Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database.
https://lists.debian.org/debian-lts-announce/2022/05/msg00012.html
https://github.com/vrana/adminer/releases/tag/v4.6.3
https://www.adminer.org/
https://sansec.io/research/adminer-4.6.2-file-disclosure-vulnerability
https://podalirius.net/en/cves/2021-43008/
Source: Mitre, NVD
Published: 2022-04-05
Updated: 2024-11-21
Named Vulnerability: Adminer Local File Inclusion
Base Score: 5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N
Severity: Medium
Base Score: 7.5
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity: High
EPSS: 0.85512