github.com
https://github.com/vrana/adminer CVE-2020-35572
MEDIUM
vrana/adminer via XSS in the history parameter in SQL command
Record summary
CVE-2020-35572 has a selected CVSS score of 6.1 (medium).
Description
Adminer through 4.7.8 allows XSS via the history parameter to the default URI.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
vrana/adminerBrowse Packagist / vrana/adminer | GitHub Advisory | Before 4.7.9 · Fixed in 4.7.9 | affected |
References
7github.com
https://github.com/vrana/adminer/commit/5c395afc098e501be3417017c6421968aac477bd github.com
https://github.com/vrana/adminer/security/advisories/GHSA-9pgx-gcph-mpqr nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-35572 sourceforge.net
https://sourceforge.net/p/adminer/bugs-and-features/775 sourceforge.net
https://sourceforge.net/p/adminer/news sourceforge.net
https://sourceforge.net/p/adminer/news/2021/02/adminer-479-released