<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T18:32:00.992424+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-308944</id>
    <title>EUVD-2026-308944</title>
    <updated>2026-10-07T18:32:01.052995+00:00</updated>
    <content>EUVD-2026-308944</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-308944"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41663</id>
    <title>fkie_cve-2026-41663</title>
    <updated>2026-10-07T18:32:01.053041+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Admidio is an open-source user management solution. Prior to version 5.0.9, several administrative operations in Admidio's preferences module (database backup, test email, htaccess generation) fire via GET requests with no CSRF token validation. Because SameSite=Lax cookies travel with top-level GET navigations, an attacker forces an authenticated admin to trigger these actions from a malicious page. This issue has been patched in version 5.0.9.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41663"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rw74-vc9h-534j</id>
    <title>GHSA-rw74-vc9h-534j — Admidio has CSRF on Admin Preferences that Triggers Unauthorized Backup, .htaccess Write, and Email Send</title>
    <updated>2026-10-07T18:32:01.053080+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: admidio/admidio</p>
<p>## Summary</p>
<p>Several administrative operations in Admidio's preferences module (database backup, test email, htaccess generation) fire via GET requests with no CSRF token validation. Because `SameSite=Lax` cookies travel with top-level GET navigations, an attacker forces an authenticated admin to trigger these actions from a malicious page.</p>
<p>## Details</p>
<p>In `modules/preferences.php`, the `backup`, `test_email`, and `htaccess` modes accept GET parameters with no CSRF token check:</p>
<p>```php
// modules/preferences.php - backup mode
case 'backup':
    // Creates full database dump and serves as download
    // No CSRF token validation
    $backupFile = $gDb-&gt;backup();
    // ... sends file to client
    break;</p>
<p>case 'test_email':
    // Sends test email from the server
    // No CSRF token validation
    break;</p>
<p>case 'htaccess':
    // Writes .htaccess file to disk
    // No CSRF token validation
    break;
```</p>
<p>The `save` mode in the same file validates CSRF via `getFormObject()`, confirming the developers intended CSRF protection but did not apply it to these other modes.</p>
<p>Because these are GET requests, `SameSite=Lax` browsers include session cookies on top-level cross-origin navigations, making CSRF exploitation trivial.</p>
<p>## Proof of Concept</p>
<p>Simplified attacker page (`csrf.html` hosted on attacker origin):</p>
<p>```html
&lt;html&gt;
&lt;body&gt;
&lt;h1&gt;Loading...&lt;/h1&gt;
&lt;!-- Trigger backup creation on victim's browser --&gt;
&lt;script&gt;window.location = 'https://target-admidio.example.com/adm_program/modu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rw74-vc9h-534j"/>
  </entry>
</feed>
