Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php that allows authenticated users to hijack list configurations. Attackers can enumerate global list UUIDs and overwrite admin-curated global lists or other users' private lists by supplying a list_uuid parameter, transferring ownership and demoting global lists to personal configurations.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Aug 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php that allows authenticated users to hijack list configurations. Attackers can enumerate global list UUIDs and overwrite admin-curated global lists or other users' private lists by supplying a list_uuid parameter, transferring ownership and demoting global lists to personal configurations. | |
| Title | Admidio before 5.0.11 IDOR via save_temporary mylist_function.php | |
| First Time appeared |
Admidio
Admidio admidio |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:admidio:admidio:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Admidio
Admidio admidio |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-03T13:20:47.133Z
Updated: 2026-08-03T20:05:54.254Z
Reserved: 2026-08-03T10:44:14.335Z
Link: CVE-2026-69094
Updated: 2026-08-03T20:05:48.922Z
No data.
No data.