CVE-2026-32813: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-32813 is a second-order SQL injection vulnerability in Admidio, an open-source user management solution. It affects all versions up to and including 5.0.6, and was disclosed on March 15, 2026, with a fix released in version 5.0.7. The vulnerability resides in the MyList configuration feature, where user-supplied values are safely stored via prepared statements but later interpolated unsanitized into dynamically constructed SQL queries. It carries a CVSS v3.1 base score of 8.0 (High) (GitHub Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The root cause is a classic second-order SQL injection pattern: user-supplied column names (lsc_special_field), sort directions (lsc_sort), and filter conditions (lsc_filter) are stored safely in the adm_list_columns table via prepared statements in mylist_function.php, but are later read back and directly interpolated into dynamically constructed SQL queries within ListConfiguration::getSql() without sanitization or parameterization. There are four distinct injection points: (1) lsc_special_field in the SELECT clause, (2) lsc_sort in the ORDER BY clause, (3) lsc_special_field in COALESCE search conditions, and (4) lsc_filter via ConditionParser. The only pre-storage validation for column names was a trivially bypassable prefix check (usr_ or mem_), and sort/condition values had no server-side validation at all (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an authenticated low-privilege attacker to inject arbitrary SQL, enabling full database compromise. Specific consequences include exfiltration of sensitive data (password hashes, email addresses, personal member data, application configuration), modification or deletion of any database records, and privilege escalation by extracting and cracking password hashes or directly modifying administrator accounts. Because the injected payload persists in the database and executes every time any user views the affected list, the impact can extend beyond the initial attacker to affect all users of the application (GitHub Advisory).

Exploitability

A proof-of-concept (PoC) with concrete step-by-step curl commands and specific SQL injection payloads is publicly available in the GitHub Security Advisory. Exploitation requires authentication and a valid CSRF token, but by default all logged-in users have list edit permissions (groups_roles_edit_lists = 1), making the attack surface broad. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is 0.03% (very low probability of exploitation in the near term), and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, Feedly).

Exploitation steps

  1. Authenticate: Obtain valid session credentials for any Admidio account with list edit permissions (default for all logged-in users) and retrieve the CSRF token from the active session.
  2. Craft injection payload for SELECT clause: Send a POST request to mylist_function.php?mode=save_temporary with a malicious column value that passes the usr_ prefix check, e.g., column[]=usr_id FROM adm_users)--. This stores the payload safely in the adm_list_columns table.
    curl -X POST "https://TARGET/adm_program/modules/groups-roles/mylist_function.php?mode=save_temporary" \
      -H "Cookie: ADMIDIO_SESSION_ID=<session>" \
      -d "adm_csrf_token=<token>" \
      -d "column[]=usr_login_name" \
      -d "column[]=usr_id FROM adm_users)--" \
      -d "sort[]=" -d "sort[]=" -d "condition[]=" -d "condition[]=" -d "sel_roles[]=<role_uuid>"
  3. Alternative: ORDER BY injection: Inject into the sort parameter (no prefix check required), e.g., sort[]=ASC,(SELECT+CASE+WHEN+(1=1)+THEN+1+ELSE+1/0+END) to perform boolean-based blind SQL injection via the ORDER BY clause.
  4. Trigger payload execution: The save_temporary mode automatically redirects to lists_show.php, which calls ListConfiguration::getSql(), reading the stored malicious values and interpolating them directly into the SQL query — executing the injected SQL.
  5. Exfiltrate data: Use UNION-based or blind SQL injection techniques to extract password hashes, email addresses, or other sensitive data from any table in the database (GitHub Advisory).

Indicators of compromise

  • Network: Unusual POST requests to /adm_program/modules/groups-roles/mylist_function.php?mode=save_temporary containing SQL keywords (UNION, SELECT, FROM, CASE, WHEN, 1/0, --) in column[], sort[], or condition[] parameters.
  • Network: Repeated or automated requests to lists_show.php following POST requests to mylist_function.php, potentially indicating automated payload triggering.
  • Database: Entries in the adm_list_columns table (lsc_special_field, lsc_sort, lsc_filter columns) containing SQL syntax, UNION statements, subqueries, or comment sequences (--, /*).
  • Logs: Web server access logs showing POST requests to mylist_function.php with abnormally long or encoded parameter values in column[] or sort[] fields.
  • Logs: Database query logs showing dynamically constructed SQL queries with unexpected UNION clauses, subqueries, or ORDER BY expressions containing SQL functions like CASE WHEN.

Mitigation and workarounds

Admidio has released version 5.0.7, which fixes this vulnerability by implementing a strict allowlist of valid special field names in ListConfiguration::addColumn() and getSql(), validating sort values to only accept ASC, DESC, or empty string, and improving filter value handling in ConditionParser. Organizations unable to upgrade immediately should restrict access to the MyList configuration feature for low-privilege users by setting groups_roles_edit_lists = 0 where possible, and review database access logs for suspicious SQL activity. Upgrading to version 5.0.7 or later is the recommended and definitive remediation (GitHub Advisory, Patch Commit).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management