-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stemmed from missing access control checks in ecard handling. The patch added critical $photoAlbum->isVisible() checks and parameter validation. In ecard_send.php, the original flow lacked visibility verification after module checks. In ecards.php, the photo_uuid wasn't strictly required and visibility checks were incomplete. The TablePhotos::isVisible() function's improvement (strict boolean check) indicates previous access control bypass possibilities through pho_locked field handling.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| admidio/admidio | composer | < 4.2.9 | 4.2.9 |
KEV Misses 88% of Exploited CVEs- Get the report