Admidio

Admidio

32 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.01%
  • Veröffentlicht 31.03.2026 20:34:37
  • Zuletzt bearbeitet 01.04.2026 18:31:30

Admidio is an open-source user management solution. Prior to version 5.0.8, the create_user, assign_member, and assign_user action modes in modules/registration.php approve pending user registrations via GET request without validating a CSRF token. U...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 31.03.2026 20:33:40
  • Zuletzt bearbeitet 01.04.2026 18:28:06

Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module's item_save endpoint accepts a user-controllable POST parameter imported that, when set to true, completely bypasses both CSRF token validation and serve...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 31.03.2026 20:32:35
  • Zuletzt bearbeitet 01.04.2026 18:25:24

Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, the delete mode handler in mylist_function.php permanently deletes list configurations without validating a CSRF token. An attacker who can lure an authen...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 31.03.2026 20:31:23
  • Zuletzt bearbeitet 01.04.2026 18:24:07

Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, Admidio relies on adm_my_files/.htaccess to deny direct HTTP access to uploaded documents. The Docker image ships with AllowOverride None in the Apache co...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 20.03.2026 02:16:35
  • Zuletzt bearbeitet 23.03.2026 13:16:30

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the documents and files module does not verify whether the current user has permission to delete folders or files. The folder_delete and file_delete action handlers ...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 20.03.2026 02:16:35
  • Zuletzt bearbeitet 23.03.2026 15:25:42

Admidio is an open-source user management solution. Versions 5.0.6 and below are vulnerable to arbitrary SQL Injection through the MyList configuration feature. The MyList configuration feature lets authenticated users define custom list column layou...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 20.03.2026 02:16:35
  • Zuletzt bearbeitet 23.03.2026 15:24:40

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, unrestricted URL fetch in the SSO Metadata API can result in SSRF and local file reads. The SSO Metadata fetch endpoint at modules/sso/fetch_metadata.php accepts an ...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 19.03.2026 23:12:37
  • Zuletzt bearbeitet 23.03.2026 16:52:29

Admidio is an open-source user management solution. In versions 5.0.6 and below, the eCard send handler uses a raw $_POST['ecard_message'] value instead of the HTMLPurifier-sanitized $formValues['ecard_message'] when constructing the greeting card HT...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 19.03.2026 23:08:03
  • Zuletzt bearbeitet 23.03.2026 16:51:44

Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload vulnerability in the Documents & Files module. Due to a design flaw in how CSRF token validation and file extension verification ...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 19.03.2026 23:00:40
  • Zuletzt bearbeitet 23.03.2026 18:47:49

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the forum module in Admidio does not verify whether the current user has permission to delete forum topics or posts. Both the topic_delete and post_delete actions in...