PT-2022-11760 · Adminer · Adminer
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adminer versions 1.12.0 through 4.6.2
Description
The issue allows an attacker to achieve arbitrary file read on a remote server by requesting Adminer to connect to a remote MySQL database, due to improper access control.
Recommendations
For Adminer versions 1.12.0 through 4.6.2, update to version 4.6.3 to resolve the issue.
Exploit
Fix
Files Accessible to External Parties
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Adminer