vrana/adminer is vulnerable to Cross-Site Request Forgery (CSRF)
68
Medium Risk
Adminer's anti-CSRF token transmits both the random mask and the masked value, so anyone who observes a single token can recover the session secret with one XOR operation and forge valid tokens. The underlying session token is generated from a small random range and the verification uses a loose comparison, further weakening the protection. With a forged token, externally hosted pages can drive authenticated requests that run arbitrary SQL through the victim's session. The fix additionally checks the Sec-Fetch-Site request header to gate state-changing requests.
You are affected if you are using a version that falls within the vulnerable range.
vrana/adminer is vulnerable to Cross-Site Request Forgery (CSRF) in versions 0.0.1 - 5.4.2.
Upgrade the vrana/adminer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant