PT-2026-37143 · Admidio · Admidio

Offset

·

Published

2026-04-29

·

Updated

2026-05-07

·

CVE-2026-41659

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Admidio versions prior to 5.0.9
Description The member assignment DataTables endpoint 'members assignment data.php' includes hidden profile fields in its SQL search condition regardless of visibility settings. While the JSON output suppresses hidden columns using isVisible() checks, the server-side search operates at the SQL level before this filtering occurs. This allows a role leader with assign-only permissions to perform a blind oracle attack, inferring hidden personally identifiable information (PII) by observing which users appear in search results for specific values. The affected hidden fields include BIRTHDAY, STREET, CITY, POSTCODE, and COUNTRY.
Recommendations Update to version 5.0.9. As a temporary workaround, restrict access to the 'members assignment data.php' endpoint to only those users who require it and are trusted with PII access.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-41659
GHSA-68PR-7PRH-MPV4

Affected Products

Admidio