<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T16:55:06.448661+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-331824</id>
    <title>EUVD-2026-331824</title>
    <updated>2026-10-06T16:55:06.498099+00:00</updated>
    <content>EUVD-2026-331824</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-331824"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-13602</id>
    <title>fkie_cve-2026-13602</title>
    <updated>2026-10-06T16:55:06.498138+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data:</p>
<p>*</p>
<p>The payment integration plugins Stripe (included in the core system), pretix-mollie, pretix-oppwa, pretix-bitpay, pretix-payone, pretix-secuconnect, pretix-sofort, and pretix-saferpay
 contain a code path that is intended for the transport of session 
parameters from a tab with isolated cookies (e.g. in the pretix widget) 
to a new tab. For this purpose, a set of session parameters is 
cryptographically signed and then passed to the new tab as a URL 
parameter. The plugins perform no further validation of the session 
parameters, other than the cryptographic signature being valid. This is 
fixed with the releases issued today by strictly validating that no 
session parameters outside of the scope of the respective plugin may be 
set.</p>
<p>*</p>
<p>An unrelated feature in the core system is used to generate redirect links that obfuscate any Referer
 headers for outgoing links to prevent leakage of secrets in URLs. This 
redirect page also requires cryptographically signed parameters. 
Unfortunately, it uses the same key and salt for the signature as the 
previously mentioned feature in the payment integration plugins. A 
motivated attacker with access to at least one event in the backend can 
trick the system into cryptographically signing arbitrary content using 
specially crafted links. In combination with the prev…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-13602"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q93m-6jvc-jc45</id>
    <title>GHSA-q93m-6jvc-jc45</title>
    <updated>2026-10-06T16:55:06.498196+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data:</p>
<p>*</p>
<p>The payment integration plugins Stripe (included in the core system), pretix-mollie, pretix-oppwa, pretix-bitpay, pretix-payone, pretix-secuconnect, pretix-sofort, and pretix-saferpay
 contain a code path that is intended for the transport of session 
parameters from a tab with isolated cookies (e.g. in the pretix widget) 
to a new tab. For this purpose, a set of session parameters is 
cryptographically signed and then passed to the new tab as a URL 
parameter. The plugins perform no further validation of the session 
parameters, other than the cryptographic signature being valid. This is 
fixed with the releases issued today by strictly validating that no 
session parameters outside of the scope of the respective plugin may be 
set.</p>
<p>*</p>
<p>An unrelated feature in the core system is used to generate redirect links that obfuscate any Referer
 headers for outgoing links to prevent leakage of secrets in URLs. This 
redirect page also requires cryptographically signed parameters. 
Unfortunately, it uses the same key and salt for the signature as the 
previously mentioned feature in the payment integration plugins. A 
motivated attacker with access to at least one event in the backend can 
trick the system into cryptographically signing arbitrary content using 
specially crafted links. In combination with the prev…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q93m-6jvc-jc45"/>
  </entry>
</feed>
