¡¾·ì϶¹«¸æ¡¿pgAdmin 4 Ô¶³ÌºÅÁîÖ´Ðзì϶(CVE-2025-13780)
°ä²¼¹¦·ò 2025-12-17Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | pgAdmin 4 Ô¶³ÌºÅÁîÖ´Ðзì϶ | ||
CVE ID | CVE-2025-13780 | ||
·ì϶ÀàÐÍ | RCE | ·¢ÏÖ¹¦·ò | 2025-12-17 |
·ì϶ÆÀ·Ö | 9.1 | ·ì϶µÈ¼¶ | ÑϳÁ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
pgAdminÊÇÒ»¸öÓÃÓÚÖÎÀíºÍ¿ª·¢PostgreSQLÊý¾Ý¿âµÄ¿ªÔ´Í¼Ðλ¯¹¤¾ß¡£¡£¡£¡£¡£¡£ËüÌṩÁËÒ»¸öÓû§¶ØÄÀµÄ½çÃæ£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÖ´ÐÐSQL²éÎÊ¡¢ÖÎÀíÊý¾Ý¿â¶ÔÏ󡢲鿴Êý¾Ý¿â¶ÔÏóµÄ½á¹¹¡¢ÌìÉú±¨±íºÍ±¸·Ý/¸´ÔÊý¾Ý¿âµÈ²Ù×÷¡£¡£¡£¡£¡£¡£pgAdminÖ§³Ö¶àÖÖ²Ù×÷ϵͳ£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬Windows¡¢macOSºÍLinux£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÄܹ»Í¨¹ýWebä¯ÀÀÆ÷½Ó¼û£¬£¬£¬£¬£¬£¬£¬£¬±ãÓÚÔ¶³ÌÖÎÀí¡£¡£¡£¡£¡£¡£Ëü¿í·ºÀûÓÃÓÚÊý¾Ý¿âÖÎÀíÔ±¡¢¿ª·¢ÈËÔ±ºÍÊý¾Ý·ÖÎöʦÖУ¬£¬£¬£¬£¬£¬£¬£¬Ö§³ÖPostgreSQLµÄËùÓÐÖ°Äܲ¢¼ò»¯ÁËÊý¾Ý¿âÖÎÀí¹¤×÷¡£¡£¡£¡£¡£¡£
2025Äê12ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯Íż¯ÍÅVSRC¼à²âµ½pgAdmin 4ÖеÄÒ»¸öÔ¶³ÌºÅÁîÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¸Ã·ì϶³Ê´Ë¿ÌPLAIN¸´ÔÔªºÅÁî¹ýÂËÆ÷ÖУ¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹ýÂËÆ÷ÊÇΪ½¨¸´CVE-2025-12762¶øÒýÈëµÄ¡£¡£¡£¡£¡£¡£¸Ã¹ýÂËÆ÷δÄÜÕýÈ·¼ø±ðÒÔUTF-8×Ö½Ú°¤´ÎÏóÕ÷£¨EF BB BF£©»òÆäËûÌØÊâ×Ö½ÚÐòÁпªÍ·µÄSQLÎļþÖеÄÔªºÅÁî¡£¡£¡£¡£¡£¡£¹ýÂËÆ÷ʹÓõÄhas_meta_commands()º¯Êýͨ¹ýÕýÔò±í°×ʽɨÃèÔʼ×Ö½Ú£¬£¬£¬£¬£¬£¬£¬£¬µ«Î´Äܽ«ÕâЩ×Ö½ÚÊÓΪ¿ÉºöÂÔ£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÔªºÅÁÈç\\!£©Î´±»¼ì²âµ½¡£¡£¡£¡£¡£¡£µ±pgAdminͨ¹ýpsql fileºÅÁîŲÓÃSQLÎļþʱ£¬£¬£¬£¬£¬£¬£¬£¬psql»áÈ¥³ýÕâЩ×Ö½Ú²¢Ö´ÐÐÆäÖеĺÅÁ£¬£¬£¬£¬£¬£¬£¬´Ó¶ø¿ÉÄܵ¼ÖÂÔ¶³ÌºÅÁîÖ´ÐС£¡£¡£¡£¡£¡£
¶þ¡¢Ó°ÏìÁìÓò
pgAdmin 4 < 9.11
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/pgadmin-org/pgadmin4/
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£¡£¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ