CVE-2020-35572
MEDIUM6.1EPSS 3.3%vrana/adminer via XSS in the history parameter in SQL command
發布日:2021/2/11修改日:2026/4/28
描述
Adminer through 4.7.8 allows XSS via the history parameter to the default URI.
受影響套件(2)
- Debian/adminerfrom 0, < 4.7.9-1
- Packagist/vrana/adminerfrom 0, < 4.7.9
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
參考連結(7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2020-35572
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2020-35572
- PATCHhttps://github.com/vrana/adminer
- WEBhttps://github.com/vrana/adminer/commit/5c395afc098e501be3417017c6421968aac477bd
- WEBhttps://github.com/vrana/adminer/security/advisories/GHSA-9pgx-gcph-mpqr
- WEBhttps://sourceforge.net/p/adminer/bugs-and-features/775
- WEBhttps://sourceforge.net/p/adminer/news/2021/02/adminer-479-released