<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 07:03:58 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-201442</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-201442</link>
      <description>EUVD-2026-201442</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-201442</guid>
    </item>
    <item>
      <title>fkie_cve-2024-52292</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-52292</link>
      <description>&lt;p&gt;Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions on system notification templates. This function accepts an absolute file path, reads the file&amp;#39;s content, and converts it into a Base64-encoded string. By embedding this function within a system notification template, the attacker can exfiltrate the Base64-encoded file content through a triggered system email notification. Once the email is received, the Base64 payload can be decoded, allowing the attacker to read arbitrary files on the server. This is fixed in 5.4.9 and 4.12.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions on system notification templates. This function accepts an absolute file path, reads the file&amp;#39;s content, and converts it into a Base64-encoded string. By embedding this function within a system notification template, the attacker can exfiltrate the Base64-encoded file content through a triggered system email notification. Once the email is received, the Base64 payload can be decoded, allowing the attacker to read arbitrary files on the server. This is fixed in 5.4.9 and 4.12.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-52292</guid>
    </item>
    <item>
      <title>GHSA-cw6g-qmjq-6w2w — Craft CMS Arbitrary System File Read</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cw6g-qmjq-6w2w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: craftcms/cms&lt;/p&gt;
&lt;p&gt;### Summary
By abusing the mail notification template it is possible to read arbitrary operating system files.&lt;/p&gt;
&lt;p&gt;### Details
The [dataUrl](https://craftcms.com/docs/3.x/dev/functions.html#dataurl) function can be exploited if an attacker has write permissions on system notification templates. This function accepts an absolute file path, reads the file&amp;#39;s content, and converts it into a Base64-encoded string. By embedding this function within a system notification template, the attacker can exfiltrate the Base64-encoded file content through a triggered system email notification. Once the email is received, the Base64 payload can be decoded, allowing the attacker to read arbitrary files on the server.&lt;/p&gt;
&lt;p&gt;Requirements:
* write permissions to system notification templates
* ability to trigger a corresponding system email&lt;/p&gt;
&lt;p&gt;### PoC
1) Modify a template to contain the following twig template string:
```twig
{{ dataUrl(&amp;#39;/var/www/web/.env&amp;#39;) }}
```
2) Trigger the corresponding notification email (e.g. by resetting a password)
3) Receive the email and decode the base64 string&lt;/p&gt;
&lt;p&gt;Mail received:
![Bildschirmfoto 2024-09-05 um 16 20 41](https://github.com/user-attachments/assets/24dc5196-6847-4006-b7ef-8cd10d659c30)&lt;/p&gt;
&lt;p&gt;Decoded string:
![Bildschirmfoto 2024-09-05 um 16 28 24](https://github.com/user-attachments/assets/1913a475-5277-49b9-9210-2f3fcd3b9bf1)&lt;/p&gt;
&lt;p&gt;### Impact
1) Exposure of Sensitive Information: Arbitrary file read can lead to the exposure of sensitive data such as configuration files (…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: craftcms/cms&lt;/p&gt;
&lt;p&gt;### Summary
By abusing the mail notification template it is possible to read arbitrary operating system files.&lt;/p&gt;
&lt;p&gt;### Details
The [dataUrl](https://craftcms.com/docs/3.x/dev/functions.html#dataurl) function can be exploited if an attacker has write permissions on system notification templates. This function accepts an absolute file path, reads the file&amp;#39;s content, and converts it into a Base64-encoded string. By embedding this function within a system notification template, the attacker can exfiltrate the Base64-encoded file content through a triggered system email notification. Once the email is received, the Base64 payload can be decoded, allowing the attacker to read arbitrary files on the server.&lt;/p&gt;
&lt;p&gt;Requirements:
* write permissions to system notification templates
* ability to trigger a corresponding system email&lt;/p&gt;
&lt;p&gt;### PoC
1) Modify a template to contain the following twig template string:
```twig
{{ dataUrl(&amp;#39;/var/www/web/.env&amp;#39;) }}
```
2) Trigger the corresponding notification email (e.g. by resetting a password)
3) Receive the email and decode the base64 string&lt;/p&gt;
&lt;p&gt;Mail received:
![Bildschirmfoto 2024-09-05 um 16 20 41](https://github.com/user-attachments/assets/24dc5196-6847-4006-b7ef-8cd10d659c30)&lt;/p&gt;
&lt;p&gt;Decoded string:
![Bildschirmfoto 2024-09-05 um 16 28 24](https://github.com/user-attachments/assets/1913a475-5277-49b9-9210-2f3fcd3b9bf1)&lt;/p&gt;
&lt;p&gt;### Impact
1) Exposure of Sensitive Information: Arbitrary file read can lead to the exposure of sensitive data such as configuration files (…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cw6g-qmjq-6w2w</guid>
    </item>
  </channel>
</rss>
