PT-2026-99368 · Adminer · Adminer
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adminer versions 6.0.0 through 6.0.1
Description
Pre-authentication server-side request forgery occurs when the official ClickHouse driver plugin
plugins/drivers/clickhouse.php is loaded. An unauthenticated attacker can provide auth[driver]=clickhouse and set the auth[server] variable to an arbitrary URL. This causes the server to send an HTTP POST request containing 'SELECT version()' to the specified host. Within the rootQuery() function, if the target returns an HTTP status code outside the 200-299 range (excluding 401 and 403), the raw HTTP response body is assigned to the connection error and displayed on the login page. This allows for internal network and port reconnaissance, as well as the disclosure of sensitive information such as stack traces, internal hostnames, file paths, and configuration identifiers found in internal error pages.Recommendations
Update to version 6.0.2.
As a temporary mitigation, avoid loading the
plugins/drivers/clickhouse.php driver plugin.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adminer