Beveiligingsadvies

CVE-2026-56702

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-25 01:30:00
Laatst bijgewerkt 2026-08-27 14:36:04
Toegewezen door VulnCheck
CVSS-score 8.8
Status PUBLISHED

Beschrijving

Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in _path and execute arbitrary code as the web-server user when uploadPath is web-served.