PT-2026-45044 · Admidio+2 · Admidio+1
CVE-2026-47234
·
Published
2026-05-29
·
Updated
2026-08-12
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Admidio versions prior to 5.0.10
Description
When debug logging is enabled, the application logs sensitive credentials in cleartext. Specifically, the
Session::setCookie() function logs full cookie values and the Session::start() function logs the current session ID. In a standard deployment, this includes both the active session cookie and the persistent auto-login cookie. An attacker with access to the log sink can recover these bearer-style credentials to perform session hijacking or gain long-lived account access.Recommendations
Update to version 5.0.10.
As a temporary workaround, disable debug logging to prevent the exposure of session identifiers and cookie values in the logs.
Exploit
Fix
Insertion into Log File
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Admidio
Admidio/Admidio