Cross-site scripting in Admidio - CVE-2026-41661
Published: April 23, 2026
Admidio
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary JavaScript in a user's browser.
The vulnerability exists due to cross-site scripting in system/msg_window.php when handling crafted GET parameters. A remote attacker can send a specially crafted link to execute arbitrary JavaScript in a user's browser.
User interaction is required, and the issue is triggered via the message_id and message_var1 parameters after square brackets in user input are converted into HTML angle brackets.