First published: Tue Feb 09 2021(Updated: )
### Impact Users of Adminer versions supporting SQL command (most versions, e.g. MySQL) using browsers not encoding URL parameters before sending to server (likely Edge, not Chrome, not Firefox) are affected. ### Patches Patched by 5c395afc, included in version [4.7.9](https://github.com/vrana/adminer/releases/tag/v4.7.9). ### Workarounds Use browser which encodes URL parameters (e.g. Chrome or Firefox). ### References https://sourceforge.net/p/adminer/bugs-and-features/775/ ### For more information If you have any questions or comments about this advisory: * Comment at https://sourceforge.net/p/adminer/bugs-and-features/775/
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/vrana/adminer | <4.7.9 | 4.7.9 |
Adminer Adminer | <=4.7.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-35572 is medium with a CVSS score of 6.1.
Adminer versions prior to 4.7.9 are affected by CVE-2020-35572.
Users of Adminer versions using browsers that do not encode URL parameters before sending to the server are affected by CVE-2020-35572. This vulnerability is likely to affect users of Edge, but not Chrome or Firefox.
CVE-2020-35572 can be patched by updating to Adminer version 4.7.9 or later.
The Common Weakness Enumeration (CWE) for CVE-2020-35572 is CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').