<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T17:45:32.012483+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-265888</id>
    <title>EUVD-2026-265888</title>
    <updated>2026-10-06T17:45:32.057817+00:00</updated>
    <content>EUVD-2026-265888</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-265888"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23622</id>
    <title>fkie_cve-2026-23622</title>
    <updated>2026-10-06T17:45:32.057857+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_verify() only enforces CSRF for POST requests and returns early for non-POST methods. Several application endpoints perform state-changing operations while accepting parameters from GET (or $_REQUEST), so an attacker can perform CSRF by forcing a victim's browser to issue a crafted GET request. Impact: creation of admin accounts, modification of admin email/password, and full admin account takeover.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-23622"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-54v4-4685-vwrj</id>
    <title>GHSA-54v4-4685-vwrj — alextselegidis/easyappointments is Vulnerable to CSRF Protection Bypass</title>
    <updated>2026-10-06T17:45:32.057893+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: alextselegidis/easyappointments</p>
<p>### Summary
`application/core/EA_Security.php::csrf_verify()` only enforces CSRF for POST requests and returns early for non-POST methods. Several application endpoints perform state-changing operations while accepting parameters from GET (or $_REQUEST), so an attacker can perform CSRF by forcing a victim's browser to issue a crafted GET request. Impact: creation of admin accounts, modification of admin email/password, and full admin account takeover</p>
<p>### Details</p>
<p>in https://github.com/alextselegidis/easyappointments/blob/41c9b93a5a2c185a914f204412324d8980943fd5/application/core/EA_Security.php#L52</p>
<p>* **Repository / tested commit:** `alextselegidis/easyappointments` — commit `41c9b93a5a2c185a914f204412324d8980943fd5`.
* **Vulnerable file &amp; function:** `application/core/EA_Security.php::csrf_verify()` — around line 52. Link: `.../application/core/EA_Security.php#L52`.
* **Root cause:** The function early-returns when the request is not `POST`:</p>
<p>```php
// vulnerable snippet
if (strtoupper($_SERVER['REQUEST_METHOD']) !== 'POST') {
    return $this-&gt;csrf_set_cookie();
}
```</p>
<p>Because of this, non-POST requests (GET/PUT/DELETE/etc.) never reach token validation. When application controllers accept state-changing parameters via `GET` or `$_REQUEST`, these requests bypass CSRF checks entirely and the application executes the state change.</p>
<p>* **Examples of vulnerable endpoints (observed during testing):**</p>
<p>* `index.php/admins/store` — create admin (accepts fields via GET)
  * `inde…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-54v4-4685-vwrj"/>
  </entry>
</feed>
