<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T22:10:47.118360+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-250400</id>
    <title>EUVD-2026-250400</title>
    <updated>2026-10-06T22:10:47.191453+00:00</updated>
    <content>EUVD-2026-250400</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-250400"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-55744</id>
    <title>fkie_cve-2025-55744</title>
    <updated>2026-10-06T22:10:47.191524+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, some of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF). This vulnerability is fixed in 0.2.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-55744"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-287x-6r2h-f9mw</id>
    <title>GHSA-287x-6r2h-f9mw — UnoPim vulnerable to CSRF on Product edit feature and creation of other types</title>
    <updated>2026-10-06T22:10:47.191571+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: unopim/unopim</p>
<p>### Summary
Some of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF).
| Method | Endpoint | Status   | Reason |
|:------:|:------:|:------:|:------:|
| POST | /admin/catalog/products/create | Not Vulnerable :white_check_mark: | `X-XSRF-TOKEN` header used |
| GET | /admin/catalog/products/copy/{id}| Vulnerable :x: | Missing `X-XSRF-TOKEN` header or similar protection |
| POST | /admin/catalog/products/edit/{id}| Vulnerable :x: | Missing `X-XSRF-TOKEN` header or similar protection |
| POST | /admin/settings/users/create | Not Vulnerable :white_check_mark: | `X-XSRF-TOKEN` header used |</p>
<p>The below are some of the vulnerable endpoints that allow state changing actions including but not limited to:
```
/admin/catalog/categories/create
/admin/catalog/categories/edit/{id}
/admin/catalog/category-fields/create
/admin/catalog/category-fields/edit/{id}
/admin/catalog/attributes/create
/admin/catalog/attributes/edit/{id}
```</p>
<p>### Details
CSRF attack happens when you visit an attacker controlled website which sends a cross origin request to vulnerable application in order to perform a state changing operation like edit the price of a product without the intention of victim.
In this case, the POST request doesn't need any special headers ( X-XSRF-TOKEN header missing ) and the content-type is either `application/x-www-form-urlencoded` or `multipart/form-data` so we can say this is a `Simple request` ( doesn't need preflight request ).  The cookies are s…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-287x-6r2h-f9mw"/>
  </entry>
</feed>
