WF-7047d53e-c9e4-46f9-8b5f-3489a1fb7e97-pexlechris-adminer

Database Management tool – Adminer <= 1.1.5 - Information Exposure

mediumExposure of Sensitive Information to an Unauthorized Actor
6.8
CVSS Score
6.8
CVSS Score
medium
Severity
1.1.6
Patched in
525d
Time to patch

Description

The Database Management tool – Adminer plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.1.5. This is due to the fact that the database password was included in a GET request as one of the parameters. This could allow individuals with access to log files to extract sensitive user or configuration data.

CVSS Vector Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
High
Confidentiality
None
Integrity
None
Availability

Technical Details

Affected versions<=1.1.5
PublishedAugust 16, 2022
Last updatedJanuary 22, 2024
Affected pluginpexlechris-adminer

Check if your site is affected.

Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.