Critical 9.4 CVSS pgAdmin 4 Flaws Enable Full OS Command Execution
ID: 0207f0bc-a7a3-53f7-a2d8-3c70093d7c65
STIX ID: report--0207f0bc-a7a3-53f7-a2d8-3c70093d7c65
Feed Name: securityonline.info
Threat Score
pgAdmin released version 9.15 to fix multiple high-severity vulnerabilities affecting all versions prior to 9.15, including authorization bypasses, privilege escalation via writable passexec_cmd, SQL injection that can escalate to OS command execution (COPY … TO PROGRAM), unsafe session deserialization leading to RCE, SSRF via LLM API config, and path traversal in the File Manager; administrators are urged to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
