Adminer · Adminer · CVE-2026-100695
**Name of the Vulnerable Software and Affected Versions**
Adminer versions prior to 6.0.2
**Description**
An issue exists where the result of the `CONNECTION ID()` database function is interpolated into JavaScript without proper escaping. This allows a malicious database server to execute arbitrary JavaScript within the authenticated origin of the application. In specific co-located deployments where the database possesses FILE privileges and has write access to the webroot, this can be leveraged to submit authenticated SQL requests that write PHP files using `INTO DUMPFILE`, potentially leading to remote code execution as the web server account.
**Recommendations**
Update to version 6.0.2 or later.