vrana/adminer is vulnerable to Code Injection
72
High Risk
Adminer's SQLite filter blocks ATTACH and VACUUM INTO statements with a regex that only matches the keyword after Adminer's own notion of whitespace or comments, before the query reaches connection()->multi_query($q). A statement prefixed with a UTF-8 byte order mark (EF BB BF) does not match that regex, but SQLite strips the BOM and runs the statement anyway. An authenticated SQLite user can use ATTACH DATABASE to create a SQLite file at an arbitrary PHP writable path and embed PHP code in a table name, which runs when that path is requested through the web server. The fix adds a SQLite authorizer that rejects file writing ATTACH and VACUUM INTO operations regardless of a BOM prefix.
You are affected if you are using a version that falls within the vulnerable range and you grant an authenticated user SQLite access on a PHP process that can write files into a web served directory.
vrana/adminer is vulnerable to Code Injection in versions 4.2.0 - 6.1.0.
Upgrade the vrana/adminer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.