PT-2021-3225 · Postgresql+7 · Pgsql+7

Harold Kim

·

Published

2021-05-19

·

Updated

2022-06-03

·

CVE-2021-29625

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adminer versions 4.6.1 through 4.8.0
Description A cross-site scripting issue affects users of MySQL, MariaDB, PgSQL, and SQLite. This issue is mostly prevented by strict Content Security Policy (CSP) in modern browsers, except when Adminer uses a pdo extension to communicate with the database. The vulnerability can be exploited in browsers without CSP.
Recommendations For versions 4.6.1 through 4.8.0, update to version 4.8.1 to resolve the issue. As a temporary workaround, consider using a browser that supports strict CSP. Enable the native PHP extensions (e.g., mysqli) to prevent exploitation. Disable displaying PHP errors (display errors) as an additional precaution.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02925
CVE-2021-29625
GHSA-2V82-5746-VWQC
USN-5271-1

Affected Products

Adminer
Linuxmint
Mariadb
Mysql Server
Php
Pgsql
Sqlite
Ubuntu