Admidio is an open-source user management solution. Prior to version 4.3.17, an authenticated SQL injection vulnerability exists in the member assignment data retrieval functionality of Admidio. Any authenticated user with permissions to assign members to a role (such as an administrator) can exploit this vulnerability to execute arbitrary SQL commands. This can lead to a full compromise of the application's database, including reading, modifying, or deleting all data. This issue has been patched in version 4.3.17.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
GHSA-2v5m-cq9w-fc33 | Admidio Vulnerable to Authenticated SQL Injection in Member Assignment Functionality |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 22 Oct 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Admidio is an open-source user management solution. Prior to version 4.3.17, an authenticated SQL injection vulnerability exists in the member assignment data retrieval functionality of Admidio. Any authenticated user with permissions to assign members to a role (such as an administrator) can exploit this vulnerability to execute arbitrary SQL commands. This can lead to a full compromise of the application's database, including reading, modifying, or deleting all data. This issue has been patched in version 4.3.17. | |
Title | Admidio Vulnerable to Authenticated SQL Injection in Member Assignment Functionality | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-22T21:19:00.940Z
Reserved: 2025-10-16T19:24:37.269Z
Link: CVE-2025-62617

No data.

Status : Received
Published: 2025-10-22T22:15:34.400
Modified: 2025-10-22T22:15:34.400
Link: CVE-2025-62617

No data.

No data.