CVE-2026-47228 PUBLISHED

Admidio's CSRF in registration `send_login` mode resets arbitrary user passwords

Assigner: GitHub_M
Reserved: 18.05.2026 Published: 12.08.2026 Updated: 12.08.2026

Admidio is an open-source user management solution. modules/registration.php mode send_login regenerates a random password for user_uuid_assigned, stores its bcrypt hash in adm_users.usr_password, and emails the cleartext to that user. Every other state-changing mode in the same file (assign_member, assign_user, delete_user, create_user) calls SecurityUtils::validateCsrfToken($_POST['adm_csrf_token']) first; the send_login branch does not. Prior to version 5.0.10, page visited by a registration-administrator can issue the request as a top-level navigation, the browser sends the admin's SameSite=Lax cookies, and the server resets the chosen user's password without any further interaction from the admin. Version 5.0.10 fixes the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:L
CVSS Score: 5.2

Product Status

Vendor Admidio
Product admidio
Versions
  • Version < 5.0.10 is affected

References

Problem Types

  • CWE-352: Cross-Site Request Forgery (CSRF) CWE