PT-2024-13226 · Unknown+1 · Adminerevo+1

Published

2024-06-21

·

Updated

2024-06-24

·

CVE-2023-45197

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AdminerEvo versions prior to 4.8.3 Adminer (affected versions not specified)
Description The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the root of the Adminer directory. The attacker can effectively guess the name of the uploaded file and execute it.
Recommendations For AdminerEvo versions prior to 4.8.3, update to version 4.8.3 to resolve the issue. For Adminer, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-45197

Affected Products

Adminer
Adminerevo