Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
High
CVE-2024-2044
Disclosure Date: March 07, 2024 (last updated February 14, 2025)
pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize remote pickle objects and gain code execution. If the server is running on POSIX/Linux, an authenticated attacker can upload pickle objects, deserialize them, and gain code execution.
2
Attacker Value
Low
CVE-2024-4215
Disclosure Date: May 02, 2024 (last updated February 14, 2025)
pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker with knowledge of a legitimate account’s username and password may authenticate to the application and perform sensitive actions within the application, such as managing files and executing SQL queries, regardless of the account’s MFA enrollment status.
1
Attacker Value
Unknown
CVE-2024-9014
Disclosure Date: September 23, 2024 (last updated September 24, 2024)
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.
0
Attacker Value
Unknown
CVE-2024-6238
Disclosure Date: June 25, 2024 (last updated June 26, 2024)
pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers can gain unauthorised access to the installation directory on the Debian or RHEL 8 platforms.
0
Attacker Value
Unknown
CVE-2024-4216
Disclosure Date: May 02, 2024 (last updated February 14, 2025)
pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.
0
Attacker Value
Unknown
CVE-2023-0241
Disclosure Date: March 27, 2023 (last updated October 08, 2023)
pgAdmin 4 versions prior to v6.19 contains a directory traversal vulnerability. A user of the product may change another user's settings or alter the database.
0
Attacker Value
Unknown
CVE-2022-0959
Disclosure Date: March 16, 2022 (last updated October 07, 2023)
A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and session cookie to manually upload files to any location that the operating system user account under which pgAdmin is running has permission to write.
0
Attacker Value
Unknown
CVE-2011-3598
Disclosure Date: October 08, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in phpPgAdmin before 5.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) a web page title, related to classes/Misc.php; or the (2) return_url or (3) return_desc parameter to display.php.
0
Attacker Value
Unknown
CVE-2008-5587
Disclosure Date: December 16, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the _language parameter to index.php.
0
Attacker Value
Unknown
CVE-2007-5728
Disclosure Date: October 30, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inject arbitrary web script or HTML via certain input available in PHP_SELF in (1) redirect.php, possibly related to (2) login.php, different vectors than CVE-2007-2865.
0