Junglewise Threat Intelligence

CVE-2026-34384: Admidio CSRF in registration approval actions

CVE-2026-34384 · Severity: medium · CVSS 4.5 · Published 2026-03-31

Technologies: admidio/admidio (Packagist), Admidio. Vendors: Packagist, Admidio.

Executive brief

Admidio is an open-source platform used by organizations to manage member registrations and profiles. A security flaw allows attackers to bypass the manual approval process for new accounts by tricking an administrator into clicking a malicious link or visiting a compromised webpage. This could allow unauthorized individuals to gain access to private member data or, in some cases, take over existing member accounts.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in Admidio's registration module. The 'create_user', 'assign_member', and 'assign_user' action modes in modules/registration.php process state-changing requests via GET parameters without validating a CSRF token. An attacker can extract their own registration UUID from a confirmation email and craft a malicious URL. If a user with 'rol_approve_users' privileges is enticed to visit this URL (e.g., via an <img> tag), the attacker's registration is automatically approved. Furthermore, the 'assign_user' mode can be abused to merge a pending registration into an existing account, leading to account takeover if the target's UUID is known. The issue is fixed in version 5.0.8 by requiring POST requests and valid CSRF tokens for these actions.

Affected products

  • Admidio Admidio < 5.0.8

Timeline

  • 2026-03-27: advisory: GitHub Security Advisory published
  • 2026-03-31: disclosed: NVD publication date
  • 2026-03-31: patched: Fix released in version 5.0.8

References

Related threats