CVE-2024-47836 LOW

CVE-2024-47836: Admidio vulnerable to HTML Injection In The Messages Section

Vendor Admidio
Product admidio
Weakness CWE-502 · Unsafe deserialization
Published October 16, 2024
Last update October 16, 2024

CVSS base score

3.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Admidio is an open-source user management solution. Prior to version 4.3.12, an unsafe deserialization vulnerability allows any unauthenticated user to execute arbitrary code on the server. Version 4.3.12 fixes this issue.

Key dates

02Disclosure timeline

October 16, 2024 CVE published
October 16, 2024 Record updated