Ad

CVE-2026-30927

MEDIUM CVSS 4.0: 5.3 EPSS 0.01%
Updated Mar 10, 2026
PHP
Parameter Value
CVSS 5.3 (MEDIUM)
Fixed In 5.0.6
Type CWE-639 (Authorization Bypass (Обход авторизации))
Vendor PHP
Public PoC No

Admidio is an open-source user management solution. Prior to 5.0.6, in modules/events/events_function.php, the event participation logic allows any user who can participate in an event to register OTHER users by manipulating the user_uuid GET parameter. The condition uses || (OR), meaning if possibleToParticipate() returns true (event is open for participation), ANY user - not just leaders - can specify a different user_uuid and register/cancel participation for that user.

The code then operates on $user->getValue('usr_id') (the target user from user_uuid) rather than the current user. This vulnerability is fixed in 5.0.6.

Attack Parameters

Attack Vector
Network
Атака возможна удалённо
Attack Complexity
Low
Легко эксплуатировать
Attack Requirements
None
Нет дополнительных условий
Privileges Required
Low
Нужны базовые права
User Interaction
None
Не нужно действие пользователя

Impact Assessment

Confidentiality
None
Нет утечки данных
Integrity
Low
Частичная модификация данных
Availability
Low
Частичное нарушение работы

CVSS Vector v4.0