CVE-2017-8382 describes a Cross-Site Request Forgery (CSRF) vulnerability in admidio version 3.2.8, specifically within the members_function.php file. This flaw allows an authenticated attacker to delete arbitrary user accounts by tricking a high-privileged user into clicking a malicious link. While the CVSS score is 4.5 (Medium), indicating a low attack complexity and high impact on availability, it requires user interaction and high privileges. Despite the existence of a public exploit (EDB-42005), there is no evidence of active exploitation, Metasploit or Nuclei modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.2.8CPE matchmatch criteria | cpe:2.3:a:admidio:admidio:3.2.8:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.