Cross-site request forgery in Admidio - CVE-2026-41663
Published: April 23, 2026
Admidio
Detailed vulnerability description
The vulnerability allows a remote user to perform unauthorized administrative actions.
The vulnerability exists due to cross-site request forgery in admin preferences when handling crafted requests from an authenticated administrator's browser. A remote privileged user can trick a victim into following a crafted link or loading attacker-controlled content to perform unauthorized administrative actions.
User interaction is required.