Improper Authorization in Admidio - #VU144272
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper authorization in profile_function.php when handling requests to reload future memberships. A remote user can send a specially crafted request for another user\'s profile data to disclose sensitive information.
This issue is exploitable only when the target role is visible to the attacker and the victim has a future membership.