vrana/adminer is vulnerable to Cookie Attribute Injection
69
Medium Risk
Adminer's bootstrap concatenates the client supplied X-Forwarded-Prefix header directly onto REQUEST_URI, and the cookie() helper embeds that unescaped value into the Set-Cookie path attribute. A semicolon in the header value injects extra cookie attributes such as Domain, Secure, and SameSite into the adminer_sid session and adminer_key database password cookies. Behind a reverse proxy or man-in-the-middle position, this widens the cookie scope to an untrusted domain so the cookies are sent there on later requests. The fix validates the header value before it reaches the cookie path attribute.
You are affected if you are using a version that falls within the vulnerable range and you run Adminer behind a reverse proxy or other component that forwards a client supplied X-Forwarded-Prefix header.
vrana/adminer is vulnerable to Cookie Attribute Injection in versions 4.6.0 - 5.4.2.
Upgrade the vrana/adminer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.