Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4rgq-38mh-9xqg | Admidio PKCS#12 private key export action lacks CSRF protection |
Wed, 12 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Admidio is an open-source user management solution. Prior to version 5.0.10, the sensitive `mode=export` action in `modules/sso/keys.php` exports a PKCS#12 bundle containing the configured private key and certificate, but the CSRF validation line is commented out. A forged cross-site POST from an administrator session can therefore trigger private key export without a valid form token. Version 5.0.10 contains a fix. | |
| Title | Admidio PKCS#12 private key export action lacks CSRF protection | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-12T13:32:17.252Z
Reserved: 2026-05-18T22:54:18.271Z
Link: CVE-2026-47232
Updated: 2026-08-12T13:32:12.818Z
Status : Received
Published: 2026-08-12T14:17:54.360
Modified: 2026-08-12T14:17:54.360
Link: CVE-2026-47232
No data.
OpenCVE Enrichment
No data.
Github GHSA