Admidio 在 5.0.12 版本之前,其 RSS 订阅源端点(针对论坛和公告模块)未能强制执行“仅限登录用户”的模块访问限制。未经身份验证的攻击者可以通过向 或 发送 GET 请求,来获取论坛主题和公告,从而泄露帖子标题、完整正文内容、作者姓名及时间戳等信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82655 | 7.5 HIGH | Admidio before 5.0.12 SQL Injection via relation_type_list |
| CVE-2026-82658 | 4.3 MEDIUM | Admidio before 5.0.12 Broken Access Control via profile_function.php |
| CVE-2026-82656 | 2.6 LOW | Admidio before 5.0.12 Path Traversal via Photo ZIP Download |
No comments yet