Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56702

Опубликовано: 25 авг. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in _path and execute arbitrary code as the web-server user when uploadPath is web-served.

EPSS

Процентиль: 27%
0.00343
Низкий

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
ubuntu
12 дней назад

Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in _path and execute arbitrary code as the web-server user when uploadPath is web-served.

CVSS3: 8.8
debian
12 дней назад

Adminer versions before 5.4.3 contain an unrestricted file upload vuln ...

CVSS3: 8.8
github
11 дней назад

Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in _path and execute arbitrary code as the web-server user when uploadPath is web-served.

CVSS3: 8.8
fstec
около 2 месяцев назад

Уязвимость плагина AdminerFileUpload модуля plugins/file-upload.php программного обеспечения для управления базами данных Adminer, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 27%
0.00343
Низкий

8.8 High

CVSS3

Дефекты

CWE-434