Improper Access Control in Adminer Affects File Security
CVE-2021-43008
Key Information:
Badges
What is CVE-2021-43008?
The vulnerability present in Adminer versions 1.12.0 through 4.6.2 enables attackers to exploit improper access control, potentially facilitating arbitrary file read operations on the remote server. By manipulating the connection requests to a remote MySQL database, unauthorized users can access sensitive files, jeopardizing data integrity and security. This flaw was addressed in version 4.6.3, urging users to update promptly to safeguard against such exploits.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
13% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability Reserved
