<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 02:29:47 +0000</lastBuildDate>
    <item>
      <title>cnvd-2025-12129</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2025-12129</link>
      <description>cnvd-2025-12129</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2025-12129</guid>
    </item>
    <item>
      <title>EUVD-2026-212169</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-212169</link>
      <description>EUVD-2026-212169</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-212169</guid>
    </item>
    <item>
      <title>fkie_cve-2024-11956</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-11956</link>
      <description>&lt;p&gt;A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affected by this issue is some unknown functionality of the file /admin/customermanagementframework/customers/list. The manipulation of the argument filterDefinition/filter leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affected by this issue is some unknown functionality of the file /admin/customermanagementframework/customers/list. The manipulation of the argument filterDefinition/filter leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-11956</guid>
    </item>
    <item>
      <title>GHSA-q53r-9hh9-w277 — pimcore/customer-data-framework vulnerable to SQL Injection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q53r-9hh9-w277</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: pimcore/customer-management-framework-bundle&lt;/p&gt;
&lt;p&gt;An SQL injection vulnerability allows any authenticated user to execute arbitrary SQL commands on the server. This can lead to unauthorized access to sensitive data, data modification, or even complete control over the server.&lt;/p&gt;
&lt;p&gt;Details
The vulnerability is found in the URL parameters of the following endpoint:&lt;/p&gt;
&lt;p&gt;`GET /admin/customermanagementframework/customers/list?add-new-customer=1&amp;amp;apply-segment-selection=Apply&amp;amp;filterDefinition[allowedRoleIds][]=1&amp;amp;filterDefinition[allowedUserIds][]=2&amp;amp;filterDefinition[id]=0&amp;amp;filterDefinition[name]=RDFYjolf&amp;amp;filterDefinition[readOnly]=on&amp;amp;filterDefinition[shortcutAvailable]=on&amp;amp;filter[active]=1&amp;amp;filter[email]=testing%40example.com&amp;amp;filter[firstname]=RDFYjolf&amp;amp;filter[id]=1&amp;amp;filter[lastname]=RDFYjolf&amp;amp;filter[operator-customer]=AND&amp;amp;filter[operator-segments]=%40%40dz1Uu&amp;amp;filter[search]=the&amp;amp;filter[segments][832][]=847&amp;amp;filter[segments][833][]=835&amp;amp;filter[segments][874][]=876&amp;amp;filter[showSegments][]=832 HTTP/1.1`&lt;/p&gt;
&lt;p&gt;The parameters filterDefinition and filter are vulnerable to SQL injection. When a specially crafted input is provided, it results in an SQL error, indicating that the input is being directly used in an SQL query without proper sanitization.&lt;/p&gt;
&lt;p&gt;PoC
To reproduce the vulnerability, follow these steps:&lt;/p&gt;
&lt;p&gt;Open a web browser or a tool like curl or Postman.
Authenticate with valid user credentials.
Navigate to the following URL with the vulnerable parameters:
```
https://demo.pimcore.fun/admin/customermanagementframework/customers/list?add-new-customer=1&amp;amp;appl…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: pimcore/customer-management-framework-bundle&lt;/p&gt;
&lt;p&gt;An SQL injection vulnerability allows any authenticated user to execute arbitrary SQL commands on the server. This can lead to unauthorized access to sensitive data, data modification, or even complete control over the server.&lt;/p&gt;
&lt;p&gt;Details
The vulnerability is found in the URL parameters of the following endpoint:&lt;/p&gt;
&lt;p&gt;`GET /admin/customermanagementframework/customers/list?add-new-customer=1&amp;amp;apply-segment-selection=Apply&amp;amp;filterDefinition[allowedRoleIds][]=1&amp;amp;filterDefinition[allowedUserIds][]=2&amp;amp;filterDefinition[id]=0&amp;amp;filterDefinition[name]=RDFYjolf&amp;amp;filterDefinition[readOnly]=on&amp;amp;filterDefinition[shortcutAvailable]=on&amp;amp;filter[active]=1&amp;amp;filter[email]=testing%40example.com&amp;amp;filter[firstname]=RDFYjolf&amp;amp;filter[id]=1&amp;amp;filter[lastname]=RDFYjolf&amp;amp;filter[operator-customer]=AND&amp;amp;filter[operator-segments]=%40%40dz1Uu&amp;amp;filter[search]=the&amp;amp;filter[segments][832][]=847&amp;amp;filter[segments][833][]=835&amp;amp;filter[segments][874][]=876&amp;amp;filter[showSegments][]=832 HTTP/1.1`&lt;/p&gt;
&lt;p&gt;The parameters filterDefinition and filter are vulnerable to SQL injection. When a specially crafted input is provided, it results in an SQL error, indicating that the input is being directly used in an SQL query without proper sanitization.&lt;/p&gt;
&lt;p&gt;PoC
To reproduce the vulnerability, follow these steps:&lt;/p&gt;
&lt;p&gt;Open a web browser or a tool like curl or Postman.
Authenticate with valid user credentials.
Navigate to the following URL with the vulnerable parameters:
```
https://demo.pimcore.fun/admin/customermanagementframework/customers/list?add-new-customer=1&amp;amp;appl…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q53r-9hh9-w277</guid>
    </item>
  </channel>
</rss>
