<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 18:39:29 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-278235</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-278235</link>
      <description>EUVD-2026-278235</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-278235</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34362</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34362</link>
      <description>&lt;p&gt;WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `verifyTokenSocket()` function in `plugin/YPTSocket/functions.php` has its token timeout validation commented out, causing WebSocket tokens to never expire despite being generated with a 12-hour timeout. This allows captured or legitimately obtained tokens to provide permanent WebSocket access, even after user accounts are deleted, banned, or demoted from admin. Admin tokens grant access to real-time connection data for all online users including IP addresses, browser info, and page locations. Commit 5d5237121bf82c24e9e0fdd5bc1699f1157783c5 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `verifyTokenSocket()` function in `plugin/YPTSocket/functions.php` has its token timeout validation commented out, causing WebSocket tokens to never expire despite being generated with a 12-hour timeout. This allows captured or legitimately obtained tokens to provide permanent WebSocket access, even after user accounts are deleted, banned, or demoted from admin. Admin tokens grant access to real-time connection data for all online users including IP addresses, browser info, and page locations. Commit 5d5237121bf82c24e9e0fdd5bc1699f1157783c5 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34362</guid>
    </item>
    <item>
      <title>GHSA-2mg4-pfgx-64cf — AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTokenSocket()</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2mg4-pfgx-64cf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wwbn/avideo&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `verifyTokenSocket()` function in `plugin/YPTSocket/functions.php` has its token timeout validation commented out, causing WebSocket tokens to never expire despite being generated with a 12-hour timeout. This allows captured or legitimately obtained tokens to provide permanent WebSocket access, even after user accounts are deleted, banned, or demoted from admin. Admin tokens grant access to real-time connection data for all online users including IP addresses, browser info, and page locations.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;WebSocket tokens are generated via `getEncryptedInfo()` which calls `getToken(43200)` to create a token with a 12-hour expiration window. The token is encrypted and contains security-critical claims: `isAdmin`, `from_users_id`, `user_name`, IP, browser, and device ID.&lt;/p&gt;
&lt;p&gt;The regular HTTP token verification at `objects/functions.php:3437-3439` enforces the timeout:&lt;/p&gt;
&lt;p&gt;```php
// objects/functions.php:3437-3439
if (!($time &amp;gt;= $obj-&amp;gt;time &amp;amp;&amp;amp; $time &amp;lt;= $obj-&amp;gt;timeout)) {
    _error_log(&amp;#34;verifyToken token timout...&amp;#34;);
    return false;  // &amp;lt;-- enforced
}
```&lt;/p&gt;
&lt;p&gt;But the WebSocket-specific verification at `plugin/YPTSocket/functions.php:65-82` has the enforcement commented out:&lt;/p&gt;
&lt;p&gt;```php
// plugin/YPTSocket/functions.php:77-80
if (!($time &amp;gt;= $obj-&amp;gt;time &amp;amp;&amp;amp; $time &amp;lt;= $obj-&amp;gt;timeout)) {
    //_error_log(&amp;#34;verifyToken token timout...&amp;#34;);
    //return false;  // &amp;lt;-- NOT enforced, always falls through to return true
}
return true;
```&lt;/p&gt;
&lt;p&gt;**Execution flow:**&lt;/p&gt;
&lt;p&gt;1. Client connects to WebSock…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wwbn/avideo&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `verifyTokenSocket()` function in `plugin/YPTSocket/functions.php` has its token timeout validation commented out, causing WebSocket tokens to never expire despite being generated with a 12-hour timeout. This allows captured or legitimately obtained tokens to provide permanent WebSocket access, even after user accounts are deleted, banned, or demoted from admin. Admin tokens grant access to real-time connection data for all online users including IP addresses, browser info, and page locations.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;WebSocket tokens are generated via `getEncryptedInfo()` which calls `getToken(43200)` to create a token with a 12-hour expiration window. The token is encrypted and contains security-critical claims: `isAdmin`, `from_users_id`, `user_name`, IP, browser, and device ID.&lt;/p&gt;
&lt;p&gt;The regular HTTP token verification at `objects/functions.php:3437-3439` enforces the timeout:&lt;/p&gt;
&lt;p&gt;```php
// objects/functions.php:3437-3439
if (!($time &amp;gt;= $obj-&amp;gt;time &amp;amp;&amp;amp; $time &amp;lt;= $obj-&amp;gt;timeout)) {
    _error_log(&amp;#34;verifyToken token timout...&amp;#34;);
    return false;  // &amp;lt;-- enforced
}
```&lt;/p&gt;
&lt;p&gt;But the WebSocket-specific verification at `plugin/YPTSocket/functions.php:65-82` has the enforcement commented out:&lt;/p&gt;
&lt;p&gt;```php
// plugin/YPTSocket/functions.php:77-80
if (!($time &amp;gt;= $obj-&amp;gt;time &amp;amp;&amp;amp; $time &amp;lt;= $obj-&amp;gt;timeout)) {
    //_error_log(&amp;#34;verifyToken token timout...&amp;#34;);
    //return false;  // &amp;lt;-- NOT enforced, always falls through to return true
}
return true;
```&lt;/p&gt;
&lt;p&gt;**Execution flow:**&lt;/p&gt;
&lt;p&gt;1. Client connects to WebSock…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2mg4-pfgx-64cf</guid>
    </item>
  </channel>
</rss>
