CVE-2026-34384 | admidio up to 5.0.7 URL modules/registration.php create_user/assign_member/assign_user cross-site request forgery (GHSA-ph84-r98x-2j22)
A vulnerability, which was classified as problematic, has been found in admidio up to 5.0.7. Affected by this issue is the function create_user/assign_member/assign_user of the file modules/registration.php of the component URL Handler. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2026-34384. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.