S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-21311 Scanner

CVE-2021-21311 scanner - Server-Side Request Forgery (SSRF) vulnerability in Adminer (open source project)

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-21311
7.2
CVSShigh
Exploitable remotely over the internet · no authentication required.

Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
adminerby vrana
>= 4.0.0, < 4.7.9
Updated Aug 21, 2026View on NVD →
Detail

Adminer is an open-source single PHP file that is used for database management. This software is very popular among developers due to its simplicity and ease of use. Users of Adminer can easily manage their databases with just a few clicks. Adminer supports almost all major databases like MySQL, PostgreSQL, Oracle, SQLite, and MS SQL. Adminer can also be used to edit tables, create and delete columns, indexes, and entire tables. Additionally, users can also manage events, triggers, and views. In short, Adminer is an all-in-one solution for database management.

CVE-2021-21311 is a vulnerability found in Adminer versions from 4.0.0 to 4.7.8. This vulnerability is related to server-side request forgery (SSRF). SSRF enables hackers to send requests from the server-side to third-party websites. By exploiting this vulnerability, attackers can use the server to send malicious requests to different websites. These requests may include sensitive information such as passwords or may cause damage to the target website.

Exploiting this vulnerability can lead to serious security issues. If a hacker can send malicious requests to a third-party website using the server, they could potentially steal sensitive information, cause website crashes, or perform other malicious activities. The primary risk of this vulnerability is that it could lead to the website's total downtime or data leakage.

In conclusion, it is critical to be aware of security vulnerabilities and take proactive measures to ensure the security of your digital assets. As an added benefit, s4e.io provides pro features to help you identify vulnerabilities in your digital assets, making it easy for you to take additional steps towards increasing your security posture. By keeping your systems and applications up-to-date and staying informed of the latest vulnerabilities, you can ensure the security and safety of your digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can follow these precautions:

  • Update Adminer to the latest version, which addresses the vulnerability.
  • Keep all software (including the server operating system and database software) up-to-date to avoid any unpatched vulnerabilities.
  • Regularly scan the server logs for any unusual requests or activities.
  • Use a web application firewall to detect and block malicious requests.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.