GHSA-gx46-wch5-wp5pMediumCVSS 6.1

Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with...

Published
August 25, 2026
Last Modified
August 25, 2026

🔗 CVE IDs covered (1)

📋 Description

Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafted version strings that break out of the JavaScript context and execute arbitrary code, bypassing Content Security Policy protections.

🔗 References (4)