A critical vulnerability has been reported in phpMyAdmin – one of the most popular MySQL database management applications – which could allow remote attackers to execute dangerous commands by tricking administrators.
phpMyAdmin is a free management tool for MySQL and MariaDB and is widely used to manage the database for websites built with WordPress, Joomla, and many other content management platforms. Some of its additional features are:
- Import data in CSV, SQL formats and export to CSV, SQL, XML and PDF.
- Search the entire database or a part of it.
- Live view of MySQL server statistics such as connections and processes being performed, even processor and memory information.
- Operation on many operating systems and different MySQL servers.
- Support for multiple languages including Greek.
The vulnerability was discovered by security researcher Ashutosh Barot, who reported that this security issue allows a CSRF (Cross-site Request Forgery) attack in phpMyAdmin versions 4.7.x.
One of the features of phpMyAdmin is the GET request followed by a POST request which triggers certain database functions. GET requests are normally protected from CSRF attacks. In this case, POST requests were used that were sent via a URL with which the attacker was able to trick the database administrator into accessing it.
Barot reported the vulnerability to the phpMyAdmin developers, who confirmed the discovery and upgraded phpMyAdmin to version 4.7.7 to address the issue. Administrators using the program are therefore advised to make the necessary updates as soon as possible.

