PT-2026-83584 · Admidio · Admidio
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Admidio versions prior to 5.0.12
Description
Broken access control in
profile function.php allows authenticated users with low privileges to view the future role memberships of other users. This is achieved by bypassing profile-level authorization through direct calls to the reload future memberships endpoint using a victim's user UUID.Recommendations
Update to version 5.0.12 or later.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Admidio