<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T13:42:33.895721+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337945</id>
    <title>EUVD-2026-337945</title>
    <updated>2026-10-05T13:42:33.941910+00:00</updated>
    <content>EUVD-2026-337945</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-52840</id>
    <title>fkie_cve-2026-52840</title>
    <updated>2026-10-05T13:42:33.941949+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Caldav::connect_to_server` at `application/controllers/Caldav.php:60` hands the request's `caldav_url` to a Guzzle `REPORT` call without scheme or host validation. A logged-in backend user (admin, provider, or secretary) reaches loopback, RFC1918, and link-local hosts on the deployment's network. The Guzzle exception path returns the upstream status code plus ~120 bytes of response body in the JSON `message` field (`Caldav.php:74-78`), so the SSRF is semi-blind. Version 1.6.0 contains a patch.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-52840"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pm5p-7w5h-jm5q</id>
    <title>GHSA-pm5p-7w5h-jm5q — Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal netw…</title>
    <updated>2026-10-05T13:42:33.941986+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: alextselegidis/easyappointments</p>
<p>### Summary</p>
<p>`Caldav::connect_to_server` at `application/controllers/Caldav.php:60` hands the request's `caldav_url` to a Guzzle `REPORT` call without scheme or host validation. A logged-in backend user (admin, provider, or secretary) reaches loopback, RFC1918, and link-local hosts on the deployment's network. The Guzzle exception path returns the upstream status code plus ~120 bytes of response body in the JSON `message` field (`Caldav.php:74-78`), so the SSRF is semi-blind.</p>
<p>### Preconditions</p>
<p>- Backend login on the target instance. Non-admin attackers supply their own `provider_id` and pass the per-row check at `Caldav.php:52`; admins can target any row.
- Default deployment per the project's own `docker-compose.yml`, which puts `mysql`, `mailpit`, `phpmyadmin`, `baikal`, `openldap`, `phpldapadmin`, and `swagger-ui` on the same docker network as `php-fpm`.</p>
<p>### Details</p>
<p>```php
// application/controllers/Caldav.php:45-82
public function connect_to_server(): void
{
    try {
        $provider_id = request('provider_id');
        $user_id = session('user_id');</p>
<p>if (cannot('edit', PRIV_USERS) &amp;&amp; (int) $user_id !== (int) $provider_id) {
            throw new RuntimeException('You do not have the required permissions for this task.');
        }</p>
<p>$caldav_url = request('caldav_url');                                  // (*) attacker-controlled
        $caldav_username = request('caldav_username');
        $caldav_password = request('caldav_password');</p>
<p>$thi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pm5p-7w5h-jm5q"/>
  </entry>
</feed>
