On April 17, phpMyAdmin v4.8.0.1 was released to address Cross-Site Request Forgery vulnerability that effects to versions 4.8.0. Cross-Site Request Forgery flaw allows an attacker can manipulate a user into following a specially-crafted link, allowing the attacker to execute arbitrary SQL commands on the server. This bug was related to js/db_operations.js, js/tbl_operations.js, libraries/classes/Operations.php, and sql.php.
CVE ID
CVE-2018-10188