Admidio 5.0.12 之前的版本中存在一个盲注 SQL 注入漏洞,位于 lists_show.php 文件的 relation_type_list 参数中。该漏洞允许未经身份验证的攻击者执行任意 SQL 查询。攻击者可以通过在 role_list 中提供一个虚拟 UUID 来绕过身份验证,并通过 relation_type_list 注入 SQL,从而提取数据库内容,包括密码哈希值和用户凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82657 | 7.5 HIGH | Admidio before 5.0.12 Authentication Bypass via RSS feeds |
| CVE-2026-82658 | 4.3 MEDIUM | Admidio before 5.0.12 Broken Access Control via profile_function.php |
| CVE-2026-82656 | 2.6 LOW | Admidio before 5.0.12 Path Traversal via Photo ZIP Download |
No comments yet