<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T06:41:01.469681+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-278424</id>
    <title>EUVD-2026-278424</title>
    <updated>2026-10-08T06:41:01.516546+00:00</updated>
    <content>EUVD-2026-278424</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-278424"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34611</id>
    <title>fkie_cve-2026-34611</title>
    <updated>2026-10-08T06:41:01.516585+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/emailAllUsers.json.php allows administrators to send HTML emails to every registered user on the platform. While the endpoint verifies admin session status, it does not validate a CSRF token. Because AVideo sets SameSite=None on session cookies, a cross-origin POST request from an attacker-controlled page will include the admin's session cookie automatically. An attacker who lures an admin to a malicious page can send an arbitrary HTML email to every user on the platform, appearing to originate from the instance's legitimate SMTP address. At time of publication, there are no publicly available patches.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34611"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c4xj-x7p8-3x7q</id>
    <title>GHSA-c4xj-x7p8-3x7q — AVideo: CSRF on emailAllUsers.json.php Enables Mass Phishing Email to All Users</title>
    <updated>2026-10-08T06:41:01.516623+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: wwbn/avideo</p>
<p>## Summary</p>
<p>The AVideo endpoint `objects/emailAllUsers.json.php` allows administrators to send HTML emails to every registered user on the platform. While the endpoint verifies admin session status, it does not validate a CSRF token. Because AVideo sets `SameSite=None` on session cookies, a cross-origin POST request from an attacker-controlled page will include the admin's session cookie automatically. An attacker who lures an admin to a malicious page can send an arbitrary HTML email to every user on the platform, appearing to originate from the instance's legitimate SMTP address.</p>
<p>The endpoint does not call `save()` on any ORM object, which means the Referer/Origin domain validation implemented in `ObjectYPT::save()` is never triggered, leaving CSRF as the only required protection - and it is absent.</p>
<p>## Details</p>
<p>The endpoint performs an admin check at line 10 but has no CSRF token validation:</p>
<p>```php
// objects/emailAllUsers.json.php:10
if (!User::isAdmin()) {
    die('{"error": "Must be admin"}');
}
```</p>
<p>The message body is taken directly from POST data at line 41:</p>
<p>```php
// objects/emailAllUsers.json.php:41
$obj-&gt;message = $_POST['message'];
```</p>
<p>The message is rendered as HTML in the email at line 48:</p>
<p>```php
// objects/emailAllUsers.json.php:48
$mail-&gt;msgHTML($obj-&gt;message);
```</p>
<p>When the `email` POST parameter is omitted, the endpoint defaults to sending to all registered users by calling `User::getAllUsers()`. This means the attacker does not need to know any email…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c4xj-x7p8-3x7q"/>
  </entry>
</feed>
