Path traversal in Admidio - #VU144270

 

Path traversal in Admidio - #VU144270

Published: August 19, 2026


Vulnerability identifier: #VU144270
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify files outside the intended extraction directory on a victim system.

The vulnerability exists due to path traversal in modules/photos/photo_download.php when creating ZIP archive entries from an unsanitized album name. A remote user can create an album with a crafted name and cause a victim to extract the resulting archive to modify files outside the intended extraction directory on a victim system.

User interaction is required to extract the archive, and the effect depends on extraction tools that honor stored archive paths.


Affected software

Admidio

Remediation

Install security update from vendor's website.

Admidio - update to 5.0.12

External References

Related Security Bulletins