PT-2026-99369 · Adminer · Adminer
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Adminer versions 5.5.1 through 6.0.1
Description
An issue exists in the
host port() function within adminer/include/functions.inc.php where the login server string is improperly parsed. The port capture group requires digits anchored to the end of the string; if a server value contains a non-digit tail, the regex fails and the entire string is returned as the host with an empty port. This allows a remote, unauthenticated attacker to bypass the privileged-port restriction in adminer/include/auth.inc.php by submitting a crafted value, such as 127.0.0.1:80/x. Consequently, the mysqli/mysqlnd client re-parses the host and port, enabling server-side request forgery (SSRF) and blind internal port scanning by observing connection responses (connection refused, handshake, or timeout) before credentials are validated.Recommendations
Update to version 6.0.2.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adminer