Impact
Admidio versions prior to 5.0.12 contain a broken access control flaw in profile_function.php. The vulnerability allows authenticated low‑privilege users to read another user’s future role memberships by bypassing profile‑level authorization. Attackers can invoke the reload_future_memberships endpoint with a victim’s user UUID to disclose membership information that should be restricted.
Affected Systems
The affected product is Admidio community edition. All installations of Admidio before version 5.0.12 are impacted. No specific distribution or build is singled out, so any deployment using a vulnerable version is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, so the current likelihood of exploitation is unclear, but the vulnerability requires only that the attacker has legitimate credentials with low privileges. The KEV database does not list this CVE, suggesting that it has not yet been widely exploited, but the exposed information is potentially sensitive. An attacker with access to the application, even at a low privilege level, can collect membership data that may be useful for further social engineering or privilege escalation.
OpenCVE Enrichment