Admidio

Admidio

46 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.43%
  • Veröffentlicht 20.03.2026 02:16:35
  • Zuletzt bearbeitet 23.03.2026 15:24:40

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, unrestricted URL fetch in the SSO Metadata API can result in SSRF and local file reads. The SSO Metadata fetch endpoint at modules/sso/fetch_metadata.php accepts an ...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 19.03.2026 23:12:37
  • Zuletzt bearbeitet 23.03.2026 16:52:29

Admidio is an open-source user management solution. In versions 5.0.6 and below, the eCard send handler uses a raw $_POST['ecard_message'] value instead of the HTMLPurifier-sanitized $formValues['ecard_message'] when constructing the greeting card HT...

Exploit
  • EPSS 0.98%
  • Veröffentlicht 19.03.2026 23:08:03
  • Zuletzt bearbeitet 23.03.2026 16:51:44

Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload vulnerability in the Documents & Files module. Due to a design flaw in how CSRF token validation and file extension verification ...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 19.03.2026 23:00:40
  • Zuletzt bearbeitet 23.03.2026 18:47:49

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the forum module in Admidio does not verify whether the current user has permission to delete forum topics or posts. Both the topic_delete and post_delete actions in...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 19.03.2026 22:57:19
  • Zuletzt bearbeitet 23.03.2026 19:10:21

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the delete, activate, and deactivate modes in modules/groups-roles/groups_roles.php perform destructive state changes on organizational roles but never validate an a...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 19.03.2026 22:53:09
  • Zuletzt bearbeitet 23.03.2026 19:11:15

Admidio is an open-source user management solution. In versions 5.0.6 and below, the save_membership action in modules/profile/profile_function.php saves changes to a member's role membership start and end dates but does not validate the CSRF token. ...

  • EPSS 0.25%
  • Veröffentlicht 09.03.2026 23:03:55
  • Zuletzt bearbeitet 13.03.2026 14:45:47

Admidio is an open-source user management solution. Prior to 5.0.6, in modules/events/events_function.php, the event participation logic allows any user who can participate in an event to register OTHER users by manipulating the user_uuid GET paramet...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 22.10.2025 21:19:00
  • Zuletzt bearbeitet 30.10.2025 17:15:48

Admidio is an open-source user management solution. Prior to version 4.3.17, an authenticated SQL injection vulnerability exists in the member assignment data retrieval functionality of Admidio. Any authenticated user with permissions to assign membe...

  • EPSS 0.47%
  • Veröffentlicht 16.10.2024 20:15:06
  • Zuletzt bearbeitet 05.03.2025 14:53:25

Admidio is an open-source user management solution. Prior to version 4.3.12, an unsafe deserialization vulnerability allows any unauthenticated user to execute arbitrary code on the server. Version 4.3.12 fixes this issue.

Exploit
  • EPSS 1.17%
  • Veröffentlicht 29.07.2024 15:15:10
  • Zuletzt bearbeitet 21.11.2024 09:26:12

Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.3.10, there is a Remote Code Execution Vulnerability in the Message module of the Admidio Application, where it is possible to...