Description
Adminer is a tool for managing content in MySQL databases. Adminer is distributed under Apache license in a form of a single PHP file.
Adminer versions up to (and including) 4.6.2 supported the use of the SQL statement LOAD DATA INFILE. It was possible to use this SQL statement to read arbitrary local files because of a protocol flaw in MySQL.
Remediation
Upgrade to the latest version of Adminer. This vulnerability was fixed in Adminer version 4.6.3.
References
Related Vulnerabilities
WordPress Plugin Cryptocurrency Widgets-Price Ticker & Coins List Security Bypass (2.4)
Joomla Insufficient Session Expiration Vulnerability (CVE-2021-26037)
MySQL Insufficiently Protected Credentials Vulnerability (CVE-2012-5627)
XWiki Improper Handling of Exceptional Conditions Vulnerability (CVE-2023-26479)