<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 19:25:38 +0000</lastBuildDate>
    <item>
      <title>cnvd-2020-48583</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-48583</link>
      <description>cnvd-2020-48583</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-48583</guid>
    </item>
    <item>
      <title>EUVD-2026-42668</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-42668</link>
      <description>EUVD-2026-42668</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-42668</guid>
    </item>
    <item>
      <title>fkie_cve-2020-15146</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-15146</link>
      <description>&lt;p&gt;In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, request parameters injected inside an expression evaluated by `symfony/expression-language` package haven&amp;#39;t been sanitized properly. This allows the attacker to access any public service by manipulating that request parameter, allowing for Remote Code Execution. This issue has been patched for versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4. Versions prior to 1.3 were not patched.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, request parameters injected inside an expression evaluated by `symfony/expression-language` package haven&amp;#39;t been sanitized properly. This allows the attacker to access any public service by manipulating that request parameter, allowing for Remote Code Execution. This issue has been patched for versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4. Versions prior to 1.3 were not patched.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-15146</guid>
    </item>
    <item>
      <title>GHSA-h6m7-j4h3-9rf5 — Remote Code Execution in SyliusResourceBundle</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h6m7-j4h3-9rf5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: sylius/resource-bundle&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Request parameters injected inside an expression evaluated by `symfony/expression-language` package haven&amp;#39;t been sanitized properly. This allows the attacker to access any public service by manipulating that request parameter, allowing for Remote Code Execution.&lt;/p&gt;
&lt;p&gt;The vulnerable versions include: `&amp;lt;=1.3.13 || &amp;gt;=1.4.0 &amp;lt;=1.4.6 || &amp;gt;=1.5.0 &amp;lt;=1.5.1 || &amp;gt;=1.6.0 &amp;lt;=1.6.3`.&lt;/p&gt;
&lt;p&gt;### Example&lt;/p&gt;
&lt;p&gt;```yaml
sylius_grid:
    grids:
        foo:
            fields:
                bar:
                    options:
                        baz: &amp;#34;expr:service(&amp;#39;sylius.repository.product&amp;#39;).find($id)&amp;#34;
```&lt;/p&gt;
&lt;p&gt;In this case, `$id` can be prepared in a way that calls other services.&lt;/p&gt;
&lt;p&gt;If you visit `/route?id=&amp;#34;~service(&amp;#39;doctrine&amp;#39;).getManager().getConnection().executeQuery(&amp;#34;DELETE * FROM TABLE&amp;#34;)~&amp;#34;`, it will result in a following expression `expr:service(&amp;#39;repository&amp;#39;).find(&amp;#34;&amp;#34;~service(&amp;#39;doctrine&amp;#39;).getManager().getConnection().executeQuery(&amp;#34;DELETE * FROM TABLE&amp;#34;)~&amp;#34;&amp;#34;)`, which will execute a query on the currently connected database.&lt;/p&gt;
&lt;p&gt;To find a vulnerability in your application, look for any routing definition that uses request parameters inside expression language.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This issue has been patched for versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4. Versions prior to 1.3 were not patched.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;The fix requires adding `addslashes` in `OptionsParser::parseOptionExpression` to sanitize user input before evaluating it using the expression language.&lt;/p&gt;
&lt;p&gt;```php
- return is_string($variable) ? sprintf(&amp;#39;…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: sylius/resource-bundle&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Request parameters injected inside an expression evaluated by `symfony/expression-language` package haven&amp;#39;t been sanitized properly. This allows the attacker to access any public service by manipulating that request parameter, allowing for Remote Code Execution.&lt;/p&gt;
&lt;p&gt;The vulnerable versions include: `&amp;lt;=1.3.13 || &amp;gt;=1.4.0 &amp;lt;=1.4.6 || &amp;gt;=1.5.0 &amp;lt;=1.5.1 || &amp;gt;=1.6.0 &amp;lt;=1.6.3`.&lt;/p&gt;
&lt;p&gt;### Example&lt;/p&gt;
&lt;p&gt;```yaml
sylius_grid:
    grids:
        foo:
            fields:
                bar:
                    options:
                        baz: &amp;#34;expr:service(&amp;#39;sylius.repository.product&amp;#39;).find($id)&amp;#34;
```&lt;/p&gt;
&lt;p&gt;In this case, `$id` can be prepared in a way that calls other services.&lt;/p&gt;
&lt;p&gt;If you visit `/route?id=&amp;#34;~service(&amp;#39;doctrine&amp;#39;).getManager().getConnection().executeQuery(&amp;#34;DELETE * FROM TABLE&amp;#34;)~&amp;#34;`, it will result in a following expression `expr:service(&amp;#39;repository&amp;#39;).find(&amp;#34;&amp;#34;~service(&amp;#39;doctrine&amp;#39;).getManager().getConnection().executeQuery(&amp;#34;DELETE * FROM TABLE&amp;#34;)~&amp;#34;&amp;#34;)`, which will execute a query on the currently connected database.&lt;/p&gt;
&lt;p&gt;To find a vulnerability in your application, look for any routing definition that uses request parameters inside expression language.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This issue has been patched for versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4. Versions prior to 1.3 were not patched.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;The fix requires adding `addslashes` in `OptionsParser::parseOptionExpression` to sanitize user input before evaluating it using the expression language.&lt;/p&gt;
&lt;p&gt;```php
- return is_string($variable) ? sprintf(&amp;#39;…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h6m7-j4h3-9rf5</guid>
    </item>
    <item>
      <title>gsd-2020-15146</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-15146</link>
      <description>gsd-2020-15146</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-15146</guid>
    </item>
  </channel>
</rss>
