VDB

GCVE-110-MAGEIA-2022-257

GCVE-110-MAGEIA-2022-257
Advisory Published
Vulnetix · Advisory published July 13, 2022
A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and session cookie to manually upload files to any location that the operating system user account under which pgAdmin is running has permission to write. (CVE-2022-0959) In addition, missing requires have been added, file and directory permissions have been corrected. Upstream update check disabled.

Affected Products

VendorProductVersionsPlatforms
Mageiapgadmin40 (affected), 4.30-5.mga8 (unaffected)

Browse GCVE Records

74,366 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›