hyp3rlinx.altervista.org
http://hyp3rlinx.altervista.org/advisories/ADMINER-UNAUTHENTICATED-SERVER-SIDE-REQUEST-FORGERY.txt CVE-2018-7667
CRITICAL
vrana/adminer vulnerable to SSRF by connecting to privileged ports
Record summary
CVE-2018-7667 has a selected CVSS score of 9.8 (critical).
Description
Adminer through 4.3.1 has SSRF via the server parameter.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
vrana/adminerBrowse Packagist / vrana/adminer | GitHub Advisory | Before 4.7.8 · Fixed in 4.7.8 | affected |
References
6github.com
https://github.com/vrana/adminer/commit/35bfaa75 github.com
https://github.com/vrana/adminer/security/advisories/GHSA-43f8-p5w3-5m25 gusralph.info
https://gusralph.info/adminer-ssrf-bypass-cve-2018-7667 [debian-lts-announce] 20180322 [SECURITY] [DLA 1311-1] adminer security updatemailing list
https://lists.debian.org/debian-lts-announce/2018/03/msg00014.html sourceforge.net
https://sourceforge.net/p/adminer/bugs-and-features/769