Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x5r2-hj5c-8jx6

Опубликовано: 11 фев. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

SSRF in adminer

Impact

Users of Adminer versions bundling all drivers (e.g. adminer.php) are affected.

Patches

Patched by ccd2374b, included in version 4.7.9.

Workarounds

  • Use a single driver version (e.g. adminer-mysql.php).
  • Protect access to Adminer also by other means, e.g. by HTTP password, IP address limiting or by OTP plugin.

References

https://github.com/vrana/adminer/files/5957311/Adminer.SSRF.pdf

For more information

If you have any questions or comments about this advisory:

  • Comment at ccd2374b.

Пакеты

Наименование

vrana/adminer

composer
Затронутые версииВерсия исправления

< 4.7.9

4.7.9

EPSS

Процентиль: 100%
0.93872
Критический

7.2 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.2
ubuntu
почти 5 лет назад

Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9.

CVSS3: 7.2
nvd
почти 5 лет назад

Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9.

CVSS3: 7.2
debian
почти 5 лет назад

Adminer is an open-source database management in a single PHP file. In ...

EPSS

Процентиль: 100%
0.93872
Критический

7.2 High

CVSS3

Дефекты

CWE-918