# Exploit Title: Admidio 3.3.5 - Cross-Site Request Forgery (Change Permissions) # Author: Nawaf Alkeraithe # Date: 2018-09-01 # Vendor Homepage: https://www.admidio.org/ # Software Link: https://sourceforge.net/projects/admidio/files/Admidio/3.3.x/admidio-3.3.5.zip/download # Version: 3.3.5 # Tested on: PHP # CVE: N/A # Description: # Low Privilage users are able to increase their permissions due to improper origin checking # by the vendor.