CVE-2026-32757

Source
https://cve.org/CVERecord?id=CVE-2026-32757
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-32757.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-32757
Aliases
Published
2026-03-19T23:12:37.664Z
Modified
2026-04-10T05:42:31.178799Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Admidio: HTMLPurifier Bypass in eCard Message Allows HTML Email Injection
Details

Admidio is an open-source user management solution. In versions 5.0.6 and below, the eCard send handler uses a raw $POST['ecardmessage'] value instead of the HTMLPurifier-sanitized $formValues['ecardmessage'] when constructing the greeting card HTML. This allows an authenticated attacker to inject arbitrary HTML and JavaScript into greeting card emails sent to other members, bypassing the server-side HTMLPurifier sanitization that is properly applied to the ecardmessage field during form validation. An attack can result in any member or role receiving phishing content that appears legitimate, crossing from the web application into recipients' email clients. This issue has been fixed in version 5.0.7.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32757.json"
}
References

Affected packages

Git / github.com/admidio/admidio

Affected ranges

Type
GIT
Repo
https://github.com/admidio/admidio
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

3.*
3.0-Beta.1
3.0-Beta.3
v3.*
v3.0.6
v3.1.5
v3.2-Beta.1
Other
v34
v4.*
v4.0-Beta.1
v4.1-Beta.2
v4.3-Beta.1
v5.*
v5.0-Beta.1
v5.0-Beta.2
v5.0-Beta.3
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-32757.json"