VulnerabilityModified
CVE-2021-43008
Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database.
HIGH 7.5EPSS 13.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.6%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 13.64% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- adminer/adminer · debian/debian linux
- Source
- cve@mitre.org
References
- https://github.com/vrana/adminer/releases/tag/v4.6.3Release Notes, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/05/msg00012.htmlMailing List, Third Party Advisory
- https://podalirius.net/en/cves/2021-43008/Exploit, Third Party Advisory
- https://sansec.io/research/adminer-4.6.2-file-disclosure-vulnerabilityExploit, Third Party Advisory
- https://www.adminer.org/Product
- https://github.com/vrana/adminer/releases/tag/v4.6.3Release Notes, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/05/msg00012.htmlMailing List, Third Party Advisory
- https://podalirius.net/en/cves/2021-43008/Exploit, Third Party Advisory
- https://sansec.io/research/adminer-4.6.2-file-disclosure-vulnerabilityExploit, Third Party Advisory
- https://www.adminer.org/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.