CVE-2018-25370
- EPSS 0.19%
- Veröffentlicht 25.05.2026 14:15:15
- Zuletzt bearbeitet 26.05.2026 19:47:48
Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their permissions by exploiting improper origin checking. Attackers can craft malicious HTML forms targeting roles_function.php with paramet...
CVE-2026-42194
- EPSS 0.24%
- Veröffentlicht 07.05.2026 04:16:34
- Zuletzt bearbeitet 07.05.2026 16:16:20
Admidio is an open-source user management solution. Prior to version 5.0.9, the incomplete SSRF fix in Admidio's fetch_metadata.php validates the resolved IP address but passes the original hostname-based URL to curl_init(), leaving a DNS rebinding T...
CVE-2026-41671
- EPSS 0.32%
- Veröffentlicht 07.05.2026 04:16:32
- Zuletzt bearbeitet 07.05.2026 14:54:40
Admidio is an open-source user management solution. Prior to version 5.0.9, the OIDC token introspection endpoint (/modules/sso/index.php/oidc/introspect) always returns {"active": true} for every request, regardless of whether a valid token is provi...
CVE-2026-41670
- EPSS 0.28%
- Veröffentlicht 07.05.2026 04:16:30
- Zuletzt bearbeitet 07.05.2026 15:16:08
Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO module uses the AssertionConsumerServiceURL value directly from incoming SAML AuthnRequest messages as the destination for the SA...
CVE-2026-41669
- EPSS 0.19%
- Veröffentlicht 07.05.2026 04:16:30
- Zuletzt bearbeitet 07.05.2026 15:16:08
Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio SAML Identity Provider implementation discards the return value of its validateSignature() method at both call sites (handleSSORequest() line 418 and handleSLOReq...
CVE-2026-41663
- EPSS 0.12%
- Veröffentlicht 07.05.2026 04:16:30
- Zuletzt bearbeitet 07.05.2026 14:51:01
Admidio is an open-source user management solution. Prior to version 5.0.9, several administrative operations in Admidio's preferences module (database backup, test email, htaccess generation) fire via GET requests with no CSRF token validation. Beca...
CVE-2026-41662
- EPSS 0.29%
- Veröffentlicht 07.05.2026 04:16:30
- Zuletzt bearbeitet 07.05.2026 15:16:08
Admidio is an open-source user management solution. Prior to version 5.0.9, Role::stopMembership() does not verify whether removing a user from the administrator role leaves zero administrators. The deprecated Membership::stopMembership() contains th...
CVE-2026-41658
- EPSS 0.23%
- Veröffentlicht 07.05.2026 04:16:29
- Zuletzt bearbeitet 07.05.2026 15:16:08
Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio inventory module enforces authorization for destructive operations (delete, retire, reinstate) only in the UI layer by conditionally rendering buttons. The backen...
CVE-2026-41659
- EPSS 0.26%
- Veröffentlicht 07.05.2026 04:16:29
- Zuletzt bearbeitet 07.05.2026 15:16:08
Admidio is an open-source user management solution. Prior to version 5.0.9, the member assignment DataTables endpoint (members_assignment_data.php) includes hidden profile fields (BIRTHDAY, STREET, CITY, POSTCODE, COUNTRY) in its SQL search condition...
CVE-2026-41660
- EPSS 0.3%
- Veröffentlicht 07.05.2026 04:16:29
- Zuletzt bearbeitet 07.05.2026 14:51:01
Admidio is an open-source user management solution. Prior to version 5.0.9, a logic error in Admidio's two-factor authentication reset inverts the authorization check. Non-admin users cannot remove their own TOTP configuration, but they can remove ot...