What is CVE-2026-47232?
This vulnerability in Admidio allows a remote attacker to obtain the private key and certificate by exploiting a missing CSRF check in the `mode=export` action of `modules/sso/keys.php`. Versions before 5.0.10 are affected, and users should urgently upgrade.
Azərbaycanca: Admidio istifadəçi idarəetmə həllində aşkar edilmiş bu boşluq, `modules/sso/keys.php` faylında CSRF qorunması söndürüldüyü üçün uzaqdan hücumçuya `mode=export` sorğusu ilə şəxsi açarı və sertifikatı əldə etməyə imkan verir. 5.0.10-dan əvvəlki versiyalar təsirlənir, istifadəçilərə dərhal yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352; shared vendor: Admidio
FAQ2
What request in `modules/sso/keys.php` allows a remote attacker to obtain the private key in CVE-2026-47232?
A `mode=export` request.
Which versions of Admidio are affected by CVE-2026-47232?
Versions before 5.0.10 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.