Vulnerabilities > Admidio

DATE CVE VULNERABILITY TITLE RISK
2021-05-20 CVE-2021-32630 Unrestricted Upload of File with Dangerous Type vulnerability in Admidio
Admidio is a free, open source user management system for websites of organizations and groups.
network
low complexity
admidio CWE-434
6.5
2020-04-24 CVE-2020-11004 SQL Injection vulnerability in Admidio
SQL Injection was discovered in Admidio before version 3.3.13.
network
low complexity
admidio CWE-89
5.0
2017-05-16 CVE-2017-8382 Cross-Site Request Forgery (CSRF) vulnerability in Admidio 3.2.8
admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user accounts.
network
admidio CWE-352
3.5
2017-03-05 CVE-2017-6492 SQL Injection vulnerability in Admidio 3.2.5
SQL Injection was discovered in adm_program/modules/dates/dates_function.php in Admidio 3.2.5.
network
low complexity
admidio CWE-89
critical
9.0
2008-11-24 CVE-2008-5209 Path Traversal vulnerability in Admidio 1.4.8
Directory traversal vulnerability in modules/download/get_file.php in Admidio 1.4.8 allows remote attackers to read arbitrary files via a ..
network
low complexity
admidio CWE-22
5.0