Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-34383

6 месяцев назад

Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module's item_save endpoint accepts a user-controllable POST parameter imported that, when set to true, completely bypasses both CSRF token validation and server-side form validation. An authenticated user can craft a direct POST request to save arbitrary inventory item data without CSRF protection and without the field value checks that the FormPresenter validation normally enforces. This issue has been patched in version 5.0.8.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4rwm-c5mj-wh7x

6 месяцев назад

Admidio has CSRF and Form Validation Bypass in Inventory Item Save via `imported` Parameter

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-34383

Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module's item_save endpoint accepts a user-controllable POST parameter imported that, when set to true, completely bypasses both CSRF token validation and server-side form validation. An authenticated user can craft a direct POST request to save arbitrary inventory item data without CSRF protection and without the field value checks that the FormPresenter validation normally enforces. This issue has been patched in version 5.0.8.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-4rwm-c5mj-wh7x

Admidio has CSRF and Form Validation Bypass in Inventory Item Save via `imported` Parameter

CVSS3: 4.3
0%
Низкий
6 месяцев назад

Уязвимостей на страницу