Files
vulhub/adminer/CVE-2021-21311/README.zh-cn.md
Aaron 63285f61aa
Some checks failed
Vulhub Format Check and Lint / format-check (push) Has been cancelled
Vulhub Format Check and Lint / markdown-check (push) Has been cancelled
Vulhub Docker Image CI / longtime-images-test (push) Has been cancelled
Vulhub Docker Image CI / images-test (push) Has been cancelled
first commit
2025-09-06 16:08:15 +08:00

1.0 KiB
Raw Blame History

Adminer ElasticSearch 和 ClickHouse 错误页面SSRF漏洞CVE-2021-21311

Adminer是一个PHP编写的开源数据库管理工具支持MySQL、MariaDB、PostgreSQL、SQLite、MS SQL、Oracle、Elasticsearch、MongoDB等数据库。

在其4.0.0到4.7.9版本之间,连接 ElasticSearch 和 ClickHouse 数据库时存在一处服务端请求伪造漏洞SSRF

参考连接:

漏洞环境

执行如下命令启动一个安装了Adminer 4.7.8的PHP服务

docker compose up -d

服务启动后,在http://your-ip:8080即可查看到Adminer的登录页面。

漏洞复现

在Adminer登录页面选择ElasticSearch作为系统目标并在server字段填写example.com,点击登录即可看到example.com返回的400错误页面展示在页面中