GHSA-x6mh-4w8x-p34v

Suggest an improvement
Source
https://github.com/advisories/GHSA-x6mh-4w8x-p34v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-x6mh-4w8x-p34v/GHSA-x6mh-4w8x-p34v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-x6mh-4w8x-p34v
Aliases
  • CVE-2025-65854
Published
2025-12-12T18:30:35Z
Modified
2025-12-12T22:41:15.284242Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
MineAdmin has an insecure default password
Details

Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover.

Database specific
{
    "github_reviewed": true,
    "github_reviewed_at": "2025-12-12T22:13:22Z",
    "nvd_published_at": "2025-12-12T16:15:44Z",
    "severity": "CRITICAL",
    "cwe_ids": [
        "CWE-94"
    ]
}
References

Affected packages

Packagist / mineadmin/mineadmin

Package

Name
mineadmin/mineadmin
Purl
pkg:composer/mineadmin/mineadmin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
3.0.9

Affected versions

v0.*

v0.6.2
v0.6.3
v0.7.0
v0.7.1
v0.7.2

v1.*

v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.3
v1.4.1
v1.4.11
v1.4.12
v1.4.13

v2.*

v2.0-stable
v2.0-RC.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.1
v2.0.1.1
v2.0.2
v2.0.3

2.*

2.0.0-alpha.1

v3.*

v3.0-RC
v3.0
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9