pgAdmin.Import.Servers.Path.Traversal
Description
This indicates an attack attempt to exploit a Directory Traversal Vulnerability in pgAdmin pgAdmin.
The vulnerability is due to insufficient input validation of the filename when processing servers import. A remote attacker can exploit this vulnerability by sending a crafted request to the vulnerable server. Successful exploitation would result in sensitive information disclosure or policy bypass.
Affected Products
pgAdmin pgAdmin prior to 6.19
Impact
Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://github.com/advisories/GHSA-9crj-hpxh-f6qg
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2024-07-25 | 28.833 | Name:pgAdmin. Import. Servers. Directory. Traversal:pgAdmin. Import. Servers. Path. Traversal |
2023-06-27 | 24.590 | Default_action:pass:drop |
2023-05-11 | 23.552 |