PT-2024-13226 · Unknown+1 · Adminerevo+1
Published
2024-06-21
·
Updated
2024-06-24
·
CVE-2023-45197
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AdminerEvo versions prior to 4.8.3
Adminer (affected versions not specified)
Description
The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the root of the Adminer directory. The attacker can effectively guess the name of the uploaded file and execute it.
Recommendations
For AdminerEvo versions prior to 4.8.3, update to version 4.8.3 to resolve the issue.
For Adminer, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Adminer
Adminerevo