Admidio

Admidio

46 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 07.05.2026 04:16:29
  • Zuletzt bearbeitet 07.05.2026 16:16:20

Admidio is an open-source user management solution. Prior to version 5.0.9, an unauthenticated attacker can execute arbitrary JavaScript in any Admidio user's browser through a reflected XSS in system/msg_window.php. The endpoint passes user input th...

  • EPSS 0.32%
  • Veröffentlicht 07.05.2026 04:16:28
  • Zuletzt bearbeitet 07.05.2026 14:51:01

Admidio is an open-source user management solution. Prior to version 5.0.9, the contacts_data.php endpoint uses a weaker permission check (isAdministratorUsers(), requiring only rol_edit_user=true) than the frontend UI (contacts.php) which correctly ...

  • EPSS 0.36%
  • Veröffentlicht 07.05.2026 04:16:28
  • Zuletzt bearbeitet 07.05.2026 15:16:08

Admidio is an open-source user management solution. Prior to version 5.0.9, the add mode in modules/documents-files.php accepts a name parameter validated only as 'string' type (HTML encoding), allowing path traversal characters (../) to pass through...

  • EPSS 0.31%
  • Veröffentlicht 07.05.2026 04:16:28
  • Zuletzt bearbeitet 07.05.2026 16:16:20

Admidio is an open-source user management solution. Prior to version 5.0.9, the ecard_preview.php endpoint does not validate that the ecard_template POST parameter is a safe filename before passing it to ECard::getEcardTemplate(). An authenticated us...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 31.03.2026 20:34:37
  • Zuletzt bearbeitet 01.04.2026 18:31:30

Admidio is an open-source user management solution. Prior to version 5.0.8, the create_user, assign_member, and assign_user action modes in modules/registration.php approve pending user registrations via GET request without validating a CSRF token. U...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 31.03.2026 20:33:40
  • Zuletzt bearbeitet 01.04.2026 18:28:06

Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module's item_save endpoint accepts a user-controllable POST parameter imported that, when set to true, completely bypasses both CSRF token validation and serve...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 31.03.2026 20:32:35
  • Zuletzt bearbeitet 01.04.2026 18:25:24

Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, the delete mode handler in mylist_function.php permanently deletes list configurations without validating a CSRF token. An attacker who can lure an authen...

Exploit
  • EPSS 0.58%
  • Veröffentlicht 31.03.2026 20:31:23
  • Zuletzt bearbeitet 01.04.2026 18:24:07

Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, Admidio relies on adm_my_files/.htaccess to deny direct HTTP access to uploaded documents. The Docker image ships with AllowOverride None in the Apache co...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 20.03.2026 02:16:35
  • Zuletzt bearbeitet 23.03.2026 13:16:30

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the documents and files module does not verify whether the current user has permission to delete folders or files. The folder_delete and file_delete action handlers ...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 20.03.2026 02:16:35
  • Zuletzt bearbeitet 23.03.2026 15:25:42

Admidio is an open-source user management solution. Versions 5.0.6 and below are vulnerable to arbitrary SQL Injection through the MyList configuration feature. The MyList configuration feature lets authenticated users define custom list column layou...