NA

CVE-2023-5002

Published: 22/09/2023 Updated: 07/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A flaw was found in pgAdmin. This issue occurs when the pgAdmin server HTTP API validates the path a user selects to external PostgreSQL utilities such as pg_dump and pg_restore. Versions of pgAdmin before 7.6 failed to properly control the server code executed on this API, allowing an authenticated user to run arbitrary commands on the server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pgadmin pgadmin

fedoraproject fedora 37

fedoraproject fedora 38