USN-5271-1

    Dashboard / Vulnerabilities / USN-5271-1

    USN-5271-1

    Published: 3 Jun 2022Last Modified: 25 Jun 2026

    Summary: adminer vulnerabilities

    Details: It was discovered that Adminer did not escape data in the history parameter of the default URI. A remote attacker could possibly use this issue to perform cross-site scripting (XSS) attacks. This issue only affected Ubuntu 20.04 ESM. (CVE-2020-35572) Adam Crosser and Brian Sizemore discovered that Adminer incorrectly handled redirection requests to internal servers. An unauthenticated remote attacker could possibly use this to perform a server-side request forgery attack and expose sensitive information. (CVE-2021-21311) It was discovered that Adminer was incorrectly escaping data in the doc_link function. A remote attacker could possibly use this issue to perform cross-site scripting (XSS) attacks. This issue only affected Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2021-29625)

    Affected packages

    Package

    Name: adminer

    Purl: pkg:deb/ubuntu/adminer?arch=source&distro=esm-apps%2Fxenial

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.2.1-1ubuntu1+esm1

    Affected versions

    4.2.1-1
    4.2.1-1ubuntu1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    USN-5271-1 | CVE-DB