PT-2025-47583 · Unknown · Phppgadmin

CVE-2025-60798

·

Publicado

2025-11-17

·

Atualizado

2025-12-18

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions phpPgAdmin versions 7.13.0 and earlier
Description phpPgAdmin versions 7.13.0 and earlier contain a SQL injection issue in the display.php file at line 396. The application directly uses user-provided input from the query parameter in the $ REQUEST array within the browseQuery function without sufficient sanitization. An authenticated attacker can manipulate queries to execute arbitrary SQL commands, potentially compromising the entire database. The vulnerable parameter is query.
Recommendations Versions prior to 7.13.0 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-14887
CVE-2025-60798
GHSA-G6XH-WRPF-V6J6

Produtos afetados

Phppgadmin