phpmyadmin: Multiple vulnerabilities (CVE-2018-12581, CVE-2018-12613)
CVE-2018-12581: XSS in Designer feature
A Cross-Site Scripting vulnerability was found in the Designer feature,
where an attacker can
deliver a payload to a user through a specially-crafted database name.
Affected Versions:
phpMyAdmin versions prior to 4.8.2.
Reference:
https://www.phpmyadmin.net/security/PMASA-2018-3/
Patch:
https://github.com/phpmyadmin/phpmyadmin/commit/6943fff87324bd54c3a37a5160a5fb77498c355e
CVE-2018-12613: File inclusion and remote code execution attack
A flaw has been discovered where an attacker can include (view and
potentially execute) files on the server.
The vulnerability comes from a portion of code where pages are
redirected and loaded within phpMyAdmin, and an improper test for
whitelisted pages.
An attacker must be authenticated, except in these situations:
- $cfg[‘AllowArbitraryServer’] = true: attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin
- $cfg[‘ServerDefault’] = 0: this bypasses the login and runs the vulnerable code without any authentication
Affected Versions:
phpMyAdmin 4.8.0 and 4.8.1 are affected.
Reference:
https://www.phpmyadmin.net/security/PMASA-2018-4/
Patch:
https://github.com/phpmyadmin/phpmyadmin/commit/7662d02939fb3cf6f0d9ec32ac664401dcfe7490
(from redmine: issue id 9091, created on 2018-07-16, closed on 2018-07-17)
- Relations:
- copied_to #9092 (closed)
- copied_to #9093 (closed)
- child #9092 (closed)
- child #9093 (closed)