<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T22:48:50.188264+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-280175</id>
    <title>EUVD-2026-280175</title>
    <updated>2026-10-07T22:48:50.190746+00:00</updated>
    <content>EUVD-2026-280175</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-280175"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34383</id>
    <title>fkie_cve-2026-34383</title>
    <updated>2026-10-07T22:48:50.190789+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module's item_save endpoint accepts a user-controllable POST parameter imported that, when set to true, completely bypasses both CSRF token validation and server-side form validation. An authenticated user can craft a direct POST request to save arbitrary inventory item data without CSRF protection and without the field value checks that the FormPresenter validation normally enforces. This issue has been patched in version 5.0.8.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34383"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4rwm-c5mj-wh7x</id>
    <title>GHSA-4rwm-c5mj-wh7x — Admidio has CSRF and Form Validation Bypass in Inventory Item Save via `imported` Parameter</title>
    <updated>2026-10-07T22:48:50.190834+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: admidio/admidio</p>
<p>## Summary</p>
<p>The inventory module's `item_save` endpoint accepts a user-controllable POST parameter `imported` that, when set to `true`, completely bypasses both CSRF token validation and server-side form validation. An authenticated user can craft a direct POST request to save arbitrary inventory item data without CSRF protection and without the field value checks that the `FormPresenter` validation normally enforces.</p>
<p>## Details</p>
<p>In `modules/inventory.php`, the `imported` parameter is read from POST input:</p>
<p>**File:** `modules/inventory.php:50`
```php
$postImported = admFuncVariableIsValid($_POST, 'imported', 'bool', array('defaultValue' =&gt; false));
```</p>
<p>This is then passed to `ItemService`:</p>
<p>**File:** `modules/inventory.php:251-256`
```php
$itemService = new ItemService($gDb, $itemUuid, $postCopyField, $postCopyNumber, $postImported);
$itemService-&gt;save(true);
```</p>
<p>Inside `ItemService::save()`, the `postImported` flag completely skips CSRF and form validation:</p>
<p>**File:** `src/Inventory/Service/ItemService.php:99-109`
```php
public function save(bool $multiEdit = false): void
{
    global $gCurrentSession, $gL10n, $gSettingsManager;</p>
<p>// check form field input and sanitized it from malicious content
    if (!$this-&gt;postImported) {
        $itemFieldsEditForm = $gCurrentSession-&gt;getFormObject($_POST['adm_csrf_token']);
        $formValues = $itemFieldsEditForm-&gt;validate($_POST, $multiEdit);
    } else {
        $formValues = $_POST;   // Raw $_POST used with no CSRF check,…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4rwm-c5mj-wh7x"/>
  </entry>
</feed>
