<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T04:01:09.871442+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-277008</id>
    <title>EUVD-2026-277008</title>
    <updated>2026-10-08T04:01:09.919382+00:00</updated>
    <content>EUVD-2026-277008</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-277008"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33507</id>
    <title>fkie_cve-2026-33507</title>
    <updated>2026-10-08T04:01:09.919424+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php` endpoint allows admin users to upload and install plugin ZIP files containing executable PHP code, but lacks any CSRF protection. Combined with the application explicitly setting `session.cookie_samesite = 'None'` for HTTPS connections, an unauthenticated attacker can craft a page that, when visited by an authenticated admin, silently uploads a malicious plugin containing a PHP webshell, achieving Remote Code Execution on the server. Commit d1bc1695edd9ad4468a48cea0df6cd943a2635f3 contains a patch.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33507"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hv36-p4w4-6vmj</id>
    <title>GHSA-hv36-p4w4-6vmj — AVideo Affected by CSRF on Plugin Import Endpoint Enables Unauthenticated Remote Code Execution via Malicious Plugin Up…</title>
    <updated>2026-10-08T04:01:09.919461+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: wwbn/avideo</p>
<p>## Summary</p>
<p>The `objects/pluginImport.json.php` endpoint allows admin users to upload and install plugin ZIP files containing executable PHP code, but lacks any CSRF protection. Combined with the application explicitly setting `session.cookie_samesite = 'None'` for HTTPS connections, an unauthenticated attacker can craft a page that, when visited by an authenticated admin, silently uploads a malicious plugin containing a PHP webshell, achieving Remote Code Execution on the server.</p>
<p>## Details</p>
<p>The root cause has two components working together:</p>
<p>**1. SameSite=None on session cookies (`objects/include_config.php:134-137`):**</p>
<p>```php
if ($isHTTPS) {
    ini_set('session.cookie_samesite', 'None');
    ini_set('session.cookie_secure', '1');
}
```</p>
<p>This explicitly allows browsers to include the session cookie on cross-origin requests to the AVideo instance.</p>
<p>**2. No CSRF protection on pluginImport.json.php (`objects/pluginImport.json.php:18`):**</p>
<p>```php
if (!User::isAdmin()) {
    $obj-&gt;msg = "You are not admin";
    die(json_encode($obj));
}
```</p>
<p>The endpoint only checks `User::isAdmin()` via the session. There is:
- No CSRF token validation (the `verifyToken`/`globalToken` mechanism used elsewhere is absent)
- No `allowOrigin()` call (contrast with `objects/videoAddNew.json.php` which calls `allowOrigin()` at line 8)
- No `Referer` or `Origin` header validation
- No requirement for custom headers (e.g., `X-Requested-With`)</p>
<p>The upload form at `view/managerPluginUpload.php` also…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hv36-p4w4-6vmj"/>
  </entry>
</feed>
