<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 22:46:59 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-280175</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-280175</link>
      <description>EUVD-2026-280175</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-280175</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34383</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34383</link>
      <description>&lt;p&gt;Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module&amp;#39;s item_save endpoint accepts a user-controllable POST parameter imported that, when set to true, completely bypasses both CSRF token validation and server-side form validation. An authenticated user can craft a direct POST request to save arbitrary inventory item data without CSRF protection and without the field value checks that the FormPresenter validation normally enforces. This issue has been patched in version 5.0.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module&amp;#39;s item_save endpoint accepts a user-controllable POST parameter imported that, when set to true, completely bypasses both CSRF token validation and server-side form validation. An authenticated user can craft a direct POST request to save arbitrary inventory item data without CSRF protection and without the field value checks that the FormPresenter validation normally enforces. This issue has been patched in version 5.0.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34383</guid>
    </item>
    <item>
      <title>GHSA-4rwm-c5mj-wh7x — Admidio has CSRF and Form Validation Bypass in Inventory Item Save via `imported` Parameter</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4rwm-c5mj-wh7x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: admidio/admidio&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The inventory module&amp;#39;s `item_save` endpoint accepts a user-controllable POST parameter `imported` that, when set to `true`, completely bypasses both CSRF token validation and server-side form validation. An authenticated user can craft a direct POST request to save arbitrary inventory item data without CSRF protection and without the field value checks that the `FormPresenter` validation normally enforces.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;In `modules/inventory.php`, the `imported` parameter is read from POST input:&lt;/p&gt;
&lt;p&gt;**File:** `modules/inventory.php:50`
```php
$postImported = admFuncVariableIsValid($_POST, &amp;#39;imported&amp;#39;, &amp;#39;bool&amp;#39;, array(&amp;#39;defaultValue&amp;#39; =&amp;gt; false));
```&lt;/p&gt;
&lt;p&gt;This is then passed to `ItemService`:&lt;/p&gt;
&lt;p&gt;**File:** `modules/inventory.php:251-256`
```php
$itemService = new ItemService($gDb, $itemUuid, $postCopyField, $postCopyNumber, $postImported);
$itemService-&amp;gt;save(true);
```&lt;/p&gt;
&lt;p&gt;Inside `ItemService::save()`, the `postImported` flag completely skips CSRF and form validation:&lt;/p&gt;
&lt;p&gt;**File:** `src/Inventory/Service/ItemService.php:99-109`
```php
public function save(bool $multiEdit = false): void
{
    global $gCurrentSession, $gL10n, $gSettingsManager;&lt;/p&gt;
&lt;p&gt;// check form field input and sanitized it from malicious content
    if (!$this-&amp;gt;postImported) {
        $itemFieldsEditForm = $gCurrentSession-&amp;gt;getFormObject($_POST[&amp;#39;adm_csrf_token&amp;#39;]);
        $formValues = $itemFieldsEditForm-&amp;gt;validate($_POST, $multiEdit);
    } else {
        $formValues = $_POST;   // Raw $_POST used with no CSRF check,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: admidio/admidio&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The inventory module&amp;#39;s `item_save` endpoint accepts a user-controllable POST parameter `imported` that, when set to `true`, completely bypasses both CSRF token validation and server-side form validation. An authenticated user can craft a direct POST request to save arbitrary inventory item data without CSRF protection and without the field value checks that the `FormPresenter` validation normally enforces.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;In `modules/inventory.php`, the `imported` parameter is read from POST input:&lt;/p&gt;
&lt;p&gt;**File:** `modules/inventory.php:50`
```php
$postImported = admFuncVariableIsValid($_POST, &amp;#39;imported&amp;#39;, &amp;#39;bool&amp;#39;, array(&amp;#39;defaultValue&amp;#39; =&amp;gt; false));
```&lt;/p&gt;
&lt;p&gt;This is then passed to `ItemService`:&lt;/p&gt;
&lt;p&gt;**File:** `modules/inventory.php:251-256`
```php
$itemService = new ItemService($gDb, $itemUuid, $postCopyField, $postCopyNumber, $postImported);
$itemService-&amp;gt;save(true);
```&lt;/p&gt;
&lt;p&gt;Inside `ItemService::save()`, the `postImported` flag completely skips CSRF and form validation:&lt;/p&gt;
&lt;p&gt;**File:** `src/Inventory/Service/ItemService.php:99-109`
```php
public function save(bool $multiEdit = false): void
{
    global $gCurrentSession, $gL10n, $gSettingsManager;&lt;/p&gt;
&lt;p&gt;// check form field input and sanitized it from malicious content
    if (!$this-&amp;gt;postImported) {
        $itemFieldsEditForm = $gCurrentSession-&amp;gt;getFormObject($_POST[&amp;#39;adm_csrf_token&amp;#39;]);
        $formValues = $itemFieldsEditForm-&amp;gt;validate($_POST, $multiEdit);
    } else {
        $formValues = $_POST;   // Raw $_POST used with no CSRF check,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4rwm-c5mj-wh7x</guid>
    </item>
  </channel>
</rss>
