<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:43:59.413918+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-319034</id>
    <title>EUVD-2026-319034</title>
    <updated>2026-10-02T10:43:59.416044+00:00</updated>
    <content>EUVD-2026-319034</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-319034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42458</id>
    <title>fkie_cve-2026-42458</title>
    <updated>2026-10-02T10:43:59.416074+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to 20.18.0, there is a reflected XSS vulnerability under admin panel -&gt; System -&gt; Import/Export -&gt; Dataflow - Profiles. This vulnerability is fixed in 20.18.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42458"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x8jv-q8j2-487c</id>
    <title>GHSA-x8jv-q8j2-487c — Magento LTS: Reflected XSS - Import -&gt; Data Flow (profiles)</title>
    <updated>2026-10-02T10:43:59.416105+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: openmage/magento-lts</p>
<p>A reflected XSS vulnerability was found under admin panel -&gt;  System -&gt; Import/Export -&gt; Dataflow -  Profiles.</p>
<p>## Steps to produce</p>
<p>+ Login to  the admin panel</p>
<p>+ Go to the path   `System -&gt; Import/Export -&gt; Dataflow -  Profiles`</p>
<p>+ Select profile direction as `Import`.</p>
<p>+ Click on `Import Customers`</p>
<p>+ Upload the file.</p>
<p>File Link: [customer_20260212_204335.csv](https://github.com/user-attachments/files/25629638/customer_20260212_204335.csv)</p>
<p>+ Go back to `Run profile`.</p>
<p>+ Select the uploaded file and Click on `Run in Popup`.</p>
<p>+ One can see a URL like this</p>
<p>```
https://demo-admin.openmage.org/index.php/admin/system_convert_gui/run/id/6/key/40dbbb2e93f45f0463c57ff733352f4f/files/import-20260215151125-1_customer_20260212_204335.csv/
```</p>
<p>+ One can see the filename getting reflection in HTML tags.</p>
<p>+ Inject an HTML tag and observe.</p>
<p>```
https://demo-admin.openmage.org/index.php/admin/system_convert_gui/run/id/6/key/40dbbb2e93f45f0463c57ff733352f4f/files/"&gt;&lt;h3&gt;hacked&lt;/h3&gt;/
```</p>
<p>&lt;img width="1796" height="302" alt="image (3)" src="https://github.com/user-attachments/assets/502330b0-fa73-4b90-a81f-6216a98e474a" /&gt;</p>
<p>+ One can see the tag is getting executed.</p>
<p>+  Proceed for XSS.</p>
<p>```
https://demo-admin.openmage.org/index.php/admin/system_convert_gui/run/id/6/key/40dbbb2e93f45f0463c57ff733352f4f/files/%3CScRiPt%20%3Eprompt(document.cookie)%3C%2FScRiPt%3E
```</p>
<p>&lt;img width="1670" height="562" alt="image (4)" src="https://github.com/user-attachments/assets/98a75081-fa8c-4483-9078-0…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x8jv-q8j2-487c"/>
  </entry>
</feed>
