CVE-2026-34383: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34383 is a CSRF and form validation bypass vulnerability in Admidio, an open-source user management solution. The flaw exists in the inventory module's item_save endpoint, where a user-controllable POST parameter imported, when set to true, completely bypasses both CSRF token validation and server-side form validation. All versions up to and including 5.0.7 are affected; the issue was patched in version 5.0.8. It was published on March 31, 2026, with a CVSS v3.1 base score of 4.3 (Moderate) (Github Advisory).

Technical details

The root cause is improper input validation (CWE-20) combined with a CSRF weakness (CWE-352). In modules/inventory.php, the imported parameter is read from user-controlled POST input and passed to ItemService. Inside ItemService::save(), when postImported is true, the code skips the call to $gCurrentSession->getFormObject() (which validates the CSRF token) and $itemFieldsEditForm->validate() (which sanitizes and validates field values), instead passing raw $_POST data directly to $this->itemRessource->setValue() and saveItemData(). This means an authenticated attacker can send a crafted POST request with imported=1 and any arbitrary adm_csrf_token value to save unsanitized data to the database without any server-side checks. A public PoC using a curl command and an HTML auto-submit form is included in the security advisory (Github Advisory).

Impact

Successful exploitation allows an authenticated attacker (or an unauthenticated attacker leveraging the CSRF vector against a logged-in user) to create or modify inventory items with arbitrary, unsanitized data. Because server-side validation is entirely skipped, there is a potential for stored XSS if unsanitized input is later rendered to other users without proper output encoding. The impact is primarily an integrity loss affecting inventory records, with no direct confidentiality or availability impact (Github Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub security advisory, including a curl command and an HTML CSRF attack page that demonstrate the bypass against a real Admidio deployment (Github Advisory). Exploitation requires the attacker to be authenticated with inventory access for the direct POST vector, or to trick a logged-in inventory user into visiting a malicious page for the CSRF vector. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.021% (2nd percentile), indicating a low probability of near-term exploitation (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify a target Admidio instance running version 5.0.7 or earlier with the inventory module enabled. Confirm the target URL and that the item_save endpoint is accessible.
  2. Obtain authentication (for direct exploitation): Acquire a valid session cookie (ADMIDIO_SESSION) for an account with inventory access, either through legitimate login or credential theft.
  3. Craft the malicious POST request: Construct a POST request to https://<target>/modules/inventory.php?mode=item_save with the following parameters: imported=1, adm_csrf_token=anything (any arbitrary value), INF-CATEGORY=<valid_category_id>, and INF-ITEMNAME=<payload> (e.g., <script>alert(1)</script> for stored XSS).
  4. Send the request directly (authenticated bypass): Execute the request using a tool like curl: curl -X POST -b 'ADMIDIO_SESSION=<session_token>' 'https://<target>/modules/inventory.php?mode=item_save' -d 'imported=1' -d 'adm_csrf_token=anything' -d 'INF-CATEGORY=1' -d 'INF-ITEMNAME=<script>alert(1)</script>'
  5. CSRF attack vector (unauthenticated attacker): Host a malicious HTML page containing an auto-submitting form targeting the item_save endpoint with imported=1 and the desired payload, then trick a logged-in inventory user into visiting the page.
  6. Verify impact: Confirm that the arbitrary inventory item data was saved to the database by browsing the inventory module, and check if the stored XSS payload executes when other users view the affected inventory record (Github Advisory).

Indicators of compromise

  • Network: Unexpected POST requests to /modules/inventory.php?mode=item_save containing the parameter imported=1 with an arbitrary or missing adm_csrf_token value; requests originating from unusual IP addresses or referrers not matching the Admidio application domain.
  • Logs: Web server access logs showing POST requests to the item_save endpoint with imported=1 in the request body; repeated requests from the same session with varying INF-ITEMNAME or other field values containing script tags or special characters.
  • Database/Application: Inventory records containing unexpected or malformed data, HTML tags (e.g., <script>, <img>), or unusually long field values inconsistent with normal user input; inventory items created or modified at unusual times or by unexpected user accounts.

Mitigation and workarounds

Upgrade Admidio to version 5.0.8 or later, which removes the conditional bypass by always enforcing CSRF token validation and form field validation regardless of the imported parameter (Github Advisory, Patch Commit). As a temporary workaround if immediate upgrade is not possible, restrict access to the inventory module to trusted users only, implement a web application firewall (WAF) rule to block POST requests to item_save containing imported=1, and monitor inventory records for unexpected modifications. The imported flag should only be set internally via a session variable during the legitimate import workflow, not via direct POST input.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management