{"id":"GHSA-rw74-vc9h-534j","summary":"Admidio has CSRF on Admin Preferences that Triggers Unauthorized Backup, .htaccess Write, and Email Send","details":"## Summary\n\nSeveral administrative operations in Admidio's preferences module (database backup, test email, htaccess generation) fire via GET requests with no CSRF token validation. Because `SameSite=Lax` cookies travel with top-level GET navigations, an attacker forces an authenticated admin to trigger these actions from a malicious page.\n\n## Details\n\nIn `modules/preferences.php`, the `backup`, `test_email`, and `htaccess` modes accept GET parameters with no CSRF token check:\n\n```php\n// modules/preferences.php - backup mode\ncase 'backup':\n    // Creates full database dump and serves as download\n    // No CSRF token validation\n    $backupFile = $gDb-\u003ebackup();\n    // ... sends file to client\n    break;\n\ncase 'test_email':\n    // Sends test email from the server\n    // No CSRF token validation\n    break;\n\ncase 'htaccess':\n    // Writes .htaccess file to disk\n    // No CSRF token validation\n    break;\n```\n\nThe `save` mode in the same file validates CSRF via `getFormObject()`, confirming the developers intended CSRF protection but did not apply it to these other modes.\n\nBecause these are GET requests, `SameSite=Lax` browsers include session cookies on top-level cross-origin navigations, making CSRF exploitation trivial.\n\n## Proof of Concept\n\nSimplified attacker page (`csrf.html` hosted on attacker origin):\n\n```html\n\u003chtml\u003e\n\u003cbody\u003e\n\u003ch1\u003eLoading...\u003c/h1\u003e\n\u003c!-- Trigger backup creation on victim's browser --\u003e\n\u003cscript\u003ewindow.location = 'https://target-admidio.example.com/adm_program/modules/preferences.php?mode=backup';\u003c/script\u003e\n\u003c/body\u003e\n\u003c/html\u003e\n```\n\nWhen an administrator visits this page, the browser navigates to the Admidio backup URL with full session cookies. The server generates a database dump and serves it as a download to the victim's browser. Note: the backup downloads to the victim's machine, not to the attacker. The attacker cannot read the response cross-origin.\n\nFor `htaccess` mode, the CSRF overwrites the `.htaccess` file on the server, disrupting the application. For `test_email` mode, it triggers email sends from the server, which an attacker can abuse for spam or to probe internal email infrastructure.\n\n## Impact\n\nAn attacker tricks an Admidio administrator into visiting a malicious page that triggers state-changing operations on the server:\n\n- **Backup creation**: forces the server to generate a full database dump. The backup downloads to the victim's browser, not to the attacker. However, repeated backup triggers can cause disk I/O and storage pressure on the server.\n- **htaccess modification**: overwrites the server's `.htaccess` file, breaking URL routing or disabling security headers.\n- **Test email**: fires email sends from the server, usable as a spam relay or to probe internal mail configuration.\n\nThe core issue is that state-changing operations run via unprotected GET requests. The victim only needs to visit a single attacker-controlled page while logged in.\n\n## Recommended Fix\n\n1. Change `backup`, `test_email`, and `htaccess` operations to require POST requests.\n2. Add CSRF token validation using the existing `getFormObject()` mechanism.\n3. As defense in depth, set `SameSite=Strict` on session cookies or add a confirmation step for destructive operations like database backup.\n\n---\n*Found by [aisafe.io](https://aisafe.io)*","aliases":["CVE-2026-41663"],"modified":"2026-05-08T20:32:25.355827Z","published":"2026-04-29T21:54:30Z","database_specific":{"github_reviewed_at":"2026-04-29T21:54:30Z","nvd_published_at":"2026-05-07T04:16:30Z","cwe_ids":["CWE-352"],"severity":"LOW","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/Admidio/admidio/security/advisories/GHSA-rw74-vc9h-534j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41663"},{"type":"PACKAGE","url":"https://github.com/Admidio/admidio"},{"type":"WEB","url":"https://github.com/Admidio/admidio/releases/tag/v5.0.9"}],"affected":[{"package":{"name":"admidio/admidio","ecosystem":"Packagist","purl":"pkg:composer/admidio/admidio"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.0.9"}]}],"versions":["4.1.0","4.1.3","v4.2-Beta.1","v4.2-Beta.2","v4.2-Beta.3","v4.2.0","v4.2.1","v4.2.10","v4.2.11","v4.2.12","v4.2.13","v4.2.14","v4.2.2","v4.2.3","v4.2.4","v4.2.5","v4.2.6","v4.2.7","v4.2.8","v4.2.9","v4.3-Beta.1","v4.3-Beta.3","v4.3-Beta.4","v4.3-Beta.5","v4.3.0","v4.3.1","v4.3.10","v4.3.11","v4.3.12","v4.3.13","v4.3.14","v4.3.15","v4.3.16","v4.3.17","v4.3.2","v4.3.3","v4.3.4","v4.3.5","v4.3.6","v4.3.7","v4.3.8","v4.3.9","v5.0-Beta.1","v5.0-Beta.2","v5.0-Beta.3","v5.0.0","v5.0.1","v5.0.2","v5.0.3","v5.0.4","v5.0.5","v5.0.6","v5.0.7","v5.0.8"],"database_specific":{"last_known_affected_version_range":"\u003c= 5.0.8","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-rw74-vc9h-534j/GHSA-rw74-vc9h-534j.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:L"}]}