Register for the AI for Security Summit: Join Figma, Perplexity & Wiz
Vulnerability DatabaseGHSA-97h7-mf38-g9mf

GHSA-97h7-mf38-g9mf
PHP vulnerability analysis and mitigation

Overview

Adminer, a popular PHP tool for MySQL and PostgreSQL database administration, contained a file disclosure vulnerability affecting versions 4.3.1 through 4.6.2. The vulnerability was discovered in June 2018 and allows attackers to access arbitrary files on systems running vulnerable versions of Adminer (GitHub Advisory, Sansec Research).

Technical details

The vulnerability stems from a protocol flaw in MySQL that could be exploited through Adminer's external connection feature. The issue has been assigned a CVSS v3.1 score of 7.5 (High), with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. The vulnerability is tracked as CWE-200, indicating an information disclosure issue (GitHub Advisory).

Impact

When exploited, this vulnerability allows attackers to fetch sensitive files from the victim's system, including configuration files containing database credentials for popular applications like Magento and WordPress. Once obtained, these credentials can be used to gain unauthorized access to the site's database, potentially leading to data theft or malicious code injection (Sansec Research).

Exploitability

The exploitation occurs in three stages: first, attackers set up a modified MySQL server designed to send data import requests to connecting clients; second, they locate an accessible adminer.php file on the target system; and finally, they use the obtained credentials to access the victim's database. Multiple Magecart factions were observed exploiting this vulnerability in the wild since October 2018, suggesting that the modified MySQL server exploit may have been available on the dark web (Sansec Research).

Mitigation and workarounds

The vulnerability was patched in Adminer version 4.6.3, released in June 2018. Users are strongly advised to upgrade to version 4.7.0 or later. Additionally, it is recommended to protect database tools with additional password protection and/or IP filtering to prevent unauthorized access (Sansec Research, GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71537MEDIUM6.5
  • PHP logoPHP
  • paymenter/paymenter
NoYesSep 18, 2026
CVE-2026-77616MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77610MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77609MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026
CVE-2026-77608MEDIUM6.1
  • PHP logoPHP
  • mediawiki/semantic-media-wiki
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management