Admidio是Admidio团队的一套开源的成员管理系统。该系统支持成员列表、事件管理、留言簿、相册和下载等功能。 Admidio 5.0.0版本至5.0.6版本存在安全漏洞,该漏洞源于论坛模块未验证用户删除权限,可能导致任何经过身份验证的用户删除任何论坛主题或帖子。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-32756 | 8.8 HIGH | Admidio: Unrestricted File Upload via CSRF Token Validation Bypass in Documents & Files Mo |
| CVE-2026-32755 | 5.7 MEDIUM | Admidio is Missing CSRF Protection on Role Membership Date Changes |
| CVE-2026-32816 | 5.7 MEDIUM | Admidio has Missing CSRF Validation on Role Delete, Activate, and Deactivate Actions |
| CVE-2026-32757 | 5.4 MEDIUM | Admidio: HTMLPurifier Bypass in eCard Message Allows HTML Email Injection |
No comments yet