Vulnerability Description
Adminer and AdminerEvo allow an unauthenticated remote attacker to cause a denial of service by connecting to an attacker-controlled service that responds with HTTP redirects. The denial of service is subject to PHP configuration limits. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.4.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adminerevo | Adminerevo | < 4.8.4 |
Related Weaknesses (CWE)
References
- https://github.com/adminerevo/adminerevo/pull/102/commits/23e7cdc0a32b3739e13d19Patch
- https://github.com/adminerevo/adminerevo/pull/102/commits/23e7cdc0a32b3739e13d19Patch
FAQ
What is CVE-2023-45196?
CVE-2023-45196 is a vulnerability with a CVSS score of 7.5 (HIGH). Adminer and AdminerEvo allow an unauthenticated remote attacker to cause a denial of service by connecting to an attacker-controlled service that responds with HTTP redirects. The denial of service is...
How severe is CVE-2023-45196?
CVE-2023-45196 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-45196?
Check the references section above for vendor advisories and patch information. Affected products include: Adminerevo Adminerevo.