Candidate: CVE-2020-35572 PublicDate: 2021-02-09 18:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35572 https://sourceforge.net/p/adminer/bugs-and-features/775/ https://sourceforge.net/p/adminer/news/ Description: Adminer through 4.7.8 allows XSS via the history parameter to the default URI. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_adminer: upstream: https://github.com/vrana/adminer/commit/5c395afc098e501be3417017c6421968aac477bd upstream_adminer: released (4.7.9) precise/esm_adminer: DNE trusty_adminer: ignored (out of standard support) trusty/esm_adminer: DNE xenial_adminer: ignored (end of standard support, was needed) bionic_adminer: needed focal_adminer: needed groovy_adminer: ignored (reached end-of-life) hirsute_adminer: ignored (reached end-of-life) impish_adminer: not-affected (4.7.9-2) jammy_adminer: not-affected (4.8.1-1) devel_adminer: not-affected (4.8.1-1)