seclists.org / fulldisclosure/2019/Sep/23
ExploitMailing ListThird Party Advisory
github.com / phpmyadmin/phpmyadmin/commit/427fbed55d3154d96ecfc1c7784d49eaa3c04161
PatchThird Party Advisory
github.com / phpmyadmin/phpmyadmin/commit/7d21d4223bdbe0306593309132b4263d7087d13b
PatchThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/PBLBE6CSC2ZLINIRBUU5XBLXYVBTF3KA
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/QJ5BW2VEMD2P23ZYRWHDBEQHOKGKGWD6
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/YCB3PTGHZ7AJCM6BKCQRRP6HG3OKYCMN
exploit-db.com / exploits/47385
ExploitThird Party AdvisoryVDB Entry