{"id":"GHSA-2v82-5746-vwqc","summary":"XSS in doc_link","details":"### Impact\nUsers of MySQL, MariaDB, PgSQL and SQLite are affected. XSS is in most cases prevented by strict CSP in all modern browsers. The only exception is when Adminer is using a `pdo_` extension to communicate with the database (it is used if the native extensions are not enabled). In browsers without CSP, Adminer versions 4.6.1 to 4.8.0 are affected.\n\n### Patches\nPatched by 4043092, included in version [4.8.1](https://github.com/vrana/adminer/releases/tag/v4.8.1).\n\n### Workarounds\nDo both:\n* Use browser supporting strict CSP.\n* Enable the native PHP extensions (e.g. `mysqli`) or disable displaying PHP errors (`display_errors`).\n\n### References\nhttps://sourceforge.net/p/adminer/bugs-and-features/797/\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Comment at 4043092.\n","aliases":["CVE-2021-29625"],"modified":"2026-05-07T05:02:48.814590837Z","published":"2022-03-18T17:49:28Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-05-17T19:18:12Z","nvd_published_at":"2021-05-19T22:15:00Z"},"references":[{"type":"WEB","url":"https://github.com/vrana/adminer/security/advisories/GHSA-2v82-5746-vwqc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-29625"},{"type":"WEB","url":"https://github.com/vrana/adminer/commit/4043092ec2c0de2258d60a99d0c5958637d051a7"},{"type":"WEB","url":"https://packagist.org/packages/vrana/adminer"},{"type":"WEB","url":"https://sourceforge.net/p/adminer/bugs-and-features/797"}],"affected":[{"package":{"name":"vrana/adminer","ecosystem":"Packagist","purl":"pkg:composer/vrana/adminer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.7.8"},{"fixed":"4.8.1"}]}],"versions":["v4.7.8","v4.7.9","v4.8.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-2v82-5746-vwqc/GHSA-2v82-5746-vwqc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}