CVE-2023-45195

MEDIUM

AdminerEvo < 4.8.4 - Unauthenticated Server-Side Request Forgery via Database Connection Fields

Title source: llm
STIX 2.1

Description

Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an unauthenticated remote attacker to enumerate or access systems the attacker would not otherwise have access to. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.4.

Scores

CVSS v3 5.3
EPSS 0.0042
EPSS Percentile 33.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
adminerevo/adminerevo < 4.8.4
Published Jun 24, 2024
Tracked Since Feb 18, 2026