What is CVE-2026-47231?
This critical vulnerability in the open-source user management solution Admidio stems from improper authorization checks in the `move_save` handler within `modules/documents-files.php`. The code verifies `hasUploadRight()` against the `folder_uuid` parameter but performs the move action on the `file_uuid` parameter, allowing authenticated users to move files from folders where they lack upload rights. Immediate update to version 5.0.10 is required.
Azərbaycanca: Admidio istifadəçi idarəetmə həllində aşkarlanan bu kritik zəiflik `modules/documents-files.php` faylındakı `move_save` əməliyyatında səlahiyyət yoxlamasının səhv parametr üzərində aparılması ilə bağlıdır. Bu, autentifikasiya olunmuş istifadəçiyə öz yükləmə hüququ olmayan qovluqlardakı faylları başqa yerə daşımağa imkan verir. Təcili olaraq 5.0.10 versiyasına yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
In which component of Admidio was CVE-2026-47231 discovered?
The vulnerability was discovered in the `move_save` handler within `modules/documents-files.php`.
What is the recommended immediate fix for CVE-2026-47231?
An immediate update to Admidio version 5.0.10 is required.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.