<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T08:05:37.341448+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-277121</id>
    <title>EUVD-2026-277121</title>
    <updated>2026-10-07T08:05:37.343483+00:00</updated>
    <content>EUVD-2026-277121</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-277121"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33688</id>
    <title>fkie_cve-2026-33688</title>
    <updated>2026-10-07T08:05:37.343514+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>WWBN AVideo is an open source video platform. In versions up to and including 26.0, the password recovery endpoint at `objects/userRecoverPass.php` performs user existence and account status checks before validating the captcha. This allows an unauthenticated attacker to enumerate valid usernames and determine whether accounts are active, inactive, or banned — at scale and without solving any captcha — by observing three distinct JSON error responses. Commit e42f54123b460fd1b2ee01f2ce3d4a386e88d157 contains a patch.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33688"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m99f-mmvg-3xmx</id>
    <title>GHSA-m99f-mmvg-3xmx — AVideo has Pre-Captcha User Enumeration and Account Status Disclosure in Password Recovery Endpoint</title>
    <updated>2026-10-07T08:05:37.343548+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: wwbn/avideo</p>
<p>## Summary</p>
<p>The password recovery endpoint at `objects/userRecoverPass.php` performs user existence and account status checks **before** validating the captcha. This allows an unauthenticated attacker to enumerate valid usernames and determine whether accounts are active, inactive, or banned — at scale and without solving any captcha — by observing three distinct JSON error responses.</p>
<p>## Details</p>
<p>In `objects/userRecoverPass.php`, the request flow is:</p>
<p>1. **Line 11** — A `User` object is instantiated from unsanitized `$_REQUEST['user']` with no authentication:
```php
$user = new User(0, $_REQUEST['user'], false);
```</p>
<p>2. **Lines 27-29** — If the user does not exist, a distinct error is returned immediately:
```php
if (empty($user-&gt;getStatus())) {
    $obj-&gt;error = __("User not found");
    die(json_encode($obj));
}
```</p>
<p>3. **Lines 31-33** — If the user exists but is not active, a different distinct error is returned:
```php
if ($user-&gt;getStatus() !== 'a') {
    $obj-&gt;error = __("The user is not active");
    die(json_encode($obj));
}
```</p>
<p>4. **Lines 37-41** — Captcha validation only occurs **after** both user enumeration checks:
```php
if (empty($_REQUEST['captcha'])) {
    $obj-&gt;error = __("Captcha is empty");
} else {
    require_once 'captcha.php';
    $valid = Captcha::validation($_REQUEST['captcha']);
```</p>
<p>This ordering creates a reliable oracle: requests that hit the captcha check confirm the user exists and is active, while the two earlier error messages reveal non-ex…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m99f-mmvg-3xmx"/>
  </entry>
</feed>
