{"id":"CVE-2017-1000499","aliases":["GHSA-f9hx-5jq4-fgjm"],"url":"https://o3.security/vulnerability/CVE-2017-1000499","summary":"phpMyAdmin CSRF Vulnerability","details":"phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.","published":"2018-01-03T14:29:00.410Z","modified":"2026-07-08T12:05:15.883508Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":3,"affectedPackages":[{"ecosystem":"Packagist","name":"phpmyadmin/phpmyadmin","fixedVersion":"4.7.7"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1040163"},{"type":"FIX","url":"http://cyberworldmirror.com/vulnerability-phpmyadmin-lets-attacker-perform-drop-table-single-click/"},{"type":"FIX","url":"https://www.phpmyadmin.net/security/PMASA-2017-9/"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/45284/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:05:15.883508Z"}}