Open-source User Management Solution Vulnerability in Admidio
CVE-2026-41663
3.5LOW
What is CVE-2026-41663?
Admidio, an open-source user management solution, has a vulnerability in its preferences module where several administrative operations, such as database backup, test email, and htaccess generation, can be triggered via GET requests without proper CSRF token validation. This flaw allows attackers to exploit the feature by forcing an authenticated administrator to perform these operations from a malicious webpage. The vulnerability has been addressed in version 5.0.9, where necessary security measures have been implemented to prevent such unauthorized actions.
Affected Version(s)
admidio < 5.0.9
