CVE-2021-47853
phpPgAdmin 7.13.0 contains a remote command execution vulnerability that allows authenticated attackers to execute arbitrary system commands through SQL query manipulation. Attackers can create a custom table, upload a malicious .txt file, and use the COPY FROM PROGRAM command to execute operating system commands with the application's privileges.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2021-47853, https://github.com/phppgadmin/phppgadmin, https://github.com/phppgadmin/phppgadmin/releases, https://www.exploit-db.com/exploits/49736, https://www.vulncheck.com/advisories/phppgadmin-copy-from-program-command-execution
