CVE Explorer
CVE-2026-32813
Admidio is an open-source user management solution. Versions 5.0.6 and below are vulnerable to arbitrary SQL Injection through the MyList configuration feature. The MyList configuration feature lets authenticated users define custom list column layouts, storing user-supplied column names, sort directions, and filter conditions in the adm_list_columns table via prepared statements. However, these stored values are later read back and interpolated directly into dynamically constructed SQL queries
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"admidio","vendor":"Admidio","versions":[{"status":"affected","version":"< 5.0.7"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2ac6891d922b5d1d389544de3f4f3c3c5b1d3af61fa63f67ffa6b41cf20d1e59 · sha256:236f91efd2efa091… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:2ac6891d922b5d1d389544de3f4f3c3c5b1d3af61fa63f67ffa6b41cf20d1e59 · sha256:236f91efd2efa091… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-89","description":"CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2ac6891d922b5d1d389544de3f4f3c3c5b1d3af61fa63f67ffa6b41cf20d1e59 · sha256:236f91efd2efa091… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/Admidio/admidio/commit/3473bf5a7aa1bfc5043e73979719396276f4189f","tags":["x_refsource_MISC"],"url":"https://github.com/Admidio/admidio/commit/3473bf5a7aa1bfc5043e73979719396276f4189f"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2ac6891d922b5d1d389544de3f4f3c3c5b1d3af61fa63f67ffa6b41cf20d1e59 · sha256:236f91efd2efa091… · /containers/cna/references/1
{"name":"https://github.com/Admidio/admidio/security/advisories/GHSA-3x67-4c2c-w45m","tags":["x_refsource_CONFIRM"],"url":"https://github.com/Admidio/admidio/security/advisories/GHSA-3x67-4c2c-w45m"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2ac6891d922b5d1d389544de3f4f3c3c5b1d3af61fa63f67ffa6b41cf20d1e59 · sha256:236f91efd2efa091… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/Admidio/admidio/security/advisories/GHSA-3x67-4c2c-w45m"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2ac6891d922b5d1d389544de3f4f3c3c5b1d3af61fa63f67ffa6b41cf20d1e59 · sha256:236f91efd2efa091… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.