¡¾Îó²îͨ¸æ¡¿pgAdmin 4 Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î(CVE-2025-13780)
Ðû²¼Ê±¼ä 2025-12-17Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | pgAdmin 4 Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-13780 | ||
Îó²îÀàÐÍ | RCE | ·¢Ã÷ʱ¼ä | 2025-12-17 |
Îó²îÆÀ·Ö | 9.1 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
pgAdminÊÇÒ»¸öÓÃÓÚÖÎÀíºÍ¿ª·¢PostgreSQLÊý¾Ý¿âµÄ¿ªÔ´Í¼Ðλ¯¹¤¾ß¡£¡£¡£ËüÌṩÁËÒ»¸öÓû§ÓѺõĽçÃæ£¬£¬ÓÃÓÚÖ´ÐÐSQLÅÌÎÊ¡¢ÖÎÀíÊý¾Ý¿â¹¤¾ß¡¢Éó²éÊý¾Ý¿â¹¤¾ßµÄ½á¹¹¡¢ÌìÉú±¨±íºÍ±¸·Ý/»Ö¸´Êý¾Ý¿âµÈ²Ù×÷¡£¡£¡£pgAdminÖ§³Ö¶àÖÖ²Ù×÷ϵͳ£¬£¬°üÀ¨Windows¡¢macOSºÍLinux£¬£¬²¢ÇÒ¿ÉÒÔͨ¹ýWebä¯ÀÀÆ÷»á¼û£¬£¬±ãÓÚÔ¶³ÌÖÎÀí¡£¡£¡£ËüÆÕ±éÓ¦ÓÃÓÚÊý¾Ý¿âÖÎÀíÔ±¡¢¿ª·¢Ö°Ô±ºÍÊý¾ÝÆÊÎöʦÖУ¬£¬Ö§³ÖPostgreSQLµÄËùÓй¦Ð§²¢¼ò»¯ÁËÊý¾Ý¿âÖÎÀíʹÃü¡£¡£¡£
2025Äê12ÔÂ17ÈÕ£¬£¬ÈËÉú¾ÍÊDz©¼¯ÍÅVSRC¼à²âµ½pgAdmin 4ÖеÄÒ»¸öÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£¸ÃÎó²î·ºÆðÔÚPLAIN»Ö¸´ÔªÏÂÁî¹ýÂËÆ÷ÖУ¬£¬¸Ã¹ýÂËÆ÷ÊÇΪÐÞ¸´CVE-2025-12762¶øÒýÈëµÄ¡£¡£¡£¸Ã¹ýÂËÆ÷δÄÜ׼ȷʶ±ðÒÔUTF-8×Ö½Ú˳Ðò±ê¼Ç£¨EF BB BF£©»òÆäËûÌØÊâ×Ö½ÚÐòÁпªÍ·µÄSQLÎļþÖеÄÔªÏÂÁî¡£¡£¡£¹ýÂËÆ÷ʹÓõÄhas_meta_commands()º¯Êýͨ¹ýÕýÔò±í´ïʽɨÃèÔʼ×Ö½Ú£¬£¬µ«Î´Äܽ«ÕâЩ×Ö½ÚÊÓΪ¿ÉºöÂÔ£¬£¬´Ó¶øµ¼ÖÂÔªÏÂÁÈç\\!£©Î´±»¼ì²âµ½¡£¡£¡£µ±pgAdminͨ¹ýpsql fileÏÂÁîŲÓÃSQLÎļþʱ£¬£¬psql»áÈ¥³ýÕâЩ×Ö½Ú²¢Ö´ÐÐÆäÖеÄÏÂÁ£¬´Ó¶ø¿ÉÄܵ¼ÖÂÔ¶³ÌÏÂÁîÖ´ÐС£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
pgAdmin 4 < 9.11
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/pgadmin-org/pgadmin4/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ