Today > 1 Critical | 2 Medium vulnerabilities   -   You can now download lists of IOCs here!

CVE-2023-45196

June 24, 2024, 9:15 p.m.

Product(s) Impacted

AdminerEvo

  • 4.8.4

Description

Adminer and AdminerEvo allow an unauthenticated remote attacker to cause a denial of service by connecting to an attacker-controlled service that responds with HTTP redirects. The denial of service is subject to PHP configuration limits. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.4.

Weaknesses

CWE-400
Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

CWE ID: 400

Date

Published: June 24, 2024, 9:15 p.m.

Last Modified: June 24, 2024, 9:15 p.m.

Status : Received

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

9119a7d8-5eab-497f-8521-727c672e3725

References

https://github.com/ 9119a7d8-5eab-497f-8521-727c672e3725