PT-2026-67412 · Admidio · Admidio
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Admidio versions prior to 5.0.11
Description
Authenticated role administrators can modify roles belonging to other organizations because the software fails to validate target organization membership in role handlers. An attacker can provide a role UUID from a different organization to the
groups roles.php endpoint to delete, activate, deactivate, or edit those roles without authorization.Recommendations
Update to version 5.0.11 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Admidio