CVE-2021-47853

Severity CVSS v4.0:
HIGH
Type:
CWE-78 OS Command Injections
Publication date:
21/01/2026
Last modified:
21/01/2026

Description

phpPgAdmin 7.13.0 contains a remote command execution vulnerability that allows authenticated attackers to execute arbitrary system commands through SQL query manipulation. Attackers can create a custom table, upload a malicious .txt file, and use the COPY FROM PROGRAM command to execute operating system commands with the application's privileges.