<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T03:30:10.250110+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-317291</id>
    <title>EUVD-2026-317291</title>
    <updated>2026-10-06T03:30:10.306072+00:00</updated>
    <content>EUVD-2026-317291</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-317291"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43875</id>
    <title>fkie_cve-2026-43875</title>
    <updated>2026-10-06T03:30:10.306106+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/MobileManager/oauth2.php completes an OAuth login by sending an HTTP 302 Location: oauth2Success.php?user=&lt;email&gt;&amp;pass=&lt;HASH&gt; where &lt;HASH&gt; is the victim's stored password hash (md5(hash("whirlpool", sha1(password)))) read directly from the users table. AVideo's own login endpoint (objects/login.json.php) accepts an encodedPass=1 flag that bypasses hashing and performs a direct string comparison between the supplied value and the stored hash. Anyone who captures the redirect URL — via server logs, referrer leakage, or browser history — therefore obtains a credential equivalent to the plaintext password and can fully take over the account, including admin accounts. Commit 977cd6930a97571a26da4239e25c8096dd4ecbc1 contains an updated fix.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-43875"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5w8w-26ch-v5cw</id>
    <title>GHSA-5w8w-26ch-v5cw — AVideo: Password Hash Leak in MobileManager OAuth Redirect URL Enables Account Takeover</title>
    <updated>2026-10-06T03:30:10.306144+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: wwbn/avideo</p>
<p>## Summary</p>
<p>`plugin/MobileManager/oauth2.php` completes an OAuth login by sending an HTTP 302 `Location: oauth2Success.php?user=&lt;email&gt;&amp;pass=&lt;HASH&gt;` where `&lt;HASH&gt;` is the victim's stored password hash (`md5(hash("whirlpool", sha1(password)))`) read directly from the `users` table. AVideo's own login endpoint (`objects/login.json.php`) accepts an `encodedPass=1` flag that bypasses hashing and performs a direct string comparison between the supplied value and the stored hash. Anyone who captures the redirect URL — via server logs, referrer leakage, or browser history — therefore obtains a credential equivalent to the plaintext password and can fully take over the account, including admin accounts.</p>
<p>## Details</p>
<p>### Sink: hash inlined in a GET redirect</p>
<p>`plugin/MobileManager/oauth2.php:98-102`:</p>
<p>```php
$pass = rand();
$users_id = User::createUserIfNotExists($user, $pass, $name, $email, $photoURL);
$adapter-&gt;disconnect();
$userObject = new User($users_id);
header("Location: oauth2Success.php?user=" . $userObject-&gt;getUser() . "&amp;pass=" . $userObject-&gt;getPassword());
```</p>
<p>`$userObject-&gt;getPassword()` returns the raw database column (`objects/user.php:159-162`):</p>
<p>```php
public function getPassword()
{
    return strip_tags($this-&gt;password);
}
```</p>
<p>The returned value is the stored password hash for the account (existing or freshly-created). It is transported to the browser as a query-string parameter in the `Location:` header, so it is written to:</p>
<p>* Web-server access logs (`combined`…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5w8w-26ch-v5cw"/>
  </entry>
</feed>
