top of page
perceptive_background_267k.jpg

Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logic in module…

Published:

3 August 2026 at 00:00:00

Alert date:

3 August 2026 at 17:06:10

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

Admidio versions before 5.0.11 contain an authentication bypass vulnerability in the forum module. When the application is configured in login-only mode, the access control logic in modules/forum.php fails to properly validate the login-only configuration state. This flaw allows unauthenticated attackers to read forum topics and posts by directly accessing the module with read-only parameters. The vulnerability effectively bypasses the intended access restriction, exposing potentially sensitive forum content to unauthorized users. A fix is available in Admidio version 5.0.11 and later. The issue has been documented in the official GitHub security advisory and tracked by VulnCheck.

Technical details

Mitigation steps:

Affected products:

Admidio

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page