Impact
Admidio versions prior to 5.0.11 contain an insecure direct object reference in the save_temporary mode of mylist_function.php. Because the application does not validate ownership before updating list configurations, an authenticated user can supply a list_uuid parameter and overwrite another user’s or an admin’s list. This allows an attacker to hijack list configurations, transfer ownership of global lists to a personal account, and demote globally curated lists to private ones. The weakness jeopardizes both the integrity of list data and the intended privacy controls enforced by administrators.
Affected Systems
The vulnerability is found in the Admidio web application. All installations of Admidio with a version earlier than 5.0.11 are susceptible. The affected releases include any patch level up to 5.0.10 inclusive.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate overall impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. Attackers must be authenticated and require knowledge or enumeration of global list UUIDs, which the application allows. Once an attacker supplies a list_uuid value corresponding to a protected list, they can overwrite it, resulting in unauthorized ownership changes. Given the moderate CVSS and lack of publicly disclosed exploits, the immediate risk is moderate but mitigable by patching.
OpenCVE Enrichment