MEDIUM
vrana
CVE published 2026-08-25
CVE-2026-34959
Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER[REQUEST_URI] with no trusted-proxy check and no validation of the prefix value. This enables an authenticated open redirect after state-changing POSTs, unauthenticated control of the session cookie path attribute, and poisoning of self-referential links. The vulnerability has a CVSS score of 5.3 and a severity of [truncated]