<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:18:37 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-02094</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-02094</link>
      <description>bdu:2024-02094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-02094</guid>
    </item>
    <item>
      <title>EUVD-2026-160370</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-160370</link>
      <description>EUVD-2026-160370</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-160370</guid>
    </item>
    <item>
      <title>fkie_cve-2024-27295</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-27295</link>
      <description>&lt;p&gt;Directus is a real-time API and App dashboard for managing SQL database content. The password reset mechanism of the Directus backend allows attackers to receive a password reset email of a victim user, specifically having it arrive at a similar email address as the victim with a one or more characters changed to use accents. This is due to the fact that by default MySQL/MariaDB are configured for accent-insensitive and case-insensitive comparisons. This vulnerability is fixed in version 10.8.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Directus is a real-time API and App dashboard for managing SQL database content. The password reset mechanism of the Directus backend allows attackers to receive a password reset email of a victim user, specifically having it arrive at a similar email address as the victim with a one or more characters changed to use accents. This is due to the fact that by default MySQL/MariaDB are configured for accent-insensitive and case-insensitive comparisons. This vulnerability is fixed in version 10.8.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-27295</guid>
    </item>
    <item>
      <title>GHSA-qw9g-7549-7wg5 — Directus has MySQL accent insensitive email matching</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qw9g-7549-7wg5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: directus&lt;/p&gt;
&lt;p&gt;## Password reset vulnerable to accent confusion&lt;/p&gt;
&lt;p&gt;The password reset mechanism of the Directus backend is implemented in a way where combined with (specific, need to double check if i can work around) configuration in MySQL or MariaDB. As such, it allows attackers to receive a password reset email of a victim user, specifically having it arrive at a similar email address as the victim with a one or more characters changed to use accents.&lt;/p&gt;
&lt;p&gt;This is due to the fact that by default MySQL/MariaDB are configured for accent-insenstive and case-insensitve comparisons.&lt;/p&gt;
&lt;p&gt;MySQL weak comparison:
```sql
select 1 from directus_users where &amp;#39;julian@cure53.de&amp;#39; = &amp;#39;julian@cüre53.de&amp;#39;;
```&lt;/p&gt;
&lt;p&gt;This is exploitable due to an error in the API using the supplied email address for sending the reset password mail instead of using the email from the database.&lt;/p&gt;
&lt;p&gt;### Steps to reproduce:&lt;/p&gt;
&lt;p&gt;1. If the attacker knows the email address of the victim user, i.e., `julian@cure53.de`. (possibly just the domain could be enough for an educated guess)
2. A off-by-one accented domain `cüre53.de` can be registered to be able to receive emails.
3. With this email the attacker can request a password reset for `julian@cüre53.de`. 
```http
POST /auth/password/request HTTP/1.1
Host: example.com
[...]
{&amp;#34;email&amp;#34;:&amp;#34;julian@cüre53.de&amp;#34;}
```
4. The supplied email (julian@cüre53.de) gets checked against the database and will match the non-accented email `julian@cure53.de` and will continue to email the password reset link to the provide…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: directus&lt;/p&gt;
&lt;p&gt;## Password reset vulnerable to accent confusion&lt;/p&gt;
&lt;p&gt;The password reset mechanism of the Directus backend is implemented in a way where combined with (specific, need to double check if i can work around) configuration in MySQL or MariaDB. As such, it allows attackers to receive a password reset email of a victim user, specifically having it arrive at a similar email address as the victim with a one or more characters changed to use accents.&lt;/p&gt;
&lt;p&gt;This is due to the fact that by default MySQL/MariaDB are configured for accent-insenstive and case-insensitve comparisons.&lt;/p&gt;
&lt;p&gt;MySQL weak comparison:
```sql
select 1 from directus_users where &amp;#39;julian@cure53.de&amp;#39; = &amp;#39;julian@cüre53.de&amp;#39;;
```&lt;/p&gt;
&lt;p&gt;This is exploitable due to an error in the API using the supplied email address for sending the reset password mail instead of using the email from the database.&lt;/p&gt;
&lt;p&gt;### Steps to reproduce:&lt;/p&gt;
&lt;p&gt;1. If the attacker knows the email address of the victim user, i.e., `julian@cure53.de`. (possibly just the domain could be enough for an educated guess)
2. A off-by-one accented domain `cüre53.de` can be registered to be able to receive emails.
3. With this email the attacker can request a password reset for `julian@cüre53.de`. 
```http
POST /auth/password/request HTTP/1.1
Host: example.com
[...]
{&amp;#34;email&amp;#34;:&amp;#34;julian@cüre53.de&amp;#34;}
```
4. The supplied email (julian@cüre53.de) gets checked against the database and will match the non-accented email `julian@cure53.de` and will continue to email the password reset link to the provide…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qw9g-7549-7wg5</guid>
    </item>
    <item>
      <title>gsd-2024-27295</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-27295</link>
      <description>gsd-2024-27295</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-27295</guid>
    </item>
  </channel>
</rss>
