Executive brief
Admidio is a web-based user management system. A security flaw in its single sign-on (SSO) component allows an attacker to trick an administrator into exporting sensitive private key files. If an administrator visits a malicious website while logged in, the attacker can trigger a download of the organization's private security keys, potentially compromising secure communications.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in Admidio's SSO key management module. Specifically, the 'mode=export' action in 'modules/sso/keys.php' has its CSRF validation logic commented out in the source code. This allows a remote attacker to craft a malicious webpage that, when visited by an authenticated administrator, triggers a POST request to export a PKCS#12 bundle containing the configured private key and certificate. While the Same-Origin Policy (SOP) typically prevents the attacker from reading the downloaded file directly, the lack of protection allows for the unauthorized execution of a highly sensitive administrative action. The issue is fixed in version 5.0.10.
Affected products
- Admidio Admidio <= 5.0.9
Timeline
- 2026-05-25: disclosed
- 2026-05-29: advisory: GitHub Advisory published