Admidio Cross-Site Request Forgery Vulnerability in roles_function.php

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in Admidio version 3.3.5. This vulnerability allows low-privilege users to escalate their permissions by exploiting inadequate origin verification. Attackers can create malicious HTML forms that target roles_function.php, using parameters such as rol_assign_roles, rol_approve_users, and rol_edit_user set to 1, to gain unauthorized privileges.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation.

Added: May 26, 2026, 7:34 PM
Updated: May 26, 2026, 7:34 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
0.6
exploitability
7.3
remediation
0.0
relevance
9.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.