PT-2024-9759 · Pgadmin+2 · Pgadmin+2
Published
2024-05-02
·
Updated
2025-04-17
·
CVE-2024-4215
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pgAdmin versions <= 8.5
Description
The issue exists due to the incorrect implementation of multi-factor authentication in the pgAdmin database management tool. This allows a remote attacker to gain unauthorized access to the application and execute arbitrary SQL code. An attacker with knowledge of a legitimate account's username and password may authenticate to the application and perform sensitive actions, such as managing files and executing SQL queries, regardless of the account's MFA enrollment status.
Recommendations
For pgAdmin versions <= 8.5, update to a version that includes a fix for the multi-factor authentication bypass issue.
As a temporary workaround, consider restricting access to sensitive actions within the application to minimize the risk of exploitation.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pgadmin
Red Os
Suse