[phpMyAdmin Developers] Bug Posted by Another User

Todd Reed <[email protected]> Wed, 18 Sep 2019 06:55:41 -0400
Newsgroups gmane.comp.php.phpmyadmin.devel
Message-ID <[email protected]>
--===============0117122546265795379==
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_9A2C3C1B-EE8F-42A6-90B0-73EB1D1640D5"


--Apple-Mail=_9A2C3C1B-EE8F-42A6-90B0-73EB1D1640D5
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

It =E2=80=9Cseems" it would be an easy fix.  According to the original =
poster it says he alerted the development team.

I searched the archive and maybe he private messaged a couple =
developers?

https://www.cvedetails.com/cve/CVE-2019-12922/ =
<https://www.cvedetails.com/cve/CVE-2019-12922/>

https://seclists.org/fulldisclosure/2019/Sep/23 =
<https://seclists.org/fulldisclosure/2019/Sep/23>

The bug would have very low probability of exploit. You would have to be =
logged into an existing phpmyadmin session and simultaneously trick the =
user to click on a link while in the setup stage.

Thought I would post here that the bug is publicly posted.

Thanks,
Todd

P.S.  Enjoy phpmyadmin.  Been using it off and on over a decade.


--Apple-Mail=_9A2C3C1B-EE8F-42A6-90B0-73EB1D1640D5
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; =
-webkit-line-break: after-white-space;" class=3D""><div class=3D"">It =
=E2=80=9Cseems" it would be an easy fix. &nbsp;According to the original =
poster it says he alerted the development team.</div><div class=3D""><br =
class=3D""></div><div class=3D"">I searched the archive and maybe he =
private messaged a couple developers?</div><div class=3D""><br =
class=3D""></div><div class=3D""><a =
href=3D"https://www.cvedetails.com/cve/CVE-2019-12922/" =
class=3D"">https://www.cvedetails.com/cve/CVE-2019-12922/</a></div><div =
class=3D""><br class=3D""></div><a =
href=3D"https://seclists.org/fulldisclosure/2019/Sep/23" =
class=3D"">https://seclists.org/fulldisclosure/2019/Sep/23</a><div =
class=3D""><br class=3D""></div><div class=3D"">The bug would have very =
low probability of exploit. You would have to be logged into an existing =
phpmyadmin session and simultaneously trick the user to click on a link =
while in the setup stage.</div><div class=3D""><br class=3D""></div><div =
class=3D"">Thought I would post here that the bug is publicly =
posted.</div><div class=3D""><br class=3D""></div><div =
class=3D"">Thanks,</div><div class=3D"">Todd</div><div class=3D""><br =
class=3D""></div><div class=3D"">P.S. &nbsp;Enjoy phpmyadmin. &nbsp;Been =
using it off and on over a decade.</div><div class=3D""><br =
class=3D""></div></body></html>=

--Apple-Mail=_9A2C3C1B-EE8F-42A6-90B0-73EB1D1640D5--


--===============0117122546265795379==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KRGV2ZWxvcGVy
cyBtYWlsaW5nIGxpc3QKRGV2ZWxvcGVyc0BwaHBteWFkbWluLm5ldApodHRwczovL2xpc3RzLnBo
cG15YWRtaW4ubmV0L21haWxtYW4vbGlzdGluZm8vZGV2ZWxvcGVycwo=

--===============0117122546265795379==--