Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p84v-vg3f-p9m6

Опубликовано: 25 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 8.8

Описание

Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in _path and execute arbitrary code as the web-server user when uploadPath is web-served.

Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in _path and execute arbitrary code as the web-server user when uploadPath is web-served.

EPSS

Процентиль: 27%
0.00343
Низкий

7.1 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
ubuntu
10 дней назад

(Adminer versions before 5.4.3 contain an unrestricted file upload vuln ...)

CVSS3: 8.8
nvd
12 дней назад

Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in _path and execute arbitrary code as the web-server user when uploadPath is web-served.

CVSS3: 8.8
debian
12 дней назад

Adminer versions before 5.4.3 contain an unrestricted file upload vuln ...

CVSS3: 8.8
fstec
около 2 месяцев назад

Уязвимость плагина AdminerFileUpload модуля plugins/file-upload.php программного обеспечения для управления базами данных Adminer, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 27%
0.00343
Низкий

7.1 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-434