<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:35:11 +0000</lastBuildDate>
    <item>
      <title>cnvd-2022-68363</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-68363</link>
      <description>cnvd-2022-68363</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-68363</guid>
    </item>
    <item>
      <title>EUVD-2026-240582</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-240582</link>
      <description>EUVD-2026-240582</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-240582</guid>
    </item>
    <item>
      <title>fkie_cve-2022-32170</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-32170</link>
      <description>&lt;p&gt;The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized user can view the “projects“ created by “Admin” and the affected endpoint is “/api/project?user=${userId}”.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized user can view the “projects“ created by “Admin” and the affected endpoint is “/api/project?user=${userId}”.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-32170</guid>
    </item>
    <item>
      <title>GHSA-9mmc-27gw-w6mq — Bytebase allows low-privilege users to view admin projects</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9mmc-27gw-w6mq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/bytebase/bytebase&lt;/p&gt;
&lt;p&gt;### Overview
The &amp;#34;Bytebase&amp;#34; application does not restrict low privilege user from accessing admin projects&lt;/p&gt;
&lt;p&gt;### Details
The &amp;#34;Bytebase&amp;#34; application does not restrict low privilege user from accessing admin projects for which an unauthorized user can view the &amp;#34;projects&amp;#34; created by &amp;#34;Admin&amp;#34;. The affected endpoint is `/api/project?user=${userId}`.&lt;/p&gt;
&lt;p&gt;### PoC
1. Log in to the application as both &amp;#34;Admin&amp;#34; (`admin@example.com:admin`) and Developer &amp;#34;User&amp;#34; (`user@admin.com:user`) and then click on &amp;#34;Projects&amp;#34;.
2. Now open &amp;#34;Burp suite&amp;#34; and turn &amp;#34;Intercept on&amp;#34; and from &amp;#34;admin&amp;#34; dashboard click on &amp;#34;projects&amp;#34; and see the &amp;#34;user id&amp;#34; of &amp;#34;admin&amp;#34; in the capture request.
3. Note the &amp;#34;user id&amp;#34; and &amp;#34;Forward&amp;#34; the request and again capture the request of &amp;#34;projects&amp;#34; from the &amp;#34;user&amp;#34; dashboard and change &amp;#34;user id&amp;#34; to &amp;#34;admin user id&amp;#34; and &amp;#34;Forward&amp;#34; the request.
4. Now &amp;#34;user&amp;#34; can see the &amp;#34;projects&amp;#34; created by &amp;#34;admin&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/bytebase/bytebase&lt;/p&gt;
&lt;p&gt;### Overview
The &amp;#34;Bytebase&amp;#34; application does not restrict low privilege user from accessing admin projects&lt;/p&gt;
&lt;p&gt;### Details
The &amp;#34;Bytebase&amp;#34; application does not restrict low privilege user from accessing admin projects for which an unauthorized user can view the &amp;#34;projects&amp;#34; created by &amp;#34;Admin&amp;#34;. The affected endpoint is `/api/project?user=${userId}`.&lt;/p&gt;
&lt;p&gt;### PoC
1. Log in to the application as both &amp;#34;Admin&amp;#34; (`admin@example.com:admin`) and Developer &amp;#34;User&amp;#34; (`user@admin.com:user`) and then click on &amp;#34;Projects&amp;#34;.
2. Now open &amp;#34;Burp suite&amp;#34; and turn &amp;#34;Intercept on&amp;#34; and from &amp;#34;admin&amp;#34; dashboard click on &amp;#34;projects&amp;#34; and see the &amp;#34;user id&amp;#34; of &amp;#34;admin&amp;#34; in the capture request.
3. Note the &amp;#34;user id&amp;#34; and &amp;#34;Forward&amp;#34; the request and again capture the request of &amp;#34;projects&amp;#34; from the &amp;#34;user&amp;#34; dashboard and change &amp;#34;user id&amp;#34; to &amp;#34;admin user id&amp;#34; and &amp;#34;Forward&amp;#34; the request.
4. Now &amp;#34;user&amp;#34; can see the &amp;#34;projects&amp;#34; created by &amp;#34;admin&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9mmc-27gw-w6mq</guid>
    </item>
    <item>
      <title>gsd-2022-32170</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-32170</link>
      <description>gsd-2022-32170</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-32170</guid>
    </item>
  </channel>
</rss>
