Логотип exploitDog
bind:CVE-2026-25892
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-25892

Количество 4

Количество 4

ubuntu логотип

CVE-2026-25892

около 2 месяцев назад

Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version info via JavaScript postMessage, which the browser then POSTs to ?script=version. This endpoint lacks origin validation and accepts POST data from any source. An attacker can POST version[] parameter which PHP converts to an array. On next page load, openssl_verify() receives this array instead of string and throws TypeError, returning HTTP 500 to all users. Upgrade to Adminer 5.4.2.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-25892

около 2 месяцев назад

Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version info via JavaScript postMessage, which the browser then POSTs to ?script=version. This endpoint lacks origin validation and accepts POST data from any source. An attacker can POST version[] parameter which PHP converts to an array. On next page load, openssl_verify() receives this array instead of string and throws TypeError, returning HTTP 500 to all users. Upgrade to Adminer 5.4.2.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-25892

около 2 месяцев назад

Adminer is open-source database management software. Adminer v5.4.1 an ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-q4f2-39gr-45jh

около 2 месяцев назад

Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-25892

Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version info via JavaScript postMessage, which the browser then POSTs to ?script=version. This endpoint lacks origin validation and accepts POST data from any source. An attacker can POST version[] parameter which PHP converts to an array. On next page load, openssl_verify() receives this array instead of string and throws TypeError, returning HTTP 500 to all users. Upgrade to Adminer 5.4.2.

CVSS3: 7.5
7%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-25892

Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version info via JavaScript postMessage, which the browser then POSTs to ?script=version. This endpoint lacks origin validation and accepts POST data from any source. An attacker can POST version[] parameter which PHP converts to an array. On next page load, openssl_verify() receives this array instead of string and throws TypeError, returning HTTP 500 to all users. Upgrade to Adminer 5.4.2.

CVSS3: 7.5
7%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-25892

Adminer is open-source database management software. Adminer v5.4.1 an ...

CVSS3: 7.5
7%
Низкий
около 2 месяцев назад
github логотип
GHSA-q4f2-39gr-45jh

Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint

CVSS3: 7.5
7%
Низкий
около 2 месяцев назад

Уязвимостей на страницу