{"id":"GHSA-7fh7-8xqm-3g88","summary":"Admidio allows Unauthenticated Access to Role-Restricted documents via neutralized .htaccess","details":"### Summary\n\nAdmidio relies on `adm_my_files/.htaccess` to deny direct HTTP access to uploaded documents. The Docker image ships with `AllowOverride None` in the Apache configuration, which causes Apache to silently ignore all `.htaccess` files. As a result, any file uploaded to the\ndocuments module regardless of the _role-based_ permissions configured in the UI, is directly accessible over HTTP without authentication by anyone who knows the file path. The file path is disclosed in the upload response JSON.\n\n---\n\n### Root Cause\n\n**File 1: Intended protection (ignored):**  \n`adm_my_files/.htaccess`\n```apache\nRequire all denied\n```\n\u003cimg width=\"408\" height=\"403\" alt=\"imagen\" src=\"https://github.com/user-attachments/assets/95f0d389-a1a9-4dc4-9840-7f189d2c58ff\" /\u003e\n\n**File 2: Apache config that neutralizes it:**  \n\n* Command in order to search in Docker container: `docker exec admidio-sec-app cat /etc/apache2/apache2.conf`\n\n`/etc/apache2/apache2.conf` (Docker image)\n```apache\n\u003cDirectory ${APACHE_DOCUMENT_ROOT}\u003e\n    AllowOverride None\n\u003c/Directory\u003e\n```\n\n\u003cimg width=\"492\" height=\"328\" alt=\"imagen\" src=\"https://github.com/user-attachments/assets/2f2e09b1-0c2e-4932-8698-a40f6b92e917\" /\u003e\n\n\n`AllowOverride None` instructs Apache to skip `.htaccess` processing entirely, the deny rule never executes. The upload directory is inside the web root at `/opt/app-root/src/adm_my_files/` and returns **HTTP 200** for direct requests.\n\n**File 3: Upload response leaks the direct URL:**  `system/file_upload.php`, upload response JSON:\n\n\u003cimg width=\"1528\" height=\"624\" alt=\"imagen\" src=\"https://github.com/user-attachments/assets/50e66fde-ff41-4efa-adc9-ceeb5b23a97d\" /\u003e\n\n```json\n{\n  \"files\": [{\n    \"name\": \"sensitive_poc.txt\",\n    \"url\": \"http://TARGET/adm_my_files/documents_research/TEST-SENSITIVE/sensitive_poc.txt\"\n  }]\n}\n```\n\n### Verified PoC\n\n**Step 1: Admin creates a restricted folder (visible only to Administrator role):**  \n\u003e `modules/documents-files.php` → permissions set to role `Administrator` only.\n\n\u003cimg width=\"1161\" height=\"784\" alt=\"imagen\" src=\"https://github.com/user-attachments/assets/25d81e44-9a7c-4991-b72e-6e664d176695\" /\u003e\n\n**Step 2: Admin uploads a file to the restricted folder.**  \n\u003e Upload response returns:\n```\nhttp://TARGET/adm_my_files/documents_research/TEST-SENSITIVE/sensitive_poc.txt\n```\n\n\u003cimg width=\"1239\" height=\"294\" alt=\"imagen\" src=\"https://github.com/user-attachments/assets/84c1bcd1-47d7-4115-ac0f-653b0a6d7301\" /\u003e\n\n**Step 3: Unauthenticated request retrieves the file:**\n```bash\ncurl -X GET 'http://TARGET/adm_my_files/documents_research/TEST-SENSITIVE/sensitive_poc.txt'\n# Response: full file contents — no authentication required\n```\n\n\u003cimg width=\"1051\" height=\"150\" alt=\"imagen\" src=\"https://github.com/user-attachments/assets/1ed7fab7-59cb-4d5b-8c60-12108490d1e4\" /\u003e\n\n**Step 4: Confirm folder is role-restricted:**\n```sql\nSELECT fil_name, fol_name, fol_public FROM adm_files JOIN adm_folders ON fil_fol_id = fol_id \nORDER BY fil_id DESC LIMIT 5; -- fol_public = 0, role restricted — yet file is publicly accessible\n```\n---\n\n### Impact\n\n- Any document uploaded to **Admidio** including files restricted to specific roles is publicly accessible via direct HTTP request with no authentication required\n- **Role-based** access control on the documents module is completely bypassed at the filesystem level\n- Sensitive organizational documents (contracts, member data, financial records) are exposed to anyone who can guess or construct the file path\n- The upload API response discloses the direct URL to the uploader, making path enumeration trivial\n\n### Recommended Fix\n\n**Option 1 (preferred): Enable AllowOverride in Apache config:**\n```apache\n\u003cDirectory /opt/app-root/src/adm_my_files\u003e\n    AllowOverride All\n\u003c/Directory\u003e\n```\n\n**Option 2: Move uploads outside the web root:**  \nStore uploaded files in a directory outside `DOCUMENT_ROOT` and serve them exclusively through Admidio's download handler (`modules/documents-files.php?mode=download`), which enforces role checks before serving the file.\n\n**Option 3: Apache-level explicit deny (does not require .htaccess):**\n```apache\n\u003cDirectory /opt/app-root/src/adm_my_files\u003e\n    Require all denied\n\u003c/Directory\u003e\n```\n\u003e The most robust long-term fix is Option 2 — moving uploads outside the web root eliminates the dependency on Apache configuration correctness entirely.\n\n**Reported by:** Juan Felipe Oz [@JF0x0r](https://x.com/PwnedRar_)\n\u003e [LinkedIn](https://www.linkedin.com/in/juanfelipeoz/)","aliases":["CVE-2026-34381"],"modified":"2026-03-31T23:26:27.452415Z","published":"2026-03-31T23:10:03Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-03-31T23:10:03Z","nvd_published_at":"2026-03-31T21:16:30Z","cwe_ids":["CWE-284"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/Admidio/admidio/security/advisories/GHSA-7fh7-8xqm-3g88"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34381"},{"type":"WEB","url":"https://github.com/Admidio/admidio/commit/5f770c1ca81a4f6b02136280cd63316a35aabaaf"},{"type":"PACKAGE","url":"https://github.com/Admidio/admidio"}],"affected":[{"package":{"name":"admidio/admidio","ecosystem":"Packagist","purl":"pkg:composer/admidio/admidio"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.0.8"}]}],"versions":["v5.0.0","v5.0.1","v5.0.2","v5.0.3","v5.0.4","v5.0.5","v5.0.6","v5.0.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-7fh7-8xqm-3g88/GHSA-7fh7-8xqm-3g88.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}