Vulnerability Description
Admidio is an open-source user management solution. Prior to version 5.0.9, the ecard_preview.php endpoint does not validate that the ecard_template POST parameter is a safe filename before passing it to ECard::getEcardTemplate(). An authenticated user can supply a path traversal payload (e.g., ../config.php) to read arbitrary files accessible to the web server process, including adm_my_files/config.php which contains database credentials. This issue has been patched in version 5.0.9.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/Admidio/admidio/releases/tag/v5.0.9
- https://github.com/Admidio/admidio/security/advisories/GHSA-m3vp-3jjm-gpmx
- https://github.com/Admidio/admidio/security/advisories/GHSA-m3vp-3jjm-gpmx
FAQ
What is CVE-2026-41655?
CVE-2026-41655 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Admidio is an open-source user management solution. Prior to version 5.0.9, the ecard_preview.php endpoint does not validate that the ecard_template POST parameter is a safe filename before passing it...
How severe is CVE-2026-41655?
CVE-2026-41655 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-41655?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.