Cross-Site Scripting Vulnerability in Admidio User Management Solution
CVE-2026-47230
6.5MEDIUM
What is CVE-2026-47230?
Admidio, a popular open-source user management solution, is impacted by a vulnerability that allows users with upload privileges in one folder to rename files in another folder without proper authorization. Specifically, the vulnerability arises from inadequate checks in modules/documents-files.php, where the system fails to re-validate the original folder's permissions during a file rename operation. As a result, an unauthorized user could exploit this flaw to overwrite files beyond their permitted limits. Mitigation is available in version 5.0.10, which addresses this oversight and strengthens the overall security posture of the application.
Affected Version(s)
admidio < 5.0.10
