CRITICAL9.8
GHSA-x6mh-4w8x-p34v
MineAdmin has an insecure default password
Details
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/mineadmin/mineadmin
Introduced in:
0No fixed version published yet for mineadmin/mineadmin (composer). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-65854[ADVISORY]
- https://gist.github.com/SourByte05/1a6c6b08ac47c5d58eb7dd4422cc23b7[WEB]
- https://github.com/mineadmin/mine-core/blob/7994da7f5cd0778eb9aadd550c50c259cc1d1048/src/Command/InstallProjectCommand.php#L123[WEB]
- https://github.com/mineadmin/mineadmin[PACKAGE]
- http://mineadmin.com[WEB]