CVE-2025-43960
- EPSS 0.22%
- Veröffentlicht 25.08.2025 00:00:00
- Zuletzt bearbeitet 12.09.2025 20:16:45
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by...
CVE-2023-45195
- EPSS 2.46%
- Veröffentlicht 24.06.2024 22:15:10
- Zuletzt bearbeitet 21.11.2024 08:26:31
Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an unauthenticated remote attacker to enumerate or access systems the attacker would not otherwise have access to. Adminer is no longer supported, but this...
CVE-2023-45196
- EPSS 1.17%
- Veröffentlicht 24.06.2024 21:15:25
- Zuletzt bearbeitet 21.11.2024 08:26:31
Adminer and AdminerEvo allow an unauthenticated remote attacker to cause a denial of service by connecting to an attacker-controlled service that responds with HTTP redirects. The denial of service is subject to PHP configuration limits. Adminer is n...
CVE-2021-43008
- EPSS 83.64%
- Veröffentlicht 05.04.2022 02:15:06
- Zuletzt bearbeitet 21.11.2024 06:28:27
Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database.
CVE-2021-29625
- EPSS 69.25%
- Veröffentlicht 19.05.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:01:31
Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4.8.0 affects users of MySQL, MariaDB, PgSQL and SQLite. XSS is in most cases prevented by strict CSP in all modern browsers. The o...
CVE-2021-21311
- EPSS 94.23%
- Veröffentlicht 11.02.2021 21:15:13
- Zuletzt bearbeitet 30.09.2025 13:41:33
Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected....
CVE-2020-35572
- EPSS 5.15%
- Veröffentlicht 09.02.2021 18:15:44
- Zuletzt bearbeitet 21.11.2024 05:27:36
Adminer through 4.7.8 allows XSS via the history parameter to the default URI.
CVE-2018-7667
- EPSS 11%
- Veröffentlicht 05.03.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:30
Adminer through 4.3.1 has SSRF via the server parameter.