<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 20:43:26 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-244938</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-244938</link>
      <description>EUVD-2026-244938</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-244938</guid>
    </item>
    <item>
      <title>fkie_cve-2023-49783</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-49783</link>
      <description>&lt;p&gt;Silverstripe Admin provides a basic management interface for the Silverstripe Framework. In versions on the 1.x branch prior to 1.13.19 and on the 2.x branch prior to 2.1.8, users who don&amp;#39;t have edit or delete permissions for records exposed in a `ModelAdmin` can still edit or delete records using the CSV import form, provided they have create permissions. The likelihood of a user having create permissions but not having edit or delete permissions is low, but it is possible. Note that this doesn&amp;#39;t affect any `ModelAdmin` which has had the import form disabled via the `showImportForm` public property. Versions 1.13.19 and 2.1.8 contain a patch for the issue. Those who have a custom implementation of `BulkLoader` should update their implementations to respect permissions when the return value of `getCheckPermissions()` is true. Those who use any `BulkLoader` in their own project logic, or maintain a module which uses it, should consider passing `true` to `setCheckPermissions()` if the data is provided by users.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Silverstripe Admin provides a basic management interface for the Silverstripe Framework. In versions on the 1.x branch prior to 1.13.19 and on the 2.x branch prior to 2.1.8, users who don&amp;#39;t have edit or delete permissions for records exposed in a `ModelAdmin` can still edit or delete records using the CSV import form, provided they have create permissions. The likelihood of a user having create permissions but not having edit or delete permissions is low, but it is possible. Note that this doesn&amp;#39;t affect any `ModelAdmin` which has had the import form disabled via the `showImportForm` public property. Versions 1.13.19 and 2.1.8 contain a patch for the issue. Those who have a custom implementation of `BulkLoader` should update their implementations to respect permissions when the return value of `getCheckPermissions()` is true. Those who use any `BulkLoader` in their own project logic, or maintain a module which uses it, should consider passing `true` to `setCheckPermissions()` if the data is provided by users.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-49783</guid>
    </item>
    <item>
      <title>GHSA-j3m6-gvm8-mhvw — No permission checks for editing/deleting records with CSV import form</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j3m6-gvm8-mhvw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: silverstripe/admin&lt;/p&gt;
&lt;p&gt;### Impact
Users who don&amp;#39;t have edit or delete permissions for records exposed in a `ModelAdmin` can still edit or delete records using the CSV import form, provided they have create permissions.&lt;/p&gt;
&lt;p&gt;The likelyhood of a user having create permissions but _not_ having edit or delete permissions is low, but it _is_ possible.&lt;/p&gt;
&lt;p&gt;Note that this doesn&amp;#39;t affect any `ModelAdmin` which has had the import form disabled via the [`showImportForm` public property](https://api.silverstripe.org/4/SilverStripe/Admin/ModelAdmin.html#property_showImportForm), nor does it impact the `SecurityAdmin` section.&lt;/p&gt;
&lt;p&gt;#### Action may be required&lt;/p&gt;
&lt;p&gt;If you have a custom implementation of [`BulkLoader`](https://api.silverstripe.org/4/SilverStripe/Dev/BulkLoader.html), you should update your implementation to respect permissions when the return value of [`getCheckPermissions()`](https://api.silverstripe.org/4/SilverStripe/Dev/BulkLoader.html#method_getCheckPermissions) is true.&lt;/p&gt;
&lt;p&gt;If you are using any `BulkLoader` in your own project logic, or maintain a module which uses it, you should consider passing `true` to [`setCheckPermissions()`](https://api.silverstripe.org/4/SilverStripe/Dev/BulkLoader.html#method_setCheckPermissions) if the data is provided by users.&lt;/p&gt;
&lt;p&gt;**Base CVSS:** [4.3](https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:F/RL:O/RC:C&amp;amp;version=3.1)
**Reported by:** Guy Sartorelli from Silverstripe&lt;/p&gt;
&lt;p&gt;### References
- https://www.silverstripe.org/download/secur…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: silverstripe/admin&lt;/p&gt;
&lt;p&gt;### Impact
Users who don&amp;#39;t have edit or delete permissions for records exposed in a `ModelAdmin` can still edit or delete records using the CSV import form, provided they have create permissions.&lt;/p&gt;
&lt;p&gt;The likelyhood of a user having create permissions but _not_ having edit or delete permissions is low, but it _is_ possible.&lt;/p&gt;
&lt;p&gt;Note that this doesn&amp;#39;t affect any `ModelAdmin` which has had the import form disabled via the [`showImportForm` public property](https://api.silverstripe.org/4/SilverStripe/Admin/ModelAdmin.html#property_showImportForm), nor does it impact the `SecurityAdmin` section.&lt;/p&gt;
&lt;p&gt;#### Action may be required&lt;/p&gt;
&lt;p&gt;If you have a custom implementation of [`BulkLoader`](https://api.silverstripe.org/4/SilverStripe/Dev/BulkLoader.html), you should update your implementation to respect permissions when the return value of [`getCheckPermissions()`](https://api.silverstripe.org/4/SilverStripe/Dev/BulkLoader.html#method_getCheckPermissions) is true.&lt;/p&gt;
&lt;p&gt;If you are using any `BulkLoader` in your own project logic, or maintain a module which uses it, you should consider passing `true` to [`setCheckPermissions()`](https://api.silverstripe.org/4/SilverStripe/Dev/BulkLoader.html#method_setCheckPermissions) if the data is provided by users.&lt;/p&gt;
&lt;p&gt;**Base CVSS:** [4.3](https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:F/RL:O/RC:C&amp;amp;version=3.1)
**Reported by:** Guy Sartorelli from Silverstripe&lt;/p&gt;
&lt;p&gt;### References
- https://www.silverstripe.org/download/secur…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j3m6-gvm8-mhvw</guid>
    </item>
    <item>
      <title>gsd-2023-49783</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-49783</link>
      <description>gsd-2023-49783</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-49783</guid>
    </item>
  </channel>
</rss>
