Description
Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their permissions by exploiting improper origin checking. Attackers can craft malicious HTML forms targeting roles_function.php with parameters like rol_assign_roles, rol_approve_users, and rol_edit_user set to 1 to escalate privileges without authentication.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Credits
Nawaf Alkeraithe
References
www.exploit-db.com/exploits/45322 (ExploitDB-45322)
www.admidio.org/ (Official Product Homepage)
sourceforge.net/.../Admidio/3.3.x/admidio-3.3.5.zip/download (Product Reference)
www.vulncheck.com/...-request-forgery-via-roles-function-php (VulnCheck Advisory: Admidio 3.3.5 Cross-Site Request Forgery via roles_function.php)