[CVE-2026-56702] Adminer versions before 5.4.3 contain an unrestricted file u

CVE-2026-56702 | CVSS: 8.8 | 严重级别: HIGH

Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in _path and execute arbitrary code as the web-server user when uploadPath is web-served.

参考链接:
https://github.com/vrana/adminer/security/advisories/GHSA-vcvj-rwwm-x6g5
https://www.vulncheck.com/advisories/adminer-before-unrestricted-file-upload-via

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部