PT-2026-37143 · Admidio · Admidio
Offset
·
Published
2026-04-29
·
Updated
2026-05-07
·
CVE-2026-41659
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Admidio versions prior to 5.0.9
Description
The member assignment DataTables endpoint 'members assignment data.php' includes hidden profile fields in its SQL search condition regardless of visibility settings. While the JSON output suppresses hidden columns using
isVisible() checks, the server-side search operates at the SQL level before this filtering occurs. This allows a role leader with assign-only permissions to perform a blind oracle attack, inferring hidden personally identifiable information (PII) by observing which users appear in search results for specific values. The affected hidden fields include BIRTHDAY, STREET, CITY, POSTCODE, and COUNTRY.Recommendations
Update to version 5.0.9.
As a temporary workaround, restrict access to the 'members assignment data.php' endpoint to only those users who require it and are trusted with PII access.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Admidio