A vulnerability categorized as critical has been discovered in Admidio up to 5.0.9. Impacted is the function
File::moveToFolder of the file modules/documents-files.php of the component Move. The manipulation of the argument folder_uuid/file_uuid results in unrestricted upload.
This vulnerability was named CVE-2026-47231. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.