Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2v5m-cq9w-fc33 | Admidio Vulnerable to Authenticated SQL Injection in Member Assignment Functionality |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 30 Oct 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:admidio:admidio:*:*:*:*:*:*:*:* |
Thu, 23 Oct 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Admidio
Admidio admidio |
|
| Vendors & Products |
Admidio
Admidio admidio |
Wed, 22 Oct 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Admidio is an open-source user management solution. Prior to version 4.3.17, an authenticated SQL injection vulnerability exists in the member assignment data retrieval functionality of Admidio. Any authenticated user with permissions to assign members to a role (such as an administrator) can exploit this vulnerability to execute arbitrary SQL commands. This can lead to a full compromise of the application's database, including reading, modifying, or deleting all data. This issue has been patched in version 4.3.17. | |
| Title | Admidio Vulnerable to Authenticated SQL Injection in Member Assignment Functionality | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-23T16:17:28.926Z
Reserved: 2025-10-16T19:24:37.269Z
Link: CVE-2025-62617
Updated: 2025-10-23T16:03:11.840Z
Status : Analyzed
Published: 2025-10-22T22:15:34.400
Modified: 2025-10-30T17:15:48.570
Link: CVE-2025-62617
No data.
OpenCVE Enrichment
Updated: 2025-10-23T09:58:47Z
Github GHSA