In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Cross-site Request Forgery (CSRF) vulnerabilities in an interactive lesson.
Start learningUpgrade admidio/admidio to version 5.0.10 or higher.
admidio/admidio is a free open source user management system for websites of organizations and groups.
Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) through the send_login process in modules/registration.php when a registration-administrator visits a crafted page. An attacker can cause arbitrary user passwords to be reset and potentially lock users out of their accounts by tricking an administrator into visiting a malicious site that issues a GET request to the vulnerable endpoint. This can also result in the victim receiving an unsolicited password reset email, which could be used for social engineering.