CVE-2023-45197
Adminer and AdminerEvo vulnerable to directory traversal and file upload
Description
Adminer and AdminerEvo contain multiple vulnerabilities. Successful exploitation of these vulnerabilities could allow a remote, unauthenticated attacker to deny service, enumerate and access systems indirectly, upload arbitrary files, and execute arbitrary code. Adminer is no longer maintained. All of these vulnerabilities are fixed in AdminerEvo 4.8.4.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
5 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2023-45197 and every CVE in our database. Create a free account — no credit card required.
Create Free Account