Admidio is an open-source user management solution. Prior to version 4.3.12, an unsafe deserialization vulnerability allows any unauthenticated user to execute arbitrary code on the server. Version 4.3.12 fixes this issue.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/Admidio/admidio/security/advisories/GHSA-7c4c-749j-pfp2 | vendor advisory |