Cross-site request forgery in Admidio - CVE-2026-47228
Published: May 25, 2026
Admidio
Detailed vulnerability description
The vulnerability allows a remote user to reset arbitrary user passwords.
The vulnerability exists due to cross-site request forgery in modules/registration.php send_login mode when handling a crafted top-level navigation request. A remote privileged user can cause a registration administrator to visit a crafted page to reset arbitrary user passwords.
User interaction is required, and the password change occurs even if e-mail delivery fails.