Impact
Admidio versions prior to 5.0.12 fail to enforce login‑only restrictions for RSS feed endpoints of the forum and announcements modules. The flaw allows unauthenticated attackers to request rss/forum.php or rss/announcements.php and obtain forum topics, announcements, author names, timestamps, and full post text, representing a direct information exposure vulnerability (CWE‑200) that could compromise confidentiality by revealing private discussions or administrative data.
Affected Systems
Admidio, an open‑source community platform, is affected by this vulnerability. All releases before 5.0.12—including every 4.x edition and all 5.x releases up to 5.0.11—are vulnerable because the default installation of the RSS endpoints serves forum and announcement content without requiring authentication.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. Because the issue is accessible over the public web via simple HTTP GET requests and requires no credentials, the attack vector is remote and straightforward to exploit. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, but the exposure of sensitive data without authentication remains a serious risk, necessitating immediate remediation to prevent disclosure of confidential information.
OpenCVE Enrichment