Skip to content

XSS via the history parameter in SQL command

High
vrana published GHSA-9pgx-gcph-mpqr Feb 10, 2021

Package

all

Affected versions

4.7.0 to 4.7.8

Patched versions

4.7.9

Description

Impact

Users of Adminer versions supporting SQL command (most versions, e.g. MySQL) using browsers not encoding URL parameters before sending to server (likely Edge, not Chrome, not Firefox) are affected.

Patches

Patched by 5c395af, included in version 4.7.9.

Workarounds

Use browser which encodes URL parameters (e.g. Chrome or Firefox).

References

https://sourceforge.net/p/adminer/bugs-and-features/775/

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2020-35572

Weaknesses