Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an unauthenticated remote attacker to enumerate or access systems the attacker would not otherwise have access to. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.4.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: cisa-cg
Published: 2024-06-24T21:06:09.735Z
Updated: 2024-08-02T20:14:19.950Z
Reserved: 2023-10-05T03:54:13.664Z
Link: CVE-2023-45195
Vulnrichment
Updated: 2024-08-02T20:14:19.950Z
NVD
Status : Awaiting Analysis
Published: 2024-06-24T22:15:10.060
Modified: 2024-11-21T08:26:31.617
Link: CVE-2023-45195
Redhat
No data.