Security: poweradmin/poweradmin
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
OIDC `sub` collation bypass in Poweradmin leading to account takeoverGHSA-cmwh-g2h8-c222 published
Jul 23, 2026 by edmondasHigh -
API user-update endpoint leads to a non-admin reset any user's password and take over the superuser accountGHSA-h4hf-v6w5-897x published
Jul 23, 2026 by edmondasHigh -
Broken access control (IDOR): any zone owner can modify DNS records in zones they do not ownGHSA-rm67-g9ch-vxff published
Jul 23, 2026 by edmondasHigh -
Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.GHSA-3735-5339-xfwx published
Jun 7, 2026 by edmondasCritical -
CSV Injection in log export endpoints allows formula execution in spreadsheet applicationsGHSA-3h6h-67x3-cv5x published
Jun 7, 2026 by edmondasModerate
Learn more about advisories related to poweradmin/poweradmin in the GitHub Advisory Database