PT-2026-3806 · Unknown · Phppgadmin
Valerio Severini
·
Published
2020-11-07
·
Updated
2026-01-23
·
CVE-2021-47853
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
phpPgAdmin version 7.13.0
Description
An authenticated attacker can execute arbitrary system commands through SQL query manipulation. This is achieved by creating a custom table, uploading a malicious .txt file, and utilizing the COPY FROM PROGRAM command to execute operating system commands with the application's privileges.
Recommendations
Update to a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the
COPY FROM PROGRAM command.
Avoid using SQL queries that involve file uploads or external program execution.Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phppgadmin