<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T20:37:00.828664+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-317250</id>
    <title>EUVD-2026-317250</title>
    <updated>2026-10-06T20:37:00.830820+00:00</updated>
    <content>EUVD-2026-317250</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-317250"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43873</id>
    <title>fkie_cve-2026-43873</title>
    <updated>2026-10-06T20:37:00.830850+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/CloneSite/cloneClient.json.php echoes the local CloneSite shared secret ($objClone-&gt;myKey, a constant md5($global['systemRootPath'] . $global['salt'])) into the HTTP response body on every unauthenticated request. The unauthenticated error branch was intended to reject non-admin callers without a valid key, but the rejection message interpolates the expected key before die(). When the victim has CloneSite configured with a remote cloneSiteURL (standard federation/backup setup), the leaked myKey is exactly the credential that authenticates the victim to that remote server's cloneServer.json.php, allowing the attacker to impersonate the victim and trigger a full mysqldump of the remote's database to the remote's public videos/clones/ directory Commit e6566f56a28f4556b2a0a09d03717a719dcb49da contains an updated fix.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-43873"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qm9p-p5pw-jrx2</id>
    <title>GHSA-qm9p-p5pw-jrx2 — AVideo: Unauthenticated Disclosure of CloneSite `myKey` via Error Echo in `cloneClient.json.php` Enables Cross-Site DB…</title>
    <updated>2026-10-06T20:37:00.830887+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: wwbn/avideo</p>
<p>## Summary</p>
<p>`plugin/CloneSite/cloneClient.json.php` echoes the local CloneSite shared secret (`$objClone-&gt;myKey`, a constant `md5($global['systemRootPath'] . $global['salt'])`) into the HTTP response body on every unauthenticated request. The unauthenticated error branch was intended to reject non-admin callers without a valid key, but the rejection message interpolates the expected key before `die()`. When the victim has CloneSite configured with a remote `cloneSiteURL` (standard federation/backup setup), the leaked `myKey` is exactly the credential that authenticates the victim to that remote server's `cloneServer.json.php`, allowing the attacker to impersonate the victim and trigger a full `mysqldump` of the remote's database to the remote's public `videos/clones/` directory.</p>
<p>## Details</p>
<p>### 1. The leak (`plugin/CloneSite/cloneClient.json.php:51-60`)</p>
<p>```php
$objCloneOriginal = $objClone;
$argv[1] = preg_replace("/[^A-Za-z0-9 ]/", '', empty($argv[1])?'':$argv[1]);</p>
<p>if (empty($objClone) || empty($argv[1]) || $objClone-&gt;myKey !== $argv[1]) {
    if (!User::isAdmin()) {
        $resp-&gt;msg = "You can't do this";
        $log-&gt;add("Clone: {$resp-&gt;msg}");
        echo "$objClone-&gt;myKey !== $argv[1]";   // &lt;-- interpolates myKey
        die(json_encode($resp));
    }
}
```</p>
<p>Under PHP's web SAPI, the script-scope `$argv` global is not populated from the query string (only `$_SERVER['argv']` is populated, and only when `register_argc_argv=On`). Verified on this host (PHP 8.4.16,…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qm9p-p5pw-jrx2"/>
  </entry>
</feed>
