GHSA-gx46-wch5-wp5pMediumCVSS 6.1
Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with...
🔗 CVE IDs covered (1)
📋 Description
Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafted version strings that break out of the JavaScript context and execute arbitrary code, bypassing Content Security Policy protections.