Intel

AIKIDO-2026-550849

vrana/adminer is vulnerable to Cookie Attribute Injection

Cookie Attribute InjectionGHSA-c533-9qwm-8w5h Published Yesterday

69

Medium Risk

This Affects:

PHPvrana/adminer
4.6.0 - 5.4.2
Fixed in 5.4.3
Are you affected? Scan for Free

TL;DR

Adminer's bootstrap concatenates the client supplied X-Forwarded-Prefix header directly onto REQUEST_URI, and the cookie() helper embeds that unescaped value into the Set-Cookie path attribute. A semicolon in the header value injects extra cookie attributes such as Domain, Secure, and SameSite into the adminer_sid session and adminer_key database password cookies. Behind a reverse proxy or man-in-the-middle position, this widens the cookie scope to an untrusted domain so the cookies are sent there on later requests. The fix validates the header value before it reaches the cookie path attribute.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you run Adminer behind a reverse proxy or other component that forwards a client supplied X-Forwarded-Prefix header.

Background info

vrana/adminer is vulnerable to Cookie Attribute Injection in versions 4.6.0 - 5.4.2.

How to fix this

Upgrade the vrana/adminer library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform