<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 08:40:03 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-265145</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-265145</link>
      <description>EUVD-2026-265145</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-265145</guid>
    </item>
    <item>
      <title>fkie_cve-2026-22242</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22242</link>
      <description>&lt;p&gt;CoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4.1.8, a blind SQL injection vulnerability exists in the application that allows an authenticated administrator-level user to extract database contents using boolean-based or time-based techniques. The database account used by the application is read-only and non-DBA, limiting impact to confidential data disclosure only. No data modification or service disruption is possible. This issue has been patched in version 4.1.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4.1.8, a blind SQL injection vulnerability exists in the application that allows an authenticated administrator-level user to extract database contents using boolean-based or time-based techniques. The database account used by the application is read-only and non-DBA, limiting impact to confidential data disclosure only. No data modification or service disruption is possible. This issue has been patched in version 4.1.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-22242</guid>
    </item>
    <item>
      <title>GHSA-ch7p-mpv4-4vg4 — CoreShop Vulnerable to SQL Injection via Admin Reports</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ch7p-mpv4-4vg4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: coreshop/core-shop&lt;/p&gt;
&lt;p&gt;### Affected Version(s)&lt;/p&gt;
&lt;p&gt;- CoreShop 4.1.2 Demo (tested) [Demo | CoreShop](https://docs.coreshop.com/CoreShop/Getting_Started/Demo/index.html)
- Earlier versions may also be affected if the same code path exists&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A blind SQL injection vulnerability exists in the application that allows an authenticated administrator-level user to extract database contents using boolean-based or time-based techniques.
The database account used by the application is read-only and non-DBA, limiting impact to confidential data disclosure only. No data modification or service disruption is possible.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability occurs due to unsanitized user input being concatenated into a SQL query without proper parameterization.&lt;/p&gt;
&lt;p&gt;An attacker with administrative access can manipulate the affected parameter to influence the backend SQL query logic. Although no direct query output is returned, boolean and time-based inference techniques allow an attacker to extract data from the database.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;**Vulnerability Type:** Blind SQL Injection&lt;/p&gt;
&lt;p&gt;**Impact:** Confidentiality only&lt;/p&gt;
&lt;p&gt;An attacker can:&lt;/p&gt;
&lt;p&gt;- Enumerate database schema
- Extract all data accessible to the application’s database user&lt;/p&gt;
&lt;p&gt;**CVSS v3.1 (Base Score: 4.9 – Medium)**&lt;/p&gt;
&lt;p&gt;```
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
```&lt;/p&gt;
&lt;p&gt;### Steps to Reproduce:&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1010&amp;#34; height=&amp;#34;372&amp;#34; alt=&amp;#34;1&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/312422c8-f3ea-4332-8c14-59aed737da6a&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;1. **Send a Normal Request:**
    - Request the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: coreshop/core-shop&lt;/p&gt;
&lt;p&gt;### Affected Version(s)&lt;/p&gt;
&lt;p&gt;- CoreShop 4.1.2 Demo (tested) [Demo | CoreShop](https://docs.coreshop.com/CoreShop/Getting_Started/Demo/index.html)
- Earlier versions may also be affected if the same code path exists&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A blind SQL injection vulnerability exists in the application that allows an authenticated administrator-level user to extract database contents using boolean-based or time-based techniques.
The database account used by the application is read-only and non-DBA, limiting impact to confidential data disclosure only. No data modification or service disruption is possible.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability occurs due to unsanitized user input being concatenated into a SQL query without proper parameterization.&lt;/p&gt;
&lt;p&gt;An attacker with administrative access can manipulate the affected parameter to influence the backend SQL query logic. Although no direct query output is returned, boolean and time-based inference techniques allow an attacker to extract data from the database.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;**Vulnerability Type:** Blind SQL Injection&lt;/p&gt;
&lt;p&gt;**Impact:** Confidentiality only&lt;/p&gt;
&lt;p&gt;An attacker can:&lt;/p&gt;
&lt;p&gt;- Enumerate database schema
- Extract all data accessible to the application’s database user&lt;/p&gt;
&lt;p&gt;**CVSS v3.1 (Base Score: 4.9 – Medium)**&lt;/p&gt;
&lt;p&gt;```
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
```&lt;/p&gt;
&lt;p&gt;### Steps to Reproduce:&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1010&amp;#34; height=&amp;#34;372&amp;#34; alt=&amp;#34;1&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/312422c8-f3ea-4332-8c14-59aed737da6a&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;1. **Send a Normal Request:**
    - Request the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ch7p-mpv4-4vg4</guid>
    </item>
  </channel>
</rss>
