vrana/adminer is vulnerable to Unrestricted File Upload
35
Low Risk
The bundled AdminerFileUpload plugin stores uploads for any column whose name ends in _path while preserving the uploader's original extension, and its default extension filter accepts any alphanumeric extension including php. An authenticated user, including a low-privilege editor, can upload a PHP file that is stored with an executable extension. When the upload directory is served as PHP this results in command execution. The fix hardens the default extension handling.
You are affected if you are using a version that falls within the vulnerable range and you enable the bundled AdminerFileUpload plugin with an upload directory that the web server executes as PHP.
vrana/adminer is vulnerable to Unrestricted File Upload in versions 0.0.1 - 5.4.2.
Upgrade the vrana/adminer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant