QID 150870
QID 150870: pgAdmin Remote Code Execution (RCE) Vulnerability (CVE-2024-3116)
pgAdmin4 is a graphical management tool for the open source database PostgreSQL.
A Remote Code Execution (RCE) vulnerability exists in pgAdmin through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting pgAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data.
Affected Versions:
pgAdmin up to version 8.4
QID Detection Logic (Unauthenticated):
This QID sends HTTP GET requests and checks for vulnerable version of pgAdmin running on the target host.
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the target system.
Solution
Vendor References
CVEs related to QID 150870
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| pgAdmin 8.5 |
|