vrana/adminer is vulnerable to Path Traversal
81
High Risk
Adminer's SQLite database-list drop action passes submitted database names to unlink() without the extension validation applied to create and rename operations. An authenticated SQLite user with a valid request token can submit an arbitrary file path in the db[] field and delete any file writable by the PHP process. The submitted path is not bound to a known SQLite database, so files outside the intended directory can be removed. The fix validates the filename before deletion.
You are affected if you are using a version that falls within the vulnerable range and you expose the SQLite driver to users who can authenticate.
vrana/adminer is vulnerable to Path Traversal in versions 0.0.1 - 5.4.2.
Upgrade the vrana/adminer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant