CVE detail
CVE-2019-10784 — CVE-2019-10784
Published 2020-02-04 · Modified 2026-06-17 · Vendor phppgadmin_project · Product phppgadmin · Source nvd
CRITICAL
severity
CVSS-derived band
0.0364
EPSS probability
exploitation probability, 30d
89.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, "database.php" does not verify the source of an HTTP request. This can be leveraged by a remote attacker to trick a logged-in administrator to visit a malicious page with a CSRF exploit and execute arbitrary system commands on the server.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References