CVE-2020-35572

MEDIUM6.1EPSS 3.3%

vrana/adminer via XSS in the history parameter in SQL command

Published: 2/11/2021Modified: 4/28/2026
Also known as:GHSA-9pgx-gcph-mpqrDEBIAN-CVE-2020-35572

Description

Adminer through 4.7.8 allows XSS via the history parameter to the default URI.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (7)