Junglewise Threat Intelligence

CVE-2026-47231: Admidio IDOR in documents-files.php move_save handler

CVE-2026-47231 · Severity: high · CVSS 8.1 · Published 2026-05-29

Technologies: admidio/admidio (Packagist), Admidio. Vendors: Packagist, Admidio.

Executive brief

Admidio is a web-based user management system for organizations and groups. A security flaw in its document management module allows any user with permission to upload files to a single folder to move files out of private, restricted folders into their own. This enables an attacker to steal sensitive documents (such as administrative or board-only files) and disrupts operations by removing files from their original locations.

Technical details

An Insecure Direct Object Reference (IDOR) exists in `modules/documents-files.php` within the `move_save` mode. The application validates permissions based on a `folder_uuid` provided in the URL, but the subsequent file move operation uses a separate `file_uuid` without verifying if the user has rights to the file's source folder. By providing a `folder_uuid` for a folder they control and a `file_uuid` for a restricted file, an attacker can move the file to a location where they have download permissions. This bypasses folder-level access controls and allows for unauthorized data exfiltration and file relocation. The issue is fixed in version 5.0.10.

Affected products

  • Admidio Admidio <= 5.0.9

Timeline

  • 2026-05-25: disclosed
  • 2026-05-29: advisory
  • 2026-05-29: patched: Fixed in version 5.0.10

References

Related threats