Home

Description

Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module's item_save endpoint accepts a user-controllable POST parameter imported that, when set to true, completely bypasses both CSRF token validation and server-side form validation. An authenticated user can craft a direct POST request to save arbitrary inventory item data without CSRF protection and without the field value checks that the FormPresenter validation normally enforces. This issue has been patched in version 5.0.8.

PUBLISHED Reserved 2026-03-27 | Published 2026-03-31 | Updated 2026-04-03 | Assigner GitHub_M




MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Problem types

CWE-20: Improper Input Validation

CWE-352: Cross-Site Request Forgery (CSRF)

Product status

< 5.0.8
affected

References

github.com/...dmidio/security/advisories/GHSA-4rwm-c5mj-wh7x

github.com/...ommit/00494b95dfe847af8b938e4397e5d909d8f36839

cve.org (CVE-2026-34383)

nvd.nist.gov (CVE-2026-34383)

Download JSON