PT-2024-13224 · Unknown+2 · Adminerevo+2
Published
2024-06-24
·
Updated
2025-10-15
·
CVE-2023-45195
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/AU:Y |
Name of the Vulnerable Software and Affected Versions
AdminerEvo versions prior to 4.8.4
Adminer (affected versions not specified)
Description
The issue allows an unauthenticated remote attacker to enumerate or access systems via database connection fields due to a Server-Side Request Forgery (SSRF) vulnerability. This could enable the attacker to access systems they would not otherwise have access to.
Recommendations
For AdminerEvo versions prior to 4.8.4, update to version 4.8.4 to resolve the issue.
For Adminer, since it is no longer supported and no fix is available, consider replacing it with a supported alternative to mitigate the risk.
As a temporary workaround, consider restricting access to the database connection fields to minimize the risk of exploitation.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adminer
Adminerevo
Debian