Threat Advisory

PostgreSQL Vulnerabilities Enable Attackers to Execute Code

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Two critical vulnerabilities have been identified in pgAdmin, an open-source administration tool for PostgreSQ. CVE-2024-4216 is a Cross-Site Scripting (XSS) flaw present allowing threat actors to execute malicious scripts on client browsers and potentially steal sensitive cookies. Exploiting this vulnerability involves crafting a malicious XSS payload that gets executed as a pop-up in the client browser. CVE-2024-4215 is a Multi-Factor Authentication (MFA) Bypass vulnerability enabling threat actors to bypass MFA protections after authenticating with a valid username and password, granting unauthorized access to manage files and execute SQL queries. Both vulnerabilities have been patched in pgAdmin and users are strongly advised to upgrade to mitigate the risk of exploitation by malicious actors.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Two critical vulnerabilities have been identified in pgAdmin, an open-source administration tool for PostgreSQ. CVE-2024-4216 is a Cross-Site Scripting (XSS) flaw present allowing threat actors to execute malicious scripts on client browsers and potentially steal sensitive cookies. Exploiting this vulnerability involves crafting a malicious XSS payload that gets executed as a pop-up in the client browser. CVE-2024-4215 is a Multi-Factor Authentication (MFA) Bypass vulnerability enabling threat actors to bypass MFA protections after authenticating with a valid username and password, granting unauthorized access to manage files and execute SQL queries. Both vulnerabilities have been patched in pgAdmin and users are strongly advised to upgrade to mitigate the risk of exploitation by malicious actors.[emaillocker id="1283"]

RECOMMENDATION:

  • We strongly recommend you update pgAdmin v4 to version 8.6

REFERENCES:

The following reports contain further technical details:

https://cybersecuritynews.com/pgadmin-security-flaws/

[/emaillocker]
crossmenu