Markus Faßbender
20 exploits
Active since Apr 2020
admidio < 4.0.12 - Reflected Cross-Site Scripting via redirect.php URL Parameter
CVSS 8.8
Admidio: Unauthenticated Access to Role-Restricted documents via neutralized .htaccess
CVSS 7.5
Admidio: Missing CSRF Protection on Custom List Deletion in mylist_function.php
CVSS 4.6
Admidio: CSRF and Form Validation Bypass in Inventory Item Save via `imported` Parameter
CVSS 4.3
Admidio: Missing CSRF Protection on Registration Approval Actions
CVSS 4.5
Admidio Vulnerable to SSRF and Local File Read via Unrestricted URL Fetch in SSO Metadata Endpoint
CVSS 6.8
Admidio: Second-Order SQL Injection via List Configuration (lsc_special_field, lsc_sort, lsc_filter)
CVSS 8.0
Admidio <5.0.6 - Privilege Escalation
CVSS 5.4
Admidio < 3.3.13 - Unauthenticated SQL Injection via Main Cookie Parameter
CVSS 7.7
admidio < 4.0.12 - Reflected Cross-Site Scripting via redirect.php URL Parameter
CVSS 8.8
admidio < 4.1.9 - Insufficient Session Expiration
CVSS 7.1
admidio < 4.2.8 - Stored Cross-Site Scripting
CVSS 5.4
admidoi/admidio <4.2.9 - Info Disclosure
CVSS 7.8
admidio/admidio <4.2.9 - Info Disclosure
CVSS 3.5
admidio/admidio <4.2.9 - Info Disclosure
CVSS 5.4
admidio < 4.2.10 - Unrestricted Upload of File with Dangerous Type
CVSS 7.2
admidio < 4.2.11 - Insufficient Session Expiration
CVSS 6.5
Admidio < 4.3.9 - Authenticated SQL Injection via ecard_recipients POST Parameter
CVSS 9.9
Admidio < 4.3.10 - Remote Code Execution via Unrestricted PHP File Upload in Message Module
CVSS 9.0
Admidio < 4.3.17 - Authenticated SQL Injection in Member Assignment Data Retrieval
CVSS 7.2