Admidio

Admidio

60 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 07.05.2026 04:16:30
  • Zuletzt bearbeitet 07.05.2026 15:16:08

Admidio is an open-source user management solution. Prior to version 5.0.9, Role::stopMembership() does not verify whether removing a user from the administrator role leaves zero administrators. The deprecated Membership::stopMembership() contains th...

  • EPSS 0.18%
  • Veröffentlicht 07.05.2026 04:16:29
  • Zuletzt bearbeitet 07.05.2026 16:16:20

Admidio is an open-source user management solution. Prior to version 5.0.9, an unauthenticated attacker can execute arbitrary JavaScript in any Admidio user's browser through a reflected XSS in system/msg_window.php. The endpoint passes user input th...

  • EPSS 0.3%
  • Veröffentlicht 07.05.2026 04:16:29
  • Zuletzt bearbeitet 07.05.2026 14:51:01

Admidio is an open-source user management solution. Prior to version 5.0.9, a logic error in Admidio's two-factor authentication reset inverts the authorization check. Non-admin users cannot remove their own TOTP configuration, but they can remove ot...

  • EPSS 0.26%
  • Veröffentlicht 07.05.2026 04:16:29
  • Zuletzt bearbeitet 07.05.2026 15:16:08

Admidio is an open-source user management solution. Prior to version 5.0.9, the member assignment DataTables endpoint (members_assignment_data.php) includes hidden profile fields (BIRTHDAY, STREET, CITY, POSTCODE, COUNTRY) in its SQL search condition...

  • EPSS 0.23%
  • Veröffentlicht 07.05.2026 04:16:29
  • Zuletzt bearbeitet 07.05.2026 15:16:08

Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio inventory module enforces authorization for destructive operations (delete, retire, reinstate) only in the UI layer by conditionally rendering buttons. The backen...

  • EPSS 0.32%
  • Veröffentlicht 07.05.2026 04:16:28
  • Zuletzt bearbeitet 07.05.2026 14:51:01

Admidio is an open-source user management solution. Prior to version 5.0.9, the contacts_data.php endpoint uses a weaker permission check (isAdministratorUsers(), requiring only rol_edit_user=true) than the frontend UI (contacts.php) which correctly ...

  • EPSS 0.36%
  • Veröffentlicht 07.05.2026 04:16:28
  • Zuletzt bearbeitet 07.05.2026 15:16:08

Admidio is an open-source user management solution. Prior to version 5.0.9, the add mode in modules/documents-files.php accepts a name parameter validated only as 'string' type (HTML encoding), allowing path traversal characters (../) to pass through...

  • EPSS 0.31%
  • Veröffentlicht 07.05.2026 04:16:28
  • Zuletzt bearbeitet 07.05.2026 16:16:20

Admidio is an open-source user management solution. Prior to version 5.0.9, the ecard_preview.php endpoint does not validate that the ecard_template POST parameter is a safe filename before passing it to ECard::getEcardTemplate(). An authenticated us...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 31.03.2026 20:34:37
  • Zuletzt bearbeitet 24.07.2026 20:10:00

Admidio is an open-source user management solution. Prior to version 5.0.8, the create_user, assign_member, and assign_user action modes in modules/registration.php approve pending user registrations via GET request without validating a CSRF token. U...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 31.03.2026 20:33:40
  • Zuletzt bearbeitet 24.07.2026 20:10:00

Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module's item_save endpoint accepts a user-controllable POST parameter imported that, when set to true, completely bypasses both CSRF token validation and serve...