Executive brief
Admidio is a web-based user management system for organizations and groups. A security flaw in its document management module allows any user with permission to upload files to a single folder to move files out of private, restricted folders into their own. This enables an attacker to steal sensitive documents (such as administrative or board-only files) and disrupts operations by removing files from their original locations.
Technical details
An Insecure Direct Object Reference (IDOR) exists in `modules/documents-files.php` within the `move_save` mode. The application validates permissions based on a `folder_uuid` provided in the URL, but the subsequent file move operation uses a separate `file_uuid` without verifying if the user has rights to the file's source folder. By providing a `folder_uuid` for a folder they control and a `file_uuid` for a restricted file, an attacker can move the file to a location where they have download permissions. This bypasses folder-level access controls and allows for unauthorized data exfiltration and file relocation. The issue is fixed in version 5.0.10.
Affected products
- Admidio Admidio <= 5.0.9
Timeline
- 2026-05-25: disclosed
- 2026-05-29: advisory
- 2026-05-29: patched: Fixed in version 5.0.10