{"id":"GHSA-9pgx-gcph-mpqr","summary":"vrana/adminer via XSS in the history parameter in SQL command","details":"### Impact\nUsers of Adminer versions supporting SQL command (most versions, e.g. MySQL) using browsers not encoding URL parameters before sending to server (likely Edge, not Chrome, not Firefox) are affected.\n\n### Patches\nPatched by 5c395afc, included in version [4.7.9](https://github.com/vrana/adminer/releases/tag/v4.7.9).\n\n### Workarounds\nUse browser which encodes URL parameters (e.g. Chrome or Firefox).\n\n### References\nhttps://sourceforge.net/p/adminer/bugs-and-features/775/\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Comment at https://sourceforge.net/p/adminer/bugs-and-features/775/\n","aliases":["CVE-2020-35572"],"modified":"2024-02-17T05:35:44.533996Z","published":"2021-02-11T20:42:28Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-02-11T20:39:01Z","nvd_published_at":"2021-02-09T18:15:00Z","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/vrana/adminer/security/advisories/GHSA-9pgx-gcph-mpqr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-35572"},{"type":"WEB","url":"https://github.com/vrana/adminer/commit/5c395afc098e501be3417017c6421968aac477bd"},{"type":"PACKAGE","url":"https://github.com/vrana/adminer"},{"type":"WEB","url":"https://sourceforge.net/p/adminer/bugs-and-features/775"},{"type":"WEB","url":"https://sourceforge.net/p/adminer/news/2021/02/adminer-479-released"}],"affected":[{"package":{"name":"vrana/adminer","ecosystem":"Packagist","purl":"pkg:composer/vrana/adminer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.7.9"}]}],"versions":["v4.2.0","v4.2.1","v4.2.2","v4.2.3","v4.2.4","v4.2.5","v4.3.0","v4.3.1","v4.4.0","v4.5.0","v4.6.0","v4.6.1","v4.6.2","v4.6.3","v4.7.0","v4.7.1","v4.7.2","v4.7.3","v4.7.4","v4.7.5","v4.7.6","v4.7.7","v4.7.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-9pgx-gcph-mpqr/GHSA-9pgx-gcph-mpqr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}