CISA Known Exploited Vulnerability

CVE-2021-21311

Adminer · Adminer

Adminer Server-Side Request Forgery Vulnerability

Date added
BOD 22-01 due date
CWE CWE-918
Ransomware Unknown

CISA description

Adminer contains a server-side request forgery vulnerability that, when exploited, allows a remote attacker to obtain potentially sensitive information.

Required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.