{"id":"CVE-2021-47853","aliases":[],"url":"https://o3.security/vulnerability/CVE-2021-47853","summary":"phpPgAdmin contains a remote command execution vulnerability","details":"phpPgAdmin 7.13.0 contains a remote command execution vulnerability that allows authenticated attackers to execute arbitrary system commands through SQL query manipulation. Attackers can create a custom table, upload a malicious .txt file, and use the COPY FROM PROGRAM command to execute operating system commands with the application's privileges.","published":"2026-01-21T18:30:31Z","modified":"2026-02-03T17:51:55.775432Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"phppgadmin/phppgadmin","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-47853"},{"type":"PACKAGE","url":"https://github.com/phppgadmin/phppgadmin"},{"type":"WEB","url":"https://github.com/phppgadmin/phppgadmin/releases"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/49736"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/phppgadmin-copy-from-program-command-execution"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-03T17:51:55.775432Z"}}