<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T10:02:31.533793+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-250398</id>
    <title>EUVD-2026-250398</title>
    <updated>2026-10-07T10:02:31.578439+00:00</updated>
    <content>EUVD-2026-250398</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-250398"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-55742</id>
    <title>fkie_cve-2025-55742</title>
    <updated>2026-10-07T10:02:31.578482+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, UnoPim contains a stored cross-site scripting vulnerability via SVG MIME/sanitizer bypass in the /admin/settings/users/create endpoint. This vulnerability is fixed in 0.2.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-55742"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xr97-25v7-hc2q</id>
    <title>GHSA-xr97-25v7-hc2q — UnoPim has Stored Cross-site Scripting vulnerability in user creation functionality</title>
    <updated>2026-10-07T10:02:31.578515+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: unopim/unopim</p>
<p>### Summary
Affected Functionality: User creation
Endpoint: `/admin/settings/users/create`</p>
<p>### Details
https://github.com/unopim/unopim/blob/a0dc81947a59ada69e19e1e4313dd591d4e277b4/packages/Webkul/Core/src/Traits/Sanitizer.php#L9-L19
See the mimetype is checked for validation.
Mime-type is usually identified by analysing the first few bytes of the file content, which contains the File signature or Magic bytes
for e.g. GIF file starts with GIF87a or GIF89a. We can mislead the sanitizer to think the uploaded file is gif ( based on magic byte provided ) while actually it is a .svg file.</p>
<p>File containing &lt;svg&gt; is considered as svg and is sanitized:
![image](https://github.com/user-attachments/assets/bcb0ce04-6bbe-4058-81da-927331247d3d)
```
Content-Disposition: form-data; name="image[]"; filename="poc.html"
Content-Type: image/svg+xml</p>
<p>&lt;?xml version="1.0" encoding="UTF-8"?&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" width="200" height="200" viewBox="0 0 200 200"  onload="alert(5)"&gt;
  &lt;rect width="200" height="200" fill="#3498db" onmouseover="alert('Hover')"&gt;&lt;/rect&gt;
  &lt;text x="50%" y="50%" font-size="20" text-anchor="middle" dy=".3em" fill="white" &gt;Proof of Concept&lt;/text&gt;
&lt;/svg&gt;
```
![image](https://github.com/user-attachments/assets/47d33392-632e-442b-8e51-5ba5189385ca)</p>
<p>Sanitization bypass using MIME type manipulation:
![image](https://github.com/user-attachments/assets/c4fa13a6-3c3a-4530-8d4e-68c203848a86)
```
Content-Disposition: form-data; name="image[]"; filename="poc.html"…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xr97-25v7-hc2q"/>
  </entry>
</feed>
