CVE Vulnerabilities

CVE-2021-43008

Published: Apr 05, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database.

Affected Software

NameVendorStart VersionEnd Version
AdminerAdminer1.12.0 (including)4.6.2 (including)
AdminerUbuntubionic*
AdminerUbuntufocal*
AdminerUbuntuimpish*
AdminerUbuntukinetic*
AdminerUbuntulunar*
AdminerUbuntumantic*
AdminerUbuntuoracular*
AdminerUbuntuplucky*
AdminerUbuntutrusty*
AdminerUbuntuxenial*

References