<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 20:36:56 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-243682</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-243682</link>
      <description>EUVD-2026-243682</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-243682</guid>
    </item>
    <item>
      <title>fkie_cve-2025-49141</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-49141</link>
      <description>&lt;p&gt;HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.3, the `gitImportSite` functionality obtains a URL string from a POST request and insufficiently validates user input. The `set_remote` function later passes this input into `proc_open`, yielding OS command injection. An authenticated attacker can craft a URL string that bypasses the validation checks employed by the `filter_var` and `strpos` functions in order to execute arbitrary OS commands on the backend server. The attacker can exfiltrate command output via an HTTP request. Version 11.0.3 contains a patch for the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.3, the `gitImportSite` functionality obtains a URL string from a POST request and insufficiently validates user input. The `set_remote` function later passes this input into `proc_open`, yielding OS command injection. An authenticated attacker can craft a URL string that bypasses the validation checks employed by the `filter_var` and `strpos` functions in order to execute arbitrary OS commands on the backend server. The attacker can exfiltrate command output via an HTTP request. Version 11.0.3 contains a patch for the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-49141</guid>
    </item>
    <item>
      <title>GHSA-g4cf-pp4x-hqgw — HaxCMS-PHP Command Injection Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g4cf-pp4x-hqgw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @haxtheweb/haxcms-nodejs&lt;/p&gt;
&lt;p&gt;### Summary
The &amp;#39;gitImportSite&amp;#39; functionality obtains a URL string from a POST request and insufficiently validates user input. The ’set_remote’ function later passes this input into ’proc_open’, yielding OS command injection.&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability exists in the logic of the ’gitImportSite’ function, located in ’Operations.php’. The current implementation only relies on the ’filter_var’ and &amp;#39;strpos&amp;#39; functions to validate the URL, which is not sufficient to ensure absence of all Bash special characters used for command injection.
![gitImportSite](https://github.com/user-attachments/assets/af9935ef-4735-446d-833f-2c2590ff1508)&lt;/p&gt;
&lt;p&gt;#### Affected Resources
• Operations.php:2103 gitImportSite()
• \&amp;lt;domain\&amp;gt;/\&amp;lt;user\&amp;gt;/system/api/gitImportSite&lt;/p&gt;
&lt;p&gt;### PoC
To replicate this vulnerability, authenticate and send a POST request to the &amp;#39;gitImportSite&amp;#39; endpoint with a crafted URL in the JSON data. Note, a valid token needs to be obtained by capturing a request to another API endpoint (such as &amp;#39;archiveSite&amp;#39;).&lt;/p&gt;
&lt;p&gt;1. Start a webserver.
![webserver](https://github.com/user-attachments/assets/8594f9b1-67fa-4352-bbc3-310bb164ec9b)&lt;/p&gt;
&lt;p&gt;2. Initiate a request to the ’archiveSite’ endpoint.
![archiveSite](https://github.com/user-attachments/assets/08503f36-d984-4d53-8fe6-577ad78d5eb7)&lt;/p&gt;
&lt;p&gt;3.  Capture and modify the request in BurpSuite.
![request-modification](https://github.com/user-attachments/assets/61cd211e-afd3-453e-b86b-58bccffaf824)&lt;/p&gt;
&lt;p&gt;4. Observe command output in the HTTP request from the s…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @haxtheweb/haxcms-nodejs&lt;/p&gt;
&lt;p&gt;### Summary
The &amp;#39;gitImportSite&amp;#39; functionality obtains a URL string from a POST request and insufficiently validates user input. The ’set_remote’ function later passes this input into ’proc_open’, yielding OS command injection.&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability exists in the logic of the ’gitImportSite’ function, located in ’Operations.php’. The current implementation only relies on the ’filter_var’ and &amp;#39;strpos&amp;#39; functions to validate the URL, which is not sufficient to ensure absence of all Bash special characters used for command injection.
![gitImportSite](https://github.com/user-attachments/assets/af9935ef-4735-446d-833f-2c2590ff1508)&lt;/p&gt;
&lt;p&gt;#### Affected Resources
• Operations.php:2103 gitImportSite()
• \&amp;lt;domain\&amp;gt;/\&amp;lt;user\&amp;gt;/system/api/gitImportSite&lt;/p&gt;
&lt;p&gt;### PoC
To replicate this vulnerability, authenticate and send a POST request to the &amp;#39;gitImportSite&amp;#39; endpoint with a crafted URL in the JSON data. Note, a valid token needs to be obtained by capturing a request to another API endpoint (such as &amp;#39;archiveSite&amp;#39;).&lt;/p&gt;
&lt;p&gt;1. Start a webserver.
![webserver](https://github.com/user-attachments/assets/8594f9b1-67fa-4352-bbc3-310bb164ec9b)&lt;/p&gt;
&lt;p&gt;2. Initiate a request to the ’archiveSite’ endpoint.
![archiveSite](https://github.com/user-attachments/assets/08503f36-d984-4d53-8fe6-577ad78d5eb7)&lt;/p&gt;
&lt;p&gt;3.  Capture and modify the request in BurpSuite.
![request-modification](https://github.com/user-attachments/assets/61cd211e-afd3-453e-b86b-58bccffaf824)&lt;/p&gt;
&lt;p&gt;4. Observe command output in the HTTP request from the s…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g4cf-pp4x-hqgw</guid>
    </item>
  </channel>
</rss>
