CVE-2020-35572Cross-site Scripting in Adminer

Severity
6.1MEDIUMNVD
EPSS
3.5%
top 12.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 9
Latest updateJun 3

Description

Adminer through 4.7.8 allows XSS via the history parameter to the default URI.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages5 packages

Packagistvrana/adminer< 4.7.9
debiandebian/adminer< adminer 4.7.9-1 (bookworm)
Debianadminer/adminer< 4.7.9-1+3
Ubuntuadminer/adminer< 4.2.1-1ubuntu1+esm1+2
NVDadminer/adminer4.7.8

🔴Vulnerability Details

4
OSV
adminer vulnerabilities2022-06-03
GHSA
vrana/adminer via XSS in the history parameter in SQL command2021-02-11
OSV
vrana/adminer via XSS in the history parameter in SQL command2021-02-11
OSV
CVE-2020-35572: Adminer through 42021-02-09

📋Vendor Advisories

2
Ubuntu
Adminer vulnerabilities2022-06-03
Debian
CVE-2020-35572: adminer - Adminer through 4.7.8 allows XSS via the history parameter to the default URI.2020