Users of Adminer versions supporting SQL command (most versions, e.g. MySQL) using browsers not encoding URL parameters before sending to server (likely Edge, not Chrome, not Firefox) are affected.
Patched by 5c395afc, included in version 4.7.9.
Use browser which encodes URL parameters (e.g. Chrome or Firefox).
https://sourceforge.net/p/adminer/bugs-and-features/775/
If you have any questions or comments about this advisory: * Comment at https://sourceforge.net/p/adminer/bugs-and-features/775/
{ "nvd_published_at": "2021-02-09T18:15:00Z", "cwe_ids": [ "CWE-79" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2021-02-11T20:39:01Z" }