Cross-site request forgery in Admidio - CVE-2026-47228

 

Cross-site request forgery in Admidio - CVE-2026-47228

Published: May 25, 2026


Vulnerability identifier: #VU132286
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-47228
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Admidio
Affected software:
Admidio

Detailed vulnerability description

The vulnerability allows a remote user to reset arbitrary user passwords.

The vulnerability exists due to cross-site request forgery in modules/registration.php send_login mode when handling a crafted top-level navigation request. A remote privileged user can cause a registration administrator to visit a crafted page to reset arbitrary user passwords.

User interaction is required, and the password change occurs even if e-mail delivery fails.


How to mitigate CVE-2026-47228

Install security update from vendor's website.

Sources