CVE-2026-69093
Severity CVSS v4.0:
HIGH
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
03/08/2026
Last modified:
03/08/2026
Description
Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs persistent Category Report configuration changes based on GET parameters (delete and copy). An attacker can trick an authenticated administrator into visiting a crafted URL to delete or duplicate Category Report configurations, affecting the integrity and availability of that module's configuration.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH
Base Score 3.x
4.60
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/Admidio/admidio/commit/e1fe6fd2fcafb6a65a550760f79447abdef31461
- https://github.com/Admidio/admidio/security/advisories/GHSA-mvx3-m6p6-7r9w
- https://www.vulncheck.com/advisories/admidio-before-csrf-via-category-report-preferences
- https://github.com/Admidio/admidio/security/advisories/GHSA-mvx3-m6p6-7r9w



