What is CVE-2026-47234?
CVE-2026-47234 affects Admidio, an open-source user management solution, prior to version 5.0.10, where debug logging enabled exposes full cookie values via `Session::setCookie()` and the session ID via `Session::start()` in log files. This can lead to session hijacking if logs are compromised. It is recommended to disable debug logging and update to the latest version.
Azərbaycanca: CVE-2026-47234 Admidio açıq mənbəli istifadəçi idarəetmə sistemində debug logging aktiv olduqda, `Session::setCookie()` funksiyası tam cookie məlumatlarını, `Session::start()` isə cari sessiya ID-sini log fayllarına yazır. Bu, tətbiqin 5.0.10 versiyasından əvvəlki versiyalarına təsir edir. Təhlükəsizlik üçün debug logging-i söndürmək və sisteminizi ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of Admidio are affected by CVE-2026-47234?
This vulnerability affects versions of Admidio prior to 5.0.10.
What measures are recommended to mitigate CVE-2026-47234?
It is recommended to disable debug logging and update the system to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.