CVE-2021-43008
Summary
| CVE | CVE-2021-43008 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-05 02:15:00 UTC |
| Updated | 2022-09-30 13:03:00 UTC |
| Description | Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adminer | Adminer | All | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PHP tool 'Adminer' leaks passwords – Sansec | MISC | sansec.io | |
| Adminer - Database management in a single PHP file | MISC | www.adminer.org | |
| Release v4.6.3 · vrana/adminer · GitHub | MISC | github.com | |
| [SECURITY] [DLA 3002-1] adminer security update | MLIST | lists.debian.org | |
| CVE-2021-43008 - Adminer - Arbitrary file read · Podalirius | MISC | podalirius.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.