<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:40:23.595255+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-188923</id>
    <title>EUVD-2026-188923</title>
    <updated>2026-10-02T19:40:23.597981+00:00</updated>
    <content>EUVD-2026-188923</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-188923"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-41879</id>
    <title>fkie_cve-2023-41879</title>
    <updated>2026-10-02T19:40:23.598011+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. This issue has been patched in versions 19.5.1 and 20.1.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-41879"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9358-cpvx-c2qp</id>
    <title>GHSA-9358-cpvx-c2qp — Magento LTS's guest order "protect code" can be brute-forced too easily</title>
    <updated>2026-10-02T19:40:23.598043+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: openmage/magento-lts</p>
<p># Impact</p>
<p>Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack.</p>
<p># Patches</p>
<p>None.</p>
<p># Workarounds</p>
<p>Implementing rate-limiting at the web server would help mitigate the issue. In particular, a very strict rate limit (e.g. 1 per minute per IP) for the specific route (`sales/guest/view/`) would effectively mitigate the issue.</p>
<p># References</p>
<p>Email from Frank Rochlitzer (f.rochlitzer@b3-it.de) to security@openmage.org:</p>
<p>## Summary</p>
<p>The German Federal Office for Information Security (BSI) found the following flaw in OpenMage through a commissioned pen test:
The web application was found to accept certain requests even without prior strong authentication if the person making the request has data that is non-public but also not secret, such as easily
easily guessed transaction numbers or names.
Attacking entities could possibly exploit this to retrieve sensitive information using this easier-to-obtain data and by trying random numbers.</p>
<p>## Details</p>
<p>Customers who place an order without an account can subsequently retrieve the order data or invoice data by specifying individual information.
Technically, the access is realized by specifying the cookie guest-view. The value of the cookie is Base64 encoded and contains a random value and the order number. The r…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9358-cpvx-c2qp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-41879</id>
    <title>gsd-2023-41879</title>
    <updated>2026-10-02T19:40:23.598116+00:00</updated>
    <content>gsd-2023-41879</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-41879"/>
  </entry>
</feed>
