Server-Side Request Forgery in Adminer by Artisan
CVE-2018-7667

9.8CRITICAL

Key Information:

Vendor

Adminer

Status
Vendor
CVE Published:
5 March 2018

What is CVE-2018-7667?

Adminer versions up to 4.3.1 are vulnerable to a Server-Side Request Forgery (SSRF) attack. This allows unauthorized users to send malicious requests to internal resources or services through the server parameter, potentially leading to data exposure or unauthorized actions on the server.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.