Impact
Admidio applications prior to version 5.0.12 lack sanitization of album names during the photo ZIP download feature. Attackers who are authenticated with album‑creation rights can name an album with directory‑traversal sequences, causing the resulting ZIP archive to contain entries that reference paths outside the intended file system directory when a recipient extracts the archive. The vulnerability does not provide remote code execution or direct system compromise, but it enables the creation of files in arbitrary locations on the host where the archive is unpacked.
Affected Systems
All installations of Admidio earlier than 5.0.12 are potentially affected. The issue is present across all supported configurations of the open‑source Admidio community edition, as it applies globally to the photo ZIP download functionality.
Risk and Exploitability
The CVSS score of 2.1 indicates low severity, and there is no EPSS data available, suggesting a low likelihood of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Exploit requires the attacker to be an authenticated user with permission to create albums; deployment involves creating a malicious album name and subsequently having a user extract the downloaded ZIP. The impact is limited to environments where users extract the archive in an uncontrolled or insecure manner, allowing arbitrary file writes but not broader system compromise.
OpenCVE Enrichment