Admidio是Admidio组织开源的一套成员管理系统。该系统支持成员列表、事件管理、留言簿、相册和下载等功能。 Admidio 5.0.11之前版本存在授权问题漏洞,该漏洞源于modules/forum.php中的访问控制逻辑未能验证login-only配置状态,可能导致未经身份验证的攻击者通过只读参数直接访问模块读取论坛主题和帖子。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: unauthenticated GET /modules/forum.php?mode=cards leaked forum topic "SECRET-TOKEN-PROOF_e7f6dae813339284" through login-only auth bypass (PROOF_e7f6dae813339284)
| CVE-2026-69092 | 6.5 MEDIUM | Admidio before 5.0.11 Reflected XSS via SSO/SAML Endpoint |
| CVE-2026-69090 | 4.9 MEDIUM | Admidio before 5.0.11 Cross-Organization Role Modification |
| CVE-2026-69093 | 4.6 MEDIUM | Admidio before 5.0.11 CSRF via category-report preferences |
| CVE-2026-69094 | 4.3 MEDIUM | Admidio before 5.0.11 IDOR via save_temporary mylist_function.php |
No comments yet