{"api_version":"1","generated_at":"2026-07-23T13:49:51+00:00","cve":"CVE-2021-43008","urls":{"html":"https://cve.report/CVE-2021-43008","api":"https://cve.report/api/cve/CVE-2021-43008.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-43008","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-43008"},"summary":{"title":"CVE-2021-43008","description":"Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2022-04-05 02:15:00","updated_at":"2022-09-30 13:03:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://sansec.io/research/adminer-4.6.2-file-disclosure-vulnerability","name":"https://sansec.io/research/adminer-4.6.2-file-disclosure-vulnerability","refsource":"MISC","tags":[],"title":"PHP tool 'Adminer' leaks passwords – Sansec","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.adminer.org/","name":"https://www.adminer.org/","refsource":"MISC","tags":[],"title":"Adminer - Database management in a single PHP file","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/vrana/adminer/releases/tag/v4.6.3","name":"https://github.com/vrana/adminer/releases/tag/v4.6.3","refsource":"MISC","tags":[],"title":"Release v4.6.3 · vrana/adminer · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2022/05/msg00012.html","name":"[debian-lts-announce] 20220513 [SECURITY] [DLA 3002-1] adminer security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 3002-1] adminer security update","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://podalirius.net/en/cves/2021-43008/","name":"https://podalirius.net/en/cves/2021-43008/","refsource":"MISC","tags":[],"title":"CVE-2021-43008 - Adminer - Arbitrary file read · Podalirius","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-43008","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43008","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"43008","vulnerable":"1","versionEndIncluding":"4.6.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adminer","cpe5":"adminer","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"43008","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-43008","qid":"179285","title":"Debian Security Update for adminer (DLA 3002-1)"},{"cve":"CVE-2021-43008","qid":"179853","title":"Debian Security Update for adminer (CVE-2021-43008)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-43008","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/vrana/adminer/releases/tag/v4.6.3","refsource":"MISC","name":"https://github.com/vrana/adminer/releases/tag/v4.6.3"},{"url":"https://www.adminer.org/","refsource":"MISC","name":"https://www.adminer.org/"},{"url":"https://sansec.io/research/adminer-4.6.2-file-disclosure-vulnerability","refsource":"MISC","name":"https://sansec.io/research/adminer-4.6.2-file-disclosure-vulnerability"},{"refsource":"MISC","name":"https://podalirius.net/en/cves/2021-43008/","url":"https://podalirius.net/en/cves/2021-43008/"},{"refsource":"MLIST","name":"[debian-lts-announce] 20220513 [SECURITY] [DLA 3002-1] adminer security update","url":"https://lists.debian.org/debian-lts-announce/2022/05/msg00012.html"}]}},"nvd":{"publishedDate":"2022-04-05 02:15:00","lastModifiedDate":"2022-09-30 13:03:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:adminer:adminer:*:*:*:*:*:*:*:*","versionStartIncluding":"1.12.0","versionEndIncluding":"4.6.2","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"43008","Ordinal":"219522","Title":"CVE-2021-43008","CVE":"CVE-2021-43008","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"43008","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}