Cross-site Request Forgery (CSRF) Affecting admidio/admidio package, versions >=5.0-Beta.1, <5.0.7


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.02% (5th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Cross-site Request Forgery (CSRF) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-ADMIDIOADMIDIO-15679890
  • published18 Mar 2026
  • disclosed16 Mar 2026
  • creditrestriction

Introduced: 16 Mar 2026

CVE-2026-32816  (opens in a new tab)
CWE-352  (opens in a new tab)

How to fix?

Upgrade admidio/admidio to version 5.0.7 or higher.

Overview

admidio/admidio is a free open source user management system for websites of organizations and groups.

Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) via the groups_roles.php process. An attacker can cause unauthorized deletion, activation, or deactivation of organizational roles by tricking a user with the appropriate role management rights into submitting a forged request from an external site. This can result in permanent loss of roles, cascading deletion of memberships and permissions, or revocation of access for entire groups.

References

CVSS Base Scores

version 4.0
version 3.1