PT-2026-29350 · Admidio · Admidio

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2026-34383

CVSS v3.1

4.3

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module's item save endpoint accepts a user-controllable POST parameter imported that, when set to true, completely bypasses both CSRF token validation and server-side form validation. An authenticated user can craft a direct POST request to save arbitrary inventory item data without CSRF protection and without the field value checks that the FormPresenter validation normally enforces. This issue has been patched in version 5.0.8.

Fix

RCE

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-34383

Affected Products

Admidio