Impact
The AdminerFileUpload plugin in Adminer versions prior to 5.4.3 contains an unrestricted file upload flaw that permits authenticated users to upload arbitrary PHP files. By placing the uploaded file in a column ending with _path, an attacker can upload a webshell and execute code on the server with web-server privileges.
Affected Systems
Affected systems are installations of the Adminer database management tool from vendor vrana, specifically any version before 5.4.3 that includes the AdminerFileUpload plugin. No specific additional product versioning is listed beyond the major 5.4 series.
Risk and Exploitability
With a CVSS score of 7.1, this vulnerability represents a moderate‑to‑high risk. The EPSS score is not reported, and the issue is not listed in the KEV catalog. Exploitation requires an authenticated session with file‑upload access; once an attacker supplies a PHP file, they can run arbitrary code as the web-server user. The threat is realistic in environments where Adminer is exposed without strict access controls.
OpenCVE Enrichment