Admidio
cpe:2.3:a:admidio:admidio:*:*:*:*:*:*:*
- <= 3.3.5
A cross-site request forgery (CSRF) vulnerability has been identified in Admidio version 3.3.5. This vulnerability allows low-privilege users to escalate their permissions by exploiting inadequate origin verification. Attackers can create malicious HTML forms that target roles_function.php, using parameters such as rol_assign_roles, rol_approve_users, and rol_edit_user set to 1, to gain unauthorized privileges.
Exploitation of this vulnerability allows for unauthorized privilege escalation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.