Missing Authentication for Critical Function in Admidio - #VU138935
Published: July 21, 2026
Admidio
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authentication for a critical function in /modules/forum.php when handling unauthenticated requests to read-only forum modes. A remote attacker can send a specially crafted HTTP GET request with mode parameters to disclose sensitive information.
The issue occurs only when the forum module is configured in login-only mode, and read operations such as cards, list, and topic are exposed without authentication.