PT-2026-83582 · Admidio · Admidio
CVSS v3.1
2.6
Low
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Admidio versions prior to 5.0.12
Description
Insufficient sanitization of album names in the photo ZIP download functionality allows authenticated users with album-creation rights to include path traversal segments in archive entry names. This enables attackers to create malicious album names containing directory traversal sequences—a technique used to access files and directories outside the intended folder—which can result in files being written outside the target directory when the recipient extracts the archive.
Recommendations
Update to version 5.0.12 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Admidio