<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T01:22:03.642497+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-12129</id>
    <title>cnvd-2025-12129</title>
    <updated>2026-10-07T01:22:03.691920+00:00</updated>
    <content>cnvd-2025-12129</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-12129"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-212169</id>
    <title>EUVD-2026-212169</title>
    <updated>2026-10-07T01:22:03.691959+00:00</updated>
    <content>EUVD-2026-212169</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-212169"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-11956</id>
    <title>fkie_cve-2024-11956</title>
    <updated>2026-10-07T01:22:03.691974+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affected by this issue is some unknown functionality of the file /admin/customermanagementframework/customers/list. The manipulation of the argument filterDefinition/filter leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-11956"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q53r-9hh9-w277</id>
    <title>GHSA-q53r-9hh9-w277 — pimcore/customer-data-framework vulnerable to SQL Injection</title>
    <updated>2026-10-07T01:22:03.692006+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: pimcore/customer-management-framework-bundle</p>
<p>An SQL injection vulnerability allows any authenticated user to execute arbitrary SQL commands on the server. This can lead to unauthorized access to sensitive data, data modification, or even complete control over the server.</p>
<p>Details
The vulnerability is found in the URL parameters of the following endpoint:</p>
<p>`GET /admin/customermanagementframework/customers/list?add-new-customer=1&amp;apply-segment-selection=Apply&amp;filterDefinition[allowedRoleIds][]=1&amp;filterDefinition[allowedUserIds][]=2&amp;filterDefinition[id]=0&amp;filterDefinition[name]=RDFYjolf&amp;filterDefinition[readOnly]=on&amp;filterDefinition[shortcutAvailable]=on&amp;filter[active]=1&amp;filter[email]=testing%40example.com&amp;filter[firstname]=RDFYjolf&amp;filter[id]=1&amp;filter[lastname]=RDFYjolf&amp;filter[operator-customer]=AND&amp;filter[operator-segments]=%40%40dz1Uu&amp;filter[search]=the&amp;filter[segments][832][]=847&amp;filter[segments][833][]=835&amp;filter[segments][874][]=876&amp;filter[showSegments][]=832 HTTP/1.1`</p>
<p>The parameters filterDefinition and filter are vulnerable to SQL injection. When a specially crafted input is provided, it results in an SQL error, indicating that the input is being directly used in an SQL query without proper sanitization.</p>
<p>PoC
To reproduce the vulnerability, follow these steps:</p>
<p>Open a web browser or a tool like curl or Postman.
Authenticate with valid user credentials.
Navigate to the following URL with the vulnerable parameters:
```
https://demo.pimcore.fun/admin/customermanagementframework/customers/list?add-new-customer=1&amp;appl…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q53r-9hh9-w277"/>
  </entry>
</feed>
