Beveiligingsadvies

CVE-2026-56704

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-25 01:30:02
Laatst bijgewerkt 2026-08-26 16:12:57
Toegewezen door VulnCheck
CVSS-score 6.1
Status PUBLISHED

Beschrijving

Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafted version strings that break out of the JavaScript context and execute arbitrary code, bypassing Content Security Policy protections.