VDB
Sign up
MEDIUM

GHSA-f339-246p-wwjp

FroshAdminer Adminer UI is accessible without admin session

Quick fix

GHSA-f339-246p-wwjp — frosh/adminer-platform: upgrade to the fixed version with the command below.

composer require frosh/adminer-platform:^2.2.1

Details

### Summary Unauthenticated access to Adminer UI

### Details The Adminer route (/admin/adminer) was accessible without Shopware admin authentication. The route was configured with auth_required=false and performed no session validation, exposing the Adminer UI to unauthenticated users.

Note: Database access itself requires credentials that are only set through the ACL-protected API endpoint. Direct database access without prior admin login is not possible through this vulnerability alone.

### Impact An unauthenticated user could access the Adminer interface, potentially disclosing version information or exploiting Adminer-specific vulnerabilities.

### Patches Version 2.2.1 adds session validation. The Adminer route now verifies an authenticated session flag before rendering — returning HTTP 403 otherwise.

### Workarounds Deactivate or uninstall the plugin.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/frosh/adminer-platform
Introduced in: 0Fixed in: 2.2.1
Fixcomposer require frosh/adminer-platform:^2.2.1

References