vendor:
Adminer
by:
John Page (aka hyp3rlinx)
8.8
CVSS
HIGH
Server Side Request Forgery
918
CWE
Product Name: Adminer
Affected Version From: Adminer <= v4.3.1
Affected Version To: Adminer <= v4.7.1
Patch Exists: YES
Related CWE: N/A
CPE: a:adminer:adminer
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux, Windows, Mac
2020
Adminer <= v4.3.1 Server Side Request Forgery
Adminer is vulnerable to Server Side Request Forgery (SSRF) allowing an attacker to initiate unauthenticated connections to arbitrary systems/ports. This vulnerability can be used to potentially bypass firewalls to identify internal hosts and perform port scanning of other servers for reconnaissance purposes.
Mitigation:
Upgrade to Adminer v4.7.1 or later.