Admidio 在 5.0.12 之前版本中的 profile_function.php 文件存在访问控制失效的漏洞,使得经过身份验证的低权限用户可以读取其他用户的未来角色成员资格信息。攻击者可以通过直接调用 reload_future_memberships 接口并传入目标用户的 UUID,绕过 profile 级别的授权检查,从而泄露敏感的成员资格信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82655 | 7.5 HIGH | Admidio before 5.0.12 SQL Injection via relation_type_list |
| CVE-2026-82657 | 7.5 HIGH | Admidio before 5.0.12 Authentication Bypass via RSS feeds |
| CVE-2026-82656 | 2.6 LOW | Admidio before 5.0.12 Path Traversal via Photo ZIP Download |
No comments yet