Vulnerabilities (CVE)

Filtered by vendor Admidio Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-47380 1 Admidio 1 Admidio 2023-12-01 N/A 6.1 MEDIUM
Admidio v4.2.12 and below is vulnerable to Cross Site Scripting (XSS).
CVE-2023-4190 1 Admidio 1 Admidio 2023-08-09 N/A 6.5 MEDIUM
Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.2.11.
CVE-2022-23896 1 Admidio 1 Admidio 2022-07-07 3.5 LOW 5.4 MEDIUM
Admidio 4.1.2 version is affected by stored cross-site scripting (XSS).
CVE-2021-43810 1 Admidio 1 Admidio 2021-12-09 4.3 MEDIUM 6.1 MEDIUM
Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vulnerability is present in Admidio prior to version 4.0.12. The Reflected XSS vulnerability occurs because redirect.php does not properly validate the value of the url parameter. Through this vulnerability, an attacker is capable to execute malicious scripts. This issue is patched in version 4.0.12.
CVE-2017-8382 1 Admidio 1 Admidio 2017-06-05 3.5 LOW 4.5 MEDIUM
admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user accounts.