PT-2026-61694 · Adminer · Adminer
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Adminer versions prior to 5.4.3
Description
An issue exists where arbitrary values can be injected into cookie attributes via the unsanitized
X-Forwarded-Prefix HTTP header, which is used in Set-Cookie path attributes. By exploiting a misconfigured reverse proxy, an attacker can downgrade SameSite protection to enable cross-origin authenticated requests and bypass cookie security controls.Recommendations
Update to version 5.4.3 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adminer