Missing Authentication for Critical Function in Admidio - #VU144271
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authentication for the RSS feed endpoints in rss/forum.php and rss/announcements.php when handling unauthenticated GET requests to login-only modules. A remote attacker can send a specially crafted request to disclose sensitive information.
Exposure occurs when RSS is enabled, the forum or announcements module is configured as login-only, and at least one category has no explicit view-role restriction.