Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xg76-5qj2-2hhv | Admidio: CSRF in SSO client `enable` action toggles SAML/OIDC clients without token validation |
Wed, 12 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm_csrf_token` on every state-changing branch except `enable`. The `enable` case loads the SAML or OIDC client by UUID, calls `$client->enable($enabled)`, and persists the new state with no token check. Because the action is reachable via plain GET parameters, a third-party page can trick an authenticated administrator into disabling (or silently re-enabling) any configured SAML or OIDC client. Disabling an SSO client breaks every downstream relying-party application that authenticates through it. Version 5.0.10 contains a fix. | |
| Title | Admidio: CSRF in SSO client `enable` action toggles SAML/OIDC clients without token validation | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-12T13:11:31.073Z
Reserved: 2026-05-18T22:25:21.259Z
Link: CVE-2026-47229
No data.
Status : Received
Published: 2026-08-12T14:17:53.910
Modified: 2026-08-12T14:17:53.910
Link: CVE-2026-47229
No data.
OpenCVE Enrichment
No data.
Github GHSA