<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T03:31:35.095842+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-278558</id>
    <title>EUVD-2026-278558</title>
    <updated>2026-10-08T03:31:35.130699+00:00</updated>
    <content>EUVD-2026-278558</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-278558"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34613</id>
    <title>fkie_cve-2026-34613</title>
    <updated>2026-10-08T03:31:35.130746+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/pluginSwitch.json.php allows administrators to enable or disable any installed plugin. The endpoint checks for an active admin session but does not validate a CSRF token. Additionally, the plugins database table is explicitly listed in ignoreTableSecurityCheck(), which means the ORM-level Referer/Origin domain validation in ObjectYPT::save() is also bypassed. Combined with SameSite=None on session cookies, an attacker can disable critical security plugins (such as LoginControl for 2FA, subscription enforcement, or access control plugins) by luring an admin to a malicious page. At time of publication, there are no publicly available patches.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34613"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hqxf-mhfw-rc44</id>
    <title>GHSA-hqxf-mhfw-rc44 — AVideo: CSRF on Plugin Enable/Disable Endpoint Allows Disabling Security Plugins</title>
    <updated>2026-10-08T03:31:35.130785+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: wwbn/avideo</p>
<p>## Summary</p>
<p>The AVideo endpoint `objects/pluginSwitch.json.php` allows administrators to enable or disable any installed plugin. The endpoint checks for an active admin session but does not validate a CSRF token. Additionally, the `plugins` database table is explicitly listed in `ignoreTableSecurityCheck()`, which means the ORM-level Referer/Origin domain validation in `ObjectYPT::save()` is also bypassed. Combined with `SameSite=None` on session cookies, an attacker can disable critical security plugins (such as LoginControl for 2FA, subscription enforcement, or access control plugins) by luring an admin to a malicious page.</p>
<p>Plugin UUIDs are not secret values. They are hardcoded in the frontend JavaScript source and are consistent across installations, making it trivial for an attacker to target specific plugins.</p>
<p>## Details</p>
<p>The `objects/pluginSwitch.json.php` endpoint checks admin status but performs no CSRF validation:</p>
<p>```php
// objects/pluginSwitch.json.php
if (!User::isAdmin()) {
    die('{"error": "Must be admin"}');
}</p>
<p>$obj = new Plugin(0);
$obj-&gt;loadFromUUID($_POST['uuid']);
$obj-&gt;setStatus($_POST['status']);
$obj-&gt;save();
```</p>
<p>The `plugins` table is explicitly excluded from the ORM security check at `objects/Object.php:529`:</p>
<p>```php
// objects/Object.php:529
public static function ignoreTableSecurityCheck() {
    return array(
        'plugins',
        // ... other tables
    );
}
```</p>
<p>This means the `save()` call does not trigger the Referer/Origin domain valid…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hqxf-mhfw-rc44"/>
  </entry>
</feed>
