Vulnerability Intelligence Report
Adminer and AdminerEvo vulnerable to directory traversal and file upload
CVE-2023-45197
The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the root of the Adminer directory. The attacker can effectively guess the name of the uploaded file and execute it. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.3.
No Active Exploit Signals
CVSS Base Score
9.2
CRITICAL
EPSS Probability:0.66%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-434 ↗CWE-434 Unrestricted Upload of File with Dangerous Type
CWE-22 ↗CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Adminer | Adminer | 0 <= * (affected), cpe:2.3:a:adminer:adminer:0:*:*:*:*:*:*:* <= cpe:2.3:a:adminer:adminer:*:*:*:*:*:*:*:* (affected) |
| AdminerEvo | AdminerEvo | 4.8.2 < 4.8.3 (affected), cpe:2.3:a:adminerevo:adminerevo:0:*:*:*:*:*:*:* < cpe:2.3:a:adminerevo:adminerevo:4.8.3:*:*:*:*:*:*:* (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.663%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government · CERT · USA |
| Reserved | 2023-10-05T03:54:13 |
| Published | 2024-06-21T14:28:36 |
| Patch Date | 2023-10-29 |
| Last Updated | 2024-08-02T20:14:19 |
Community Chatter & Buzz