<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 01:58:07 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-277182</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277182</link>
      <description>EUVD-2026-277182</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277182</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33649</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33649</link>
      <description>&lt;p&gt;WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Permissions/setPermission.json.php` endpoint accepts GET parameters for a state-changing operation that modifies user group permissions. The endpoint has no CSRF token validation, and the application explicitly sets `session.cookie_samesite=None` on session cookies. This allows an unauthenticated attacker to craft a page with `&amp;lt;img&amp;gt;` tags that, when visited by an admin, silently grant arbitrary permissions to the attacker&amp;#39;s user group — escalating the attacker to near-admin access. As of time of publication, no known patched versions are available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Permissions/setPermission.json.php` endpoint accepts GET parameters for a state-changing operation that modifies user group permissions. The endpoint has no CSRF token validation, and the application explicitly sets `session.cookie_samesite=None` on session cookies. This allows an unauthenticated attacker to craft a page with `&amp;lt;img&amp;gt;` tags that, when visited by an admin, silently grant arbitrary permissions to the attacker&amp;#39;s user group — escalating the attacker to near-admin access. As of time of publication, no known patched versions are available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33649</guid>
    </item>
    <item>
      <title>GHSA-g8x9-7mgh-7cvj — AVideo's GET-Based CSRF in setPermission.json.php Enables Privilege Escalation via Arbitrary Permission Modification</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g8x9-7mgh-7cvj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wwbn/avideo&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `plugin/Permissions/setPermission.json.php` endpoint accepts GET parameters for a state-changing operation that modifies user group permissions. The endpoint has no CSRF token validation, and the application explicitly sets `session.cookie_samesite=None` on session cookies. This allows an unauthenticated attacker to craft a page with `&amp;lt;img&amp;gt;` tags that, when visited by an admin, silently grant arbitrary permissions to the attacker&amp;#39;s user group — escalating the attacker to near-admin access.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The root cause is a combination of three issues:&lt;/p&gt;
&lt;p&gt;**1. `$_REQUEST` used instead of `$_POST` (accepts GET parameters):**&lt;/p&gt;
&lt;p&gt;`plugin/Permissions/setPermission.json.php:14-24`:
```php
$intvalList = array(&amp;#39;users_groups_id&amp;#39;,&amp;#39;plugins_id&amp;#39;,&amp;#39;type&amp;#39;,&amp;#39;isEnabled&amp;#39;);
foreach ($intvalList as $value) {
    if($_REQUEST[$value]===&amp;#39;true&amp;#39;){
        $_REQUEST[$value] = 1;
    }else{
        $_REQUEST[$value] = intval($_REQUEST[$value]);
    }
}&lt;/p&gt;
&lt;p&gt;$obj = new stdClass();
$obj-&amp;gt;id = Permissions::setPermission($_REQUEST[&amp;#39;users_groups_id&amp;#39;], $_REQUEST[&amp;#39;plugins_id&amp;#39;], $_REQUEST[&amp;#39;type&amp;#39;], $_REQUEST[&amp;#39;isEnabled&amp;#39;]);
```&lt;/p&gt;
&lt;p&gt;The only authorization check is `User::isAdmin()` at line 10 — there is no CSRF token validation via `isGlobalTokenValid()`.&lt;/p&gt;
&lt;p&gt;**2. Session cookies set to `SameSite=None`:**&lt;/p&gt;
&lt;p&gt;`objects/include_config.php:134-141`:
```php
if ($isHTTPS) {
    // SameSite=None is intentional: AVideo supports cross-origin iframe embedding
    ini_set(&amp;#39;session.cookie_samesite&amp;#39;, &amp;#39;None&amp;#39;);
    ini_set(&amp;#39;sess…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wwbn/avideo&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `plugin/Permissions/setPermission.json.php` endpoint accepts GET parameters for a state-changing operation that modifies user group permissions. The endpoint has no CSRF token validation, and the application explicitly sets `session.cookie_samesite=None` on session cookies. This allows an unauthenticated attacker to craft a page with `&amp;lt;img&amp;gt;` tags that, when visited by an admin, silently grant arbitrary permissions to the attacker&amp;#39;s user group — escalating the attacker to near-admin access.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The root cause is a combination of three issues:&lt;/p&gt;
&lt;p&gt;**1. `$_REQUEST` used instead of `$_POST` (accepts GET parameters):**&lt;/p&gt;
&lt;p&gt;`plugin/Permissions/setPermission.json.php:14-24`:
```php
$intvalList = array(&amp;#39;users_groups_id&amp;#39;,&amp;#39;plugins_id&amp;#39;,&amp;#39;type&amp;#39;,&amp;#39;isEnabled&amp;#39;);
foreach ($intvalList as $value) {
    if($_REQUEST[$value]===&amp;#39;true&amp;#39;){
        $_REQUEST[$value] = 1;
    }else{
        $_REQUEST[$value] = intval($_REQUEST[$value]);
    }
}&lt;/p&gt;
&lt;p&gt;$obj = new stdClass();
$obj-&amp;gt;id = Permissions::setPermission($_REQUEST[&amp;#39;users_groups_id&amp;#39;], $_REQUEST[&amp;#39;plugins_id&amp;#39;], $_REQUEST[&amp;#39;type&amp;#39;], $_REQUEST[&amp;#39;isEnabled&amp;#39;]);
```&lt;/p&gt;
&lt;p&gt;The only authorization check is `User::isAdmin()` at line 10 — there is no CSRF token validation via `isGlobalTokenValid()`.&lt;/p&gt;
&lt;p&gt;**2. Session cookies set to `SameSite=None`:**&lt;/p&gt;
&lt;p&gt;`objects/include_config.php:134-141`:
```php
if ($isHTTPS) {
    // SameSite=None is intentional: AVideo supports cross-origin iframe embedding
    ini_set(&amp;#39;session.cookie_samesite&amp;#39;, &amp;#39;None&amp;#39;);
    ini_set(&amp;#39;sess…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g8x9-7mgh-7cvj</guid>
    </item>
  </channel>
</rss>
