Vulnerability record · CVE-2021-32630 · published 20 May 2021
CVE-2021-32630: Admidio unrestricted file upload vulnerability
Admidio · Admidio
Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.0.4, there is an authenticated RCE via .phar file upload. A php web shell can be uploaded via the Documents & Files upload feature. Someone with upload permissions could rename the php shell with a .phar extension, visit the file, triggering the payload for a reverse/bind shell. This can be mitigated by excluding a .phar file extension to be uploaded (like you did with .php .phtml .php5 etc). The vulnerability is patched in version 4.0.4.
Description
Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.0.4, there is an authenticated RCE via .phar file upload. A php web shell can be uploaded via the Documents & Files upload feature. Someone with upload permissions could rename the php shell with a .phar extension, visit the file, triggering the payload for a reverse/bind shell. This can be mitigated by excluding a .phar file extension to be uploaded (like you did with .php .phtml .php5 etc). The vulnerability is patched in version 4.0.4.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/Admidio/admidio/issues/994 | Third Party Advisory |
| https://github.com/Admidio/admidio/releases/tag/v4.0.4 | Release NotesThird Party Advisory |
| https://github.com/Admidio/admidio/security/advisories/GHSA-xpqj-67r8-25j2 | ExploitThird Party Advisory |
| https://github.com/Admidio/admidio/issues/994 | Third Party Advisory |
| https://github.com/Admidio/admidio/releases/tag/v4.0.4 | Release NotesThird Party Advisory |
| https://github.com/Admidio/admidio/security/advisories/GHSA-xpqj-67r8-25j2 | ExploitThird Party Advisory |
Track CVE-2021-32630 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-32630), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.