CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-47228

mediumCVSS 5.2covered by 1 sourcefirst seen 2026-08-12
Admidio is an open-source user management solution. modules/registration.php mode send_login regenerates a random password for user_uuid_assigned, stores its bcrypt hash in adm_users.usr_password, and emails the cleartext to that user. Every other state-changing mode in the same file (assign_member, assign_user, delete_user, create_user) calls SecurityUtils::validateCsrfToken($_POST['adm_csrf_token']) first; the send_login branch does not. Prior to version 5.0.10, page visited by a registration-administrator can issue the request as a top-level navigation, the browser sends the admin's SameSite=Lax cookies, and the server resets the chosen user's password without any further interaction from the admin. Version 5.0.10 fixes the issue.

⚡ Watch CVE-2026-47228

Get an email if CVE-2026-47228 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-47228

CVE.org record

Embed the live status

CVE-2026-47228 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-47228 status](https://www.csirts.com/badge/CVE-2026-47228)](https://www.csirts.com/cve/CVE-2026-47228)