<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:56:02 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-321995</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-321995</link>
      <description>EUVD-2026-321995</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-321995</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44833</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44833</link>
      <description>&lt;p&gt;Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. This vulnerability is fixed in 8.4.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. This vulnerability is fixed in 8.4.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44833</guid>
    </item>
    <item>
      <title>GHSA-mghp-5cq4-v6mg — Snipe-IT has an open redirect vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mghp-5cq4-v6mg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: snipe/snipe-it&lt;/p&gt;
&lt;p&gt;Open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;-   **Phishing**: Redirect users to fake login pages to steal credentials
-   **Session Hijacking**: Redirect to attacker site that captures session cookies via JavaScript
-   **Malware Distribution**: Redirect to sites hosting malware or drive-by downloads
-   **Reputation Damage**: Users lose trust when redirected to malicious sites from legitimate application
-   **Social Engineering**: Use trusted Snipe-IT domain to increase phishing success rate&lt;/p&gt;
&lt;p&gt;When the user clicks &amp;#34;Save&amp;#34;, the application: 
1. Processes the form 
2. Checks `redirect_option` (if set to &amp;#39;back&amp;#39;) 
3. Calls `Helper::getRedirectOption()` 
4. Retrieves `back_url` from session: `https://evil.com/phishing?target=snipeit` 
5. Executes `redirect()-&amp;gt;to($backUrl)` 
6. User is redirected to attacker&amp;#39;s site&lt;/p&gt;
&lt;p&gt;This would still require session poisoning, so the actual practical threat here is minimal.&lt;/p&gt;
&lt;p&gt;### Patches
Patched in https://github.com/grokability/snipe-it/commit/e37649212861a337e68a624e589c3540b7a82373, released in 8.4.1.&lt;/p&gt;
&lt;p&gt;### Workarounds
 None.&lt;/p&gt;
&lt;p&gt;### Resources
-   CWE-601: URL Redirection to Untrusted Site (&amp;#39;Open Redirect&amp;#39;)
-   OWASP: Unvalidated Redirects and Forwards
-   Laravel Security: Safe Redirects&lt;/p&gt;
&lt;p&gt;[snipeit_open_redirect_submission.md](https://github.com/user-attachments/files/27414869/snipeit_open_redirect_submission.md)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: snipe/snipe-it&lt;/p&gt;
&lt;p&gt;Open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;-   **Phishing**: Redirect users to fake login pages to steal credentials
-   **Session Hijacking**: Redirect to attacker site that captures session cookies via JavaScript
-   **Malware Distribution**: Redirect to sites hosting malware or drive-by downloads
-   **Reputation Damage**: Users lose trust when redirected to malicious sites from legitimate application
-   **Social Engineering**: Use trusted Snipe-IT domain to increase phishing success rate&lt;/p&gt;
&lt;p&gt;When the user clicks &amp;#34;Save&amp;#34;, the application: 
1. Processes the form 
2. Checks `redirect_option` (if set to &amp;#39;back&amp;#39;) 
3. Calls `Helper::getRedirectOption()` 
4. Retrieves `back_url` from session: `https://evil.com/phishing?target=snipeit` 
5. Executes `redirect()-&amp;gt;to($backUrl)` 
6. User is redirected to attacker&amp;#39;s site&lt;/p&gt;
&lt;p&gt;This would still require session poisoning, so the actual practical threat here is minimal.&lt;/p&gt;
&lt;p&gt;### Patches
Patched in https://github.com/grokability/snipe-it/commit/e37649212861a337e68a624e589c3540b7a82373, released in 8.4.1.&lt;/p&gt;
&lt;p&gt;### Workarounds
 None.&lt;/p&gt;
&lt;p&gt;### Resources
-   CWE-601: URL Redirection to Untrusted Site (&amp;#39;Open Redirect&amp;#39;)
-   OWASP: Unvalidated Redirects and Forwards
-   Laravel Security: Safe Redirects&lt;/p&gt;
&lt;p&gt;[snipeit_open_redirect_submission.md](https://github.com/user-attachments/files/27414869/snipeit_open_redirect_submission.md)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mghp-5cq4-v6mg</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1377 — Snipe-IT: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1377</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Snipe-IT ausnutzen, um Cross-Site-Scripting-Angriffe durchzuführen, Benutzer auf bösartige Websites umzuleiten, Administratorrechte zu erlangen oder beliebigen Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Snipe-IT ausnutzen, um Cross-Site-Scripting-Angriffe durchzuführen, Benutzer auf bösartige Websites umzuleiten, Administratorrechte zu erlangen oder beliebigen Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1377</guid>
    </item>
  </channel>
</rss>
