<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 10:07:03 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-36462</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-36462</link>
      <description>EUVD-2026-36462</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-36462</guid>
    </item>
    <item>
      <title>fkie_cve-2020-5237</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-5237</link>
      <description>&lt;p&gt;Multiple relative path traversal vulnerabilities in the oneup/uploader-bundle before 1.9.3 and 2.1.5 allow remote attackers to upload, copy, and modify files on the filesystem (potentially leading to arbitrary code execution) via the (1) filename parameter to BlueimpController.php; the (2) dzchunkindex, (3) dzuuid, or (4) filename parameter to DropzoneController.php; the (5) qqpartindex, (6) qqfilename, or (7) qquuid parameter to FineUploaderController.php; the (8) x-file-id or (9) x-file-name parameter to MooUploadController.php; or the (10) name or (11) chunk parameter to PluploadController.php. This is fixed in versions 1.9.3 and 2.1.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple relative path traversal vulnerabilities in the oneup/uploader-bundle before 1.9.3 and 2.1.5 allow remote attackers to upload, copy, and modify files on the filesystem (potentially leading to arbitrary code execution) via the (1) filename parameter to BlueimpController.php; the (2) dzchunkindex, (3) dzuuid, or (4) filename parameter to DropzoneController.php; the (5) qqpartindex, (6) qqfilename, or (7) qquuid parameter to FineUploaderController.php; the (8) x-file-id or (9) x-file-name parameter to MooUploadController.php; or the (10) name or (11) chunk parameter to PluploadController.php. This is fixed in versions 1.9.3 and 2.1.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-5237</guid>
    </item>
    <item>
      <title>GHSA-x8wj-6m73-gfqp — Relative Path Traversal (CWE-23) in chunked uploads in oneup/uploader-bundle</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x8wj-6m73-gfqp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: oneup/uploader-bundle&lt;/p&gt;
&lt;p&gt;### Impact
The vulnerability was identified in the web service for a chunked file
upload. While the names of the POST parameters vary with the used
frontend, their values are always used in the same way to build a path
where the chunks are stored and assembled temporarily. By not validating
these parameters properly, OneupUploaderBundle is susceptible to a path
traversal vulnerability which can be exploited to upload files to
arbitrary folders on the filesystem. The assembly process can further be
misused with some restrictions to delete and copy files to other
locations.&lt;/p&gt;
&lt;p&gt;The vulnerability can be exploited by any users that have legitimate
access to the upload functionality and can lead to arbitrary code
execution, denial of service and disclosure of confidential information.&lt;/p&gt;
&lt;p&gt;### Patches
Yes, see version 1.9.3 and 2.1.5.&lt;/p&gt;
&lt;p&gt;### References
https://owasp.org/www-community/attacks/Path_Traversal&lt;/p&gt;
&lt;p&gt;### Credits:
This security vulnerability was found by Thibaud Kehler of SySS GmbH.
E-Mail: thibaud.kehler@syss.de&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: oneup/uploader-bundle&lt;/p&gt;
&lt;p&gt;### Impact
The vulnerability was identified in the web service for a chunked file
upload. While the names of the POST parameters vary with the used
frontend, their values are always used in the same way to build a path
where the chunks are stored and assembled temporarily. By not validating
these parameters properly, OneupUploaderBundle is susceptible to a path
traversal vulnerability which can be exploited to upload files to
arbitrary folders on the filesystem. The assembly process can further be
misused with some restrictions to delete and copy files to other
locations.&lt;/p&gt;
&lt;p&gt;The vulnerability can be exploited by any users that have legitimate
access to the upload functionality and can lead to arbitrary code
execution, denial of service and disclosure of confidential information.&lt;/p&gt;
&lt;p&gt;### Patches
Yes, see version 1.9.3 and 2.1.5.&lt;/p&gt;
&lt;p&gt;### References
https://owasp.org/www-community/attacks/Path_Traversal&lt;/p&gt;
&lt;p&gt;### Credits:
This security vulnerability was found by Thibaud Kehler of SySS GmbH.
E-Mail: thibaud.kehler@syss.de&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x8wj-6m73-gfqp</guid>
    </item>
    <item>
      <title>gsd-2020-5237</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-5237</link>
      <description>gsd-2020-5237</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-5237</guid>
    </item>
  </channel>
</rss>
