Path traversal in Admidio - CVE-2026-41656
Published: April 23, 2026
Admidio
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to path traversal in the add mode of modules/documents-files.php and the documents file handling logic when processing a crafted name parameter. A remote privileged user can trick a documents administrator into clicking a crafted link to disclose sensitive information.
User interaction is required, and exploitation relies on the add action being performed through a cross-site GET request that includes the victim's session.