<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T03:31:48.618924+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-277437</id>
    <title>EUVD-2026-277437</title>
    <updated>2026-10-08T03:31:48.621311+00:00</updated>
    <content>EUVD-2026-277437</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-277437"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32755</id>
    <title>fkie_cve-2026-32755</title>
    <updated>2026-10-08T03:31:48.621343+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Admidio is an open-source user management solution. In versions 5.0.6 and below, the save_membership action in modules/profile/profile_function.php saves changes to a member's role membership start and end dates but does not validate the CSRF token. The handler checks stop_membership and remove_former_membership against the CSRF token but omits save_membership from that check. Because membership UUIDs appear in the HTML source visible to authenticated users, an attacker can embed a crafted POST form on any external page and trick a role leader into submitting it, silently altering membership dates for any member of roles the victim leads. A role leader's session can be silently exploited via CSRF to manipulate any member's membership dates, terminating access by backdating, covertly extending unauthorized access, or revoking role-restricted features, all without confirmation, notification, or administrative approval. This issue has been fixed in version 5.0.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32755"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h8gr-qwr6-m9gx</id>
    <title>GHSA-h8gr-qwr6-m9gx — Admidio is Missing CSRF Protection on Role Membership Date Changes</title>
    <updated>2026-10-08T03:31:48.621379+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: admidio/admidio</p>
<p>## Summary</p>
<p>The `save_membership` action in `modules/profile/profile_function.php` saves changes to a member's role membership start and end dates but does not validate the CSRF token. The handler checks `stop_membership` and `remove_former_membership` against the CSRF token but omits `save_membership` from that check. Because membership UUIDs appear in the HTML source visible to authenticated users, an attacker can embed a crafted POST form on any external page and trick a role leader into submitting it, silently altering membership dates for any member of roles the victim leads.</p>
<p>## Details</p>
<p>### CSRF Check Is Absent for save_membership</p>
<p>File: `D:/bugcrowd/admidio/repo/modules/profile/profile_function.php`, lines 40-42</p>
<p>The CSRF guard covers only two of the three mutative modes:</p>
<p>```php
if (in_array($getMode, array('stop_membership', 'remove_former_membership'))) {
    // check the CSRF token of the form against the session token
    SecurityUtils::validateCsrfToken($_POST['adm_csrf_token']);
}
```</p>
<p>The `save_membership` mode is missing from this array. The handler then proceeds to read dates from `$_POST` and update the database without any token verification:</p>
<p>```php
} elseif ($getMode === 'save_membership') {
    $postMembershipStart = admFuncVariableIsValid($_POST, 'adm_membership_start_date', 'date', array('requireValue' =&gt; true));
    $postMembershipEnd   = admFuncVariableIsValid($_POST, 'adm_membership_end_date',   'date', array('requireValue' =&gt; true));</p>
<p>$member…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h8gr-qwr6-m9gx"/>
  </entry>
</feed>
