vrana/adminer is vulnerable to Cross-Site Scripting (XSS)
61
Medium Risk
Adminer inserts the connected database server's version string into an inline script tag that already carries a valid Content-Security-Policy nonce, without sanitizing it. A database server whose reported version does not match the expected numeric shape passes through unchanged. A payload can be passed, leading to execution of arbitrary script in the user's browser. Because the script tag has a valid nonce, the Content-Security-Policy does not block execution, and a login form without a token allows the connection to be forced cross-site. The fix validates the server version string before it is emitted.
You are affected if you are using a version that falls within the vulnerable range and a user logs in to a database server whose reported version string is externally controlled.
vrana/adminer is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 5.4.2.
Upgrade the vrana/adminer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant