CVE-2024-47836

LOW

admidio < 4.3.12 - Unauthenticated Remote Code Execution via Unsafe Deserialization

Title source: llm
STIX 2.1

Description

Admidio is an open-source user management solution. Prior to version 4.3.12, an unsafe deserialization vulnerability allows any unauthenticated user to execute arbitrary code on the server. Version 4.3.12 fixes this issue.

References (1)

Core 1
Core References

Scores

CVSS v3 3.5
EPSS 0.0047
EPSS Percentile 36.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-502 CWE-79
Status published
Products (2)
admidio/admidio < 4.3.12
admidio/admidio 0 - 4.3.12Packagist
Published Oct 16, 2024
Tracked Since Feb 18, 2026