PT-2025-34607 · Adminer+1 · Adminer+1

Fabian Rosales

+1

·

Published

2025-08-25

·

Updated

2025-08-29

·

CVE-2025-43960

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Adminer version 4.8.1
Description: Adminer 4.8.1, when using Monolog for logging, is susceptible to a Denial of Service (memory consumption) through a crafted serialized payload, resulting in a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering the Adminer interface unresponsive and potentially causing a server-level DoS. Multiple simultaneous requests can lead to a complete server crash requiring manual intervention.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-43960
GHSA-MQH4-2MM8-G7W9

Affected Products

Adminer
Debian