<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T21:28:04.217273+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-308637</id>
    <title>EUVD-2026-308637</title>
    <updated>2026-10-05T21:28:04.273970+00:00</updated>
    <content>EUVD-2026-308637</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-308637"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32699</id>
    <title>fkie_cve-2026-32699</title>
    <updated>2026-10-05T21:28:04.274008+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fails to validate the nick parameter during a POST request to the EditUser controller. Although the user interface prevents editing this field, a user can bypass this restriction by intercepting the request and modifying the nick form-data parameter to rename any account, including the administrator account. This leads to unauthorized modification of a field intended to be immutable.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32699"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pp79-hqv6-vmc3</id>
    <title>GHSA-pp79-hqv6-vmc3 — FacturaScripts has Insecure Parameter Handling: Unauthorized Modification of Immutable 'nick' Field</title>
    <updated>2026-10-05T21:28:04.274044+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: facturascripts/facturascripts</p>
<p>### Summary
The application fails to validate the ```nick``` parameter during a ```POST``` request to the ```EditUser``` controller. Although the UI prevents editing this field, a user can bypass this restriction using a proxy to rename any account (including the Administrator). This leads to Broken Access Control and potential Audit Log Corruption.</p>
<p>### Details
The vulnerability exists in the user update logic. When a ```POST``` request is sent to ```/EditUser```, the backend processes the ```nick``` form-data parameter without checking if it matches the original value or if the user has the privilege to change a unique identifier that is intended to be immutable.</p>
<p>### PoC
***1.*** Log in to the dashboard as any user  (e.g. admin user).</p>
<p>***2.*** Go to your Profile  by clicking your username/avatar in the top right.</p>
<p>***3.*** Open Burp Suite and ensure Intercept is ON.</p>
<p>***5.*** Click the Save button in the UI.</p>
<p>***6.*** In Burp Suite, locate  ```nick```  in the body:</p>
<p>&lt;img width="1915" height="1013" alt="Screenshot_2026-03-04_05_26_32" src="https://github.com/user-attachments/assets/aea4e6fd-beba-4a47-96da-8b9bd9075681" /&gt;</p>
<p>***7.*** Change the value admin to Vulnerable (or any other string).</p>
<p>***8.*** Click Forward in Burp Suite.</p>
<p>The application will log the user out. It is possible to now log back in using the username "Vulnerable" and the original password.</p>
<p>### Impact
An attacker can effectively sabotage the system’s audit trail, performing malicious actions and then…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pp79-hqv6-vmc3"/>
  </entry>
</feed>
