Admidio

Admidio

60 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Veröffentlicht 03.08.2026 13:20:46
  • Zuletzt bearbeitet 03.08.2026 16:16:31

Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs persistent Category Report configuration changes based on GET parameters (delete and copy). An attacker can trick an authenticated a...

  • EPSS 0.23%
  • Veröffentlicht 03.08.2026 13:20:45
  • Zuletzt bearbeitet 03.08.2026 15:16:21

Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoes unencoded exception messages to the HTTP response. Unauthenticated attackers can inject arbitrary JavaScript through SAML Issue...

  • EPSS 0.36%
  • Veröffentlicht 03.08.2026 13:20:44
  • Zuletzt bearbeitet 03.08.2026 17:16:45

Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logic in modules/forum.php fails to validate the login-only configuration state, allowing unauthenticated...

  • EPSS 0.2%
  • Veröffentlicht 03.08.2026 13:20:44
  • Zuletzt bearbeitet 03.08.2026 15:16:21

Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to other organizations. Attackers can supply a role UUID from...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 25.05.2026 14:15:15
  • Zuletzt bearbeitet 23.07.2026 19:10:00

Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their permissions by exploiting improper origin checking. Attackers can craft malicious HTML forms targeting roles_function.php with paramet...

  • EPSS 0.24%
  • Veröffentlicht 07.05.2026 04:16:34
  • Zuletzt bearbeitet 07.05.2026 16:16:20

Admidio is an open-source user management solution. Prior to version 5.0.9, the incomplete SSRF fix in Admidio's fetch_metadata.php validates the resolved IP address but passes the original hostname-based URL to curl_init(), leaving a DNS rebinding T...

  • EPSS 0.32%
  • Veröffentlicht 07.05.2026 04:16:32
  • Zuletzt bearbeitet 07.05.2026 14:54:40

Admidio is an open-source user management solution. Prior to version 5.0.9, the OIDC token introspection endpoint (/modules/sso/index.php/oidc/introspect) always returns {"active": true} for every request, regardless of whether a valid token is provi...

  • EPSS 0.28%
  • Veröffentlicht 07.05.2026 04:16:30
  • Zuletzt bearbeitet 07.05.2026 15:16:08

Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO module uses the AssertionConsumerServiceURL value directly from incoming SAML AuthnRequest messages as the destination for the SA...

  • EPSS 0.19%
  • Veröffentlicht 07.05.2026 04:16:30
  • Zuletzt bearbeitet 07.05.2026 15:16:08

Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio SAML Identity Provider implementation discards the return value of its validateSignature() method at both call sites (handleSSORequest() line 418 and handleSLOReq...

  • EPSS 0.12%
  • Veröffentlicht 07.05.2026 04:16:30
  • Zuletzt bearbeitet 07.05.2026 14:51:01

Admidio is an open-source user management solution. Prior to version 5.0.9, several administrative operations in Admidio's preferences module (database backup, test email, htaccess generation) fire via GET requests with no CSRF token validation. Beca...