CVE-2019-12922 is a Cross-Site Request Forgery (CSRF) vulnerability in phpMyAdmin version 4.9.0.1, allowing an attacker to delete any server listed on the Setup page. This medium-severity vulnerability has a CVSS score of 6.5, indicating it can be exploited remotely with low attack complexity, requiring user interaction, and resulting in high integrity impact (data deletion) without affecting confidentiality or availability. While there is no evidence of active exploitation or KEV listing, a public exploit is available on ExploitDB, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.9.0.1CPE matchmatch criteria | cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:* | ||
29CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.