CVE-2024-9014
CRITICAL EXPLOITED NUCLEIPgadmin 4 < 8.12 - Insufficiently Protected Credentials
Title source: ruleDescription
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.
Exploits (2)
Nuclei Templates (1)
pgAdmin 4 - Authentication Bypass
CRITICALVERIFIEDby s4e-io
FOFA:
pgadmin4
Scores
CVSS v3
9.9
EPSS
0.9288
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitation Intel
VulnCheck KEV
2024-10-07
Classification
CWE
CWE-522
Status
published
Affected Products (2)
pgadmin/pgadmin_4
< 8.12
pypi/pgadmin4
< 8.12PyPI
Timeline
Published
Sep 23, 2024
Tracked Since
Feb 18, 2026