<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T16:25:06.299793+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-201442</id>
    <title>EUVD-2026-201442</title>
    <updated>2026-10-07T16:25:06.348149+00:00</updated>
    <content>EUVD-2026-201442</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-201442"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-52292</id>
    <title>fkie_cve-2024-52292</title>
    <updated>2026-10-07T16:25:06.348188+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions on system notification templates. This function accepts an absolute file path, reads the file's content, and converts it into a Base64-encoded string. By embedding this function within a system notification template, the attacker can exfiltrate the Base64-encoded file content through a triggered system email notification. Once the email is received, the Base64 payload can be decoded, allowing the attacker to read arbitrary files on the server. This is fixed in 5.4.9 and 4.12.8.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-52292"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cw6g-qmjq-6w2w</id>
    <title>GHSA-cw6g-qmjq-6w2w — Craft CMS Arbitrary System File Read</title>
    <updated>2026-10-07T16:25:06.348226+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: craftcms/cms</p>
<p>### Summary
By abusing the mail notification template it is possible to read arbitrary operating system files.</p>
<p>### Details
The [dataUrl](https://craftcms.com/docs/3.x/dev/functions.html#dataurl) function can be exploited if an attacker has write permissions on system notification templates. This function accepts an absolute file path, reads the file's content, and converts it into a Base64-encoded string. By embedding this function within a system notification template, the attacker can exfiltrate the Base64-encoded file content through a triggered system email notification. Once the email is received, the Base64 payload can be decoded, allowing the attacker to read arbitrary files on the server.</p>
<p>Requirements:
* write permissions to system notification templates
* ability to trigger a corresponding system email</p>
<p>### PoC
1) Modify a template to contain the following twig template string:
```twig
{{ dataUrl('/var/www/web/.env') }}
```
2) Trigger the corresponding notification email (e.g. by resetting a password)
3) Receive the email and decode the base64 string</p>
<p>Mail received:
![Bildschirmfoto 2024-09-05 um 16 20 41](https://github.com/user-attachments/assets/24dc5196-6847-4006-b7ef-8cd10d659c30)</p>
<p>Decoded string:
![Bildschirmfoto 2024-09-05 um 16 28 24](https://github.com/user-attachments/assets/1913a475-5277-49b9-9210-2f3fcd3b9bf1)</p>
<p>### Impact
1) Exposure of Sensitive Information: Arbitrary file read can lead to the exposure of sensitive data such as configuration files (…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cw6g-qmjq-6w2w"/>
  </entry>
</feed>
