PT-2024-13224 · Unknown+2 · Adminerevo+2

Published

2024-06-24

·

Updated

2025-10-15

·

CVE-2023-45195

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/AU:Y
Name of the Vulnerable Software and Affected Versions AdminerEvo versions prior to 4.8.4 Adminer (affected versions not specified)
Description The issue allows an unauthenticated remote attacker to enumerate or access systems via database connection fields due to a Server-Side Request Forgery (SSRF) vulnerability. This could enable the attacker to access systems they would not otherwise have access to.
Recommendations For AdminerEvo versions prior to 4.8.4, update to version 4.8.4 to resolve the issue. For Adminer, since it is no longer supported and no fix is available, consider replacing it with a supported alternative to mitigate the risk. As a temporary workaround, consider restricting access to the database connection fields to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-45195

Affected Products

Adminer
Adminerevo
Debian