CVE-2026-34382
⚪ Do wiadomości
Brak walidacji tokena CSRF w Admidio pozwala na trwałe usunięcie konfiguracji list przez atakującego.
CVSS
4.6
EPSS
0.1%
Exploit
poc
Vendor
admidio
Opis źródłowy (NVD)
Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, the delete mode handler in mylist_function.php permanently deletes list configurations without validating a CSRF token. An attacker who can lure an authenticated user to a malicious page can silently destroy that user's list configurations — including organization-wide shared lists when the victim holds administrator rights. This issue has been patched in version 5.0.8.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 4.6 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.1% |
| Opublikowano (NVD) | 2026-03-31 21:16:30 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-06 22:10:00 UTC |
Referencje
- https://github.com/Admidio/admidio/commit/317ec91ad3baf19d4179db6c32413812eb36d7ca ([email protected]) [Patch]
- https://github.com/Admidio/admidio/security/advisories/GHSA-g3mx-8jm6-rc85 ([email protected]) [Exploit, Mitigation, Vendor Advisory]