Adminer · Adminer · CVE-2020-35572
Name of the Vulnerable Software and Affected Versions:
Adminer versions 4.7.8 and earlier
Description:
The issue allows XSS via the `history` parameter to the default URI. Users of Adminer using browsers that do not encode URL parameters before sending them to the server are affected.
Recommendations:
For Adminer versions 4.7.8 and earlier, update to version 4.7.9 or later to resolve the issue.
As a temporary workaround, consider using a browser that encodes URL parameters, such as Chrome or Firefox, to minimize the risk of exploitation.