Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38460
HistoryDec 14, 2022 - 2:27 a.m.

Remote Code Execution (RCE)

2022-12-1402:27:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
remote code execution
pgadmin
binary path validation
malicious query parameters
vulnerability

0.016 Low

EPSS

Percentile

87.4%

pgadmin4 is vulnerable to remote code execution. The vulnerability exists in validate_binary_path() function of __init__.py due to lack of validation of the binary path which allows an attacker to inject and execute malicious query parameters via the pgAdmin server.

0.016 Low

EPSS

Percentile

87.4%