{"id":"GHSA-m56g-3g8v-2rxw","summary":"XSS in Adminer","details":"**Withdrawn:** Duplicate of GHSA-9pgx-gcph-mpqr.\n\nAdminer before 4.7.9 allows XSS via the history parameter to the default URI.","modified":"2024-12-02T05:44:57.021282Z","published":"2021-02-11T20:46:53Z","withdrawn":"2021-02-11T20:36:42Z","database_specific":{"github_reviewed_at":"2021-02-10T18:26:24Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-35572"},{"type":"WEB","url":"https://github.com/vrana/adminer/commit/5c395afc098e501be3417017c6421968aac477bd"},{"type":"WEB","url":"https://github.com/vrana/adminer"},{"type":"WEB","url":"https://sourceforge.net/p/adminer/bugs-and-features/775"},{"type":"WEB","url":"https://sourceforge.net/p/adminer/news"},{"type":"WEB","url":"https://sourceforge.net/p/adminer/news/2021/02/adminer-479-released"}],"affected":[{"package":{"name":"vrana/adminer","ecosystem":"Packagist","purl":"pkg:composer/vrana/adminer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.7.9"}]}],"versions":["v4.2.0","v4.2.1","v4.2.2","v4.2.3","v4.2.4","v4.2.5","v4.3.0","v4.3.1","v4.4.0","v4.5.0","v4.6.0","v4.6.1","v4.6.2","v4.6.3","v4.7.0","v4.7.1","v4.7.2","v4.7.3","v4.7.4","v4.7.5","v4.7.6","v4.7.7","v4.7.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-m56g-3g8v-2rxw/GHSA-m56g-3g8v-2rxw.json"}}],"schema_version":"1.9.0"}