CVE-2023-5002

MEDIUM

pgAdmin 4 < 7.7 - Authenticated OS Command Injection via External Utility Path Validation

Title source: llm
STIX 2.1

Description

A flaw was found in pgAdmin. This issue occurs when the pgAdmin server HTTP API validates the path a user selects to external PostgreSQL utilities such as pg_dump and pg_restore. Versions of pgAdmin prior to 7.6 failed to properly control the server code executed on this API, allowing an authenticated user to run arbitrary commands on the server.

Scores

CVSS v3 6.0
EPSS 0.2376
EPSS Percentile 96.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (4)
fedoraproject/fedora 37
fedoraproject/fedora 38
pgadmin/pgadmin_4 < 7.7
pypi/pgadmin4 0 - 7.7PyPI
Published Sep 22, 2023
Tracked Since Feb 18, 2026