Cross-Site Scripting Vulnerability in Admidio User Management Solution
CVE-2026-47230

6.5MEDIUM

Key Information:

Vendor

Admidio

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-47230?

Admidio, a popular open-source user management solution, is impacted by a vulnerability that allows users with upload privileges in one folder to rename files in another folder without proper authorization. Specifically, the vulnerability arises from inadequate checks in modules/documents-files.php, where the system fails to re-validate the original folder's permissions during a file rename operation. As a result, an unauthorized user could exploit this flaw to overwrite files beyond their permitted limits. Mitigation is available in version 5.0.10, which addresses this oversight and strengthens the overall security posture of the application.

Affected Version(s)

admidio < 5.0.10

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.