CVE-2025-43960

Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory usage, rendering Adminer’s interface unresponsive and causing a server-level DoS. While the server may recover after several minutes, multiple simultaneous requests can cause a complete crash requiring manual intervention.
Configurations

Configuration 1 (hide)

cpe:2.3:a:adminer:adminer:4.8.1:*:*:*:*:*:*:*

History

12 Sep 2025, 20:16

Type Values Removed Values Added
Summary
  • (es) Adminer 4.8.1, al usar Monolog para el registro, permite una denegación de servicio (consumo de memoria) mediante una payload serializada manipulada(p. ej., usando s:1000000000), lo que provoca un problema de inyección de objetos PHP. Atacantes remotos no autenticados pueden desencadenar esto enviando un objeto serializado malicioso, lo que fuerza un uso excesivo de memoria, bloqueando la interfaz de Adminer y provocando un ataque de denegación de servicio (DoS) a nivel de servidor. Si bien el servidor puede recuperarse después de varios minutos, múltiples solicitudes simultáneas pueden provocar un bloqueo completo que requiera intervención manual.
First Time Adminer adminer
Adminer
References () https://github.com/Seldaek/monolog - () https://github.com/Seldaek/monolog - Product
References () https://github.com/far00t01/CVE-2025-43960 - () https://github.com/far00t01/CVE-2025-43960 - Exploit, Third Party Advisory
References () https://github.com/vrana/adminer/compare/v4.8.1...v4.8.2 - () https://github.com/vrana/adminer/compare/v4.8.1...v4.8.2 - Release Notes
References () https://www.adminer.org - () https://www.adminer.org - Product
CPE cpe:2.3:a:adminer:adminer:4.8.1:*:*:*:*:*:*:*

25 Aug 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-25 14:15

Updated : 2025-09-12 20:16


NVD link : CVE-2025-43960

Mitre link : CVE-2025-43960

CVE.ORG link : CVE-2025-43960


JSON object : View

Products Affected

adminer

  • adminer
CWE
CWE-502

Deserialization of Untrusted Data