<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 23:08:40 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-207110</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-207110</link>
      <description>EUVD-2026-207110</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-207110</guid>
    </item>
    <item>
      <title>fkie_cve-2024-55889</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-55889</link>
      <description>&lt;p&gt;phpMyFAQ is an open source FAQ web application. Prior to version 3.2.10, a vulnerability exists in the FAQ Record component where a privileged attacker can trigger a file download on a victim&amp;#39;s machine upon page visit by embedding it in an &amp;lt;iframe&amp;gt; element without user interaction or explicit consent. Version 3.2.10 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;phpMyFAQ is an open source FAQ web application. Prior to version 3.2.10, a vulnerability exists in the FAQ Record component where a privileged attacker can trigger a file download on a victim&amp;#39;s machine upon page visit by embedding it in an &amp;lt;iframe&amp;gt; element without user interaction or explicit consent. Version 3.2.10 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-55889</guid>
    </item>
    <item>
      <title>GHSA-m3r7-8gw7-qwvc — thorsten/phpmyfaq Unintended File Download Triggered by Embedded Frames</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m3r7-8gw7-qwvc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: thorsten/phpmyfaq&lt;/p&gt;
&lt;p&gt;### Summary
A vulnerability exists in the FAQ Record component where a privileged attacker can trigger a file download on a victim&amp;#39;s machine upon page visit by embedding it in an &amp;lt;iframe&amp;gt; element without user interaction or explicit consent.&lt;/p&gt;
&lt;p&gt;### Details
In http://localhost/admin/index.php?action=editentry&amp;amp;id=20&amp;amp;lang=en, where a FAQ record is either created or edited, an attacker can insert an iframe, as &amp;#34;source code&amp;#34;, pointing to a prior &amp;#34;malicious&amp;#34; attachment that the attacker has uploaded via FAQ &amp;#34;new attachment&amp;#34; upload, such that any page visits to this FAQ will trigger an automated download (from the edit screen, download is automated; from the faq page view as a normal user, depending on the browser, a pop up confirmation may be presented before the actual download. Firebox browser, for instance, does not require any interactions).
![image](https://github.com/user-attachments/assets/74fee719-1eea-4bcb-9c7d-da0c5045c74b)&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. create a new FAQ record and upload a &amp;#34;malicious&amp;#34; file - in my case, I uploaded an eicar file. take note of the uri, ie &amp;lt;p&amp;gt;&amp;lt;iframe &amp;#34;index.php?action=attachment&amp;amp;amp;id=2&amp;#34;
![image](https://github.com/user-attachments/assets/06072ef6-9311-423a-a735-1d6a3274cde8)&lt;/p&gt;
&lt;p&gt;3. in the FAQ record, insert a &amp;#34;source code&amp;#34; blob using the &amp;#34;&amp;lt; &amp;gt;&amp;#34; button
4. insert in the following snippet: &amp;lt;p&amp;gt;&amp;lt;iframe src=&amp;#34;index.php?action=attachment&amp;amp;amp;id=2&amp;#34;&amp;gt;&amp;lt;/iframe&amp;gt;&amp;lt;/p&amp;gt; and save FAQ record
5. once the edit page reloads, the malicious code will be downloaded onto the local mach…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: thorsten/phpmyfaq&lt;/p&gt;
&lt;p&gt;### Summary
A vulnerability exists in the FAQ Record component where a privileged attacker can trigger a file download on a victim&amp;#39;s machine upon page visit by embedding it in an &amp;lt;iframe&amp;gt; element without user interaction or explicit consent.&lt;/p&gt;
&lt;p&gt;### Details
In http://localhost/admin/index.php?action=editentry&amp;amp;id=20&amp;amp;lang=en, where a FAQ record is either created or edited, an attacker can insert an iframe, as &amp;#34;source code&amp;#34;, pointing to a prior &amp;#34;malicious&amp;#34; attachment that the attacker has uploaded via FAQ &amp;#34;new attachment&amp;#34; upload, such that any page visits to this FAQ will trigger an automated download (from the edit screen, download is automated; from the faq page view as a normal user, depending on the browser, a pop up confirmation may be presented before the actual download. Firebox browser, for instance, does not require any interactions).
![image](https://github.com/user-attachments/assets/74fee719-1eea-4bcb-9c7d-da0c5045c74b)&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. create a new FAQ record and upload a &amp;#34;malicious&amp;#34; file - in my case, I uploaded an eicar file. take note of the uri, ie &amp;lt;p&amp;gt;&amp;lt;iframe &amp;#34;index.php?action=attachment&amp;amp;amp;id=2&amp;#34;
![image](https://github.com/user-attachments/assets/06072ef6-9311-423a-a735-1d6a3274cde8)&lt;/p&gt;
&lt;p&gt;3. in the FAQ record, insert a &amp;#34;source code&amp;#34; blob using the &amp;#34;&amp;lt; &amp;gt;&amp;#34; button
4. insert in the following snippet: &amp;lt;p&amp;gt;&amp;lt;iframe src=&amp;#34;index.php?action=attachment&amp;amp;amp;id=2&amp;#34;&amp;gt;&amp;lt;/iframe&amp;gt;&amp;lt;/p&amp;gt; and save FAQ record
5. once the edit page reloads, the malicious code will be downloaded onto the local mach…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m3r7-8gw7-qwvc</guid>
    </item>
  </channel>
</rss>
