PT-2022-11760 · Adminer · Adminer

Podalirius

·

Published

2021-07-17

·

Updated

2025-11-18

·

CVE-2021-43008

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adminer versions 1.12.0 through 4.6.2
Description The issue allows an attacker to achieve arbitrary file read on a remote server by requesting Adminer to connect to a remote MySQL database, due to improper access control.
Recommendations For Adminer versions 1.12.0 through 4.6.2, update to version 4.6.3 to resolve the issue.

Exploit

Fix

Improper Access Control

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

BDU:2025-14681
CVE-2021-43008
DLA-3002-1
GHSA-RXFQ-3VPC-VV72

Affected Products

Adminer