CVE-2022-0959

MEDIUM

Pgadmin 4 < 6.7 - Path Traversal

Title source: rule
STIX 2.1

Description

A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and session cookie to manually upload files to any location that the operating system user account under which pgAdmin is running has permission to write.

References (1)

Core 1
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=2063759

Scores

CVSS v3 6.5
EPSS 0.0052
EPSS Percentile 67.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-22 CWE-434
Status published
Products (2)
pgadmin/pgadmin_4 < 6.7
pypi/pgadmin4 0 - 6.7PyPI
Published Mar 16, 2022
Tracked Since Feb 18, 2026