Admidio

Admidio

60 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.12%
  • Veröffentlicht 31.03.2026 20:32:35
  • Zuletzt bearbeitet 24.07.2026 20:10:00

Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, the delete mode handler in mylist_function.php permanently deletes list configurations without validating a CSRF token. An attacker who can lure an authen...

Exploit
  • EPSS 0.58%
  • Veröffentlicht 31.03.2026 20:31:23
  • Zuletzt bearbeitet 24.07.2026 20:10:00

Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, Admidio relies on adm_my_files/.htaccess to deny direct HTTP access to uploaded documents. The Docker image ships with AllowOverride None in the Apache co...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 20.03.2026 02:16:35
  • Zuletzt bearbeitet 23.03.2026 13:16:30

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the documents and files module does not verify whether the current user has permission to delete folders or files. The folder_delete and file_delete action handlers ...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 20.03.2026 02:16:35
  • Zuletzt bearbeitet 23.03.2026 15:25:42

Admidio is an open-source user management solution. Versions 5.0.6 and below are vulnerable to arbitrary SQL Injection through the MyList configuration feature. The MyList configuration feature lets authenticated users define custom list column layou...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 20.03.2026 02:16:35
  • Zuletzt bearbeitet 23.03.2026 15:24:40

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, unrestricted URL fetch in the SSO Metadata API can result in SSRF and local file reads. The SSO Metadata fetch endpoint at modules/sso/fetch_metadata.php accepts an ...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 19.03.2026 23:12:37
  • Zuletzt bearbeitet 23.03.2026 16:52:29

Admidio is an open-source user management solution. In versions 5.0.6 and below, the eCard send handler uses a raw $_POST['ecard_message'] value instead of the HTMLPurifier-sanitized $formValues['ecard_message'] when constructing the greeting card HT...

Exploit
  • EPSS 0.98%
  • Veröffentlicht 19.03.2026 23:08:03
  • Zuletzt bearbeitet 23.03.2026 16:51:44

Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload vulnerability in the Documents & Files module. Due to a design flaw in how CSRF token validation and file extension verification ...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 19.03.2026 23:00:40
  • Zuletzt bearbeitet 23.03.2026 18:47:49

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the forum module in Admidio does not verify whether the current user has permission to delete forum topics or posts. Both the topic_delete and post_delete actions in...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 19.03.2026 22:57:19
  • Zuletzt bearbeitet 23.03.2026 19:10:21

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the delete, activate, and deactivate modes in modules/groups-roles/groups_roles.php perform destructive state changes on organizational roles but never validate an a...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 19.03.2026 22:53:09
  • Zuletzt bearbeitet 23.03.2026 19:11:15

Admidio is an open-source user management solution. In versions 5.0.6 and below, the save_membership action in modules/profile/profile_function.php saves changes to a member's role membership start and end dates but does not validate the CSRF token. ...