<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:27:44 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-01106</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-01106</link>
      <description>bdu:2025-01106</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-01106</guid>
    </item>
    <item>
      <title>EUVD-2026-247787</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-247787</link>
      <description>EUVD-2026-247787</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-247787</guid>
    </item>
    <item>
      <title>fkie_cve-2024-47823</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-47823</link>
      <description>&lt;p&gt;Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and `v3.5.2`, the file extension of an uploaded file is guessed based on the MIME type. As a result, the actual file extension from the file name is not validated. An attacker can therefore bypass the validation by uploading a file with a valid MIME type (e.g., `image/png`) and a “.php” file extension. If the following criteria are met, the attacker can carry out an RCE attack: 1. Filename is composed of the original file name using `$file-&amp;gt;getClientOriginalName()`. 2. Files stored directly on your server in a public storage disk. 3. Webserver is configured to execute “.php” files. This issue has been addressed in release versions `2.12.7` and `3.5.2`. All users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and `v3.5.2`, the file extension of an uploaded file is guessed based on the MIME type. As a result, the actual file extension from the file name is not validated. An attacker can therefore bypass the validation by uploading a file with a valid MIME type (e.g., `image/png`) and a “.php” file extension. If the following criteria are met, the attacker can carry out an RCE attack: 1. Filename is composed of the original file name using `$file-&amp;gt;getClientOriginalName()`. 2. Files stored directly on your server in a public storage disk. 3. Webserver is configured to execute “.php” files. This issue has been addressed in release versions `2.12.7` and `3.5.2`. All users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-47823</guid>
    </item>
    <item>
      <title>GHSA-f3cx-396f-7jqp — Livewire Remote Code Execution on File Uploads</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f3cx-396f-7jqp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: livewire/livewire&lt;/p&gt;
&lt;p&gt;In livewire/livewire prior to `v2.12.7` and `v3.5.2`, the file extension of an uploaded file is guessed based on the MIME type. As a result, the actual file extension from the file name is not validated. An attacker can therefore bypass the validation by uploading a file with a valid MIME type (e.g., `image/png`) and a “.php” file extension.
If the following criteria are met, the attacker can carry out an RCE attack:&lt;/p&gt;
&lt;p&gt;- Filename is composed of the original file name using `$file-&amp;gt;getClientOriginalName()`
- Files stored directly on your server in a public storage disk
- Webserver is configured to execute “.php” files&lt;/p&gt;
&lt;p&gt;### PoC
In the following scenario, an attacker could upload a file called `shell.php` with an `image/png` MIME type and execute it on the remote server.
```php
class SomeComponent extends Component
{
    use WithFileUploads;&lt;/p&gt;
&lt;p&gt;#[Validate(&amp;#39;image|extensions:png&amp;#39;)]
    public $file;&lt;/p&gt;
&lt;p&gt;public function save()
    {
        $this-&amp;gt;validate();&lt;/p&gt;
&lt;p&gt;$this-&amp;gt;file-&amp;gt;storeAs(
            path: &amp;#39;images&amp;#39;,
            name: $this-&amp;gt;file-&amp;gt;getClientOriginalName(),
            options: [&amp;#39;disk&amp;#39; =&amp;gt; &amp;#39;public&amp;#39;],
        );
    }
}
```&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: livewire/livewire&lt;/p&gt;
&lt;p&gt;In livewire/livewire prior to `v2.12.7` and `v3.5.2`, the file extension of an uploaded file is guessed based on the MIME type. As a result, the actual file extension from the file name is not validated. An attacker can therefore bypass the validation by uploading a file with a valid MIME type (e.g., `image/png`) and a “.php” file extension.
If the following criteria are met, the attacker can carry out an RCE attack:&lt;/p&gt;
&lt;p&gt;- Filename is composed of the original file name using `$file-&amp;gt;getClientOriginalName()`
- Files stored directly on your server in a public storage disk
- Webserver is configured to execute “.php” files&lt;/p&gt;
&lt;p&gt;### PoC
In the following scenario, an attacker could upload a file called `shell.php` with an `image/png` MIME type and execute it on the remote server.
```php
class SomeComponent extends Component
{
    use WithFileUploads;&lt;/p&gt;
&lt;p&gt;#[Validate(&amp;#39;image|extensions:png&amp;#39;)]
    public $file;&lt;/p&gt;
&lt;p&gt;public function save()
    {
        $this-&amp;gt;validate();&lt;/p&gt;
&lt;p&gt;$this-&amp;gt;file-&amp;gt;storeAs(
            path: &amp;#39;images&amp;#39;,
            name: $this-&amp;gt;file-&amp;gt;getClientOriginalName(),
            options: [&amp;#39;disk&amp;#39; =&amp;gt; &amp;#39;public&amp;#39;],
        );
    }
}
```&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f3cx-396f-7jqp</guid>
    </item>
  </channel>
</rss>
