<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:43:32 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-319034</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-319034</link>
      <description>EUVD-2026-319034</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-319034</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42458</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42458</link>
      <description>&lt;p&gt;Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to 20.18.0, there is a reflected XSS vulnerability under admin panel -&amp;gt; System -&amp;gt; Import/Export -&amp;gt; Dataflow - Profiles. This vulnerability is fixed in 20.18.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to 20.18.0, there is a reflected XSS vulnerability under admin panel -&amp;gt; System -&amp;gt; Import/Export -&amp;gt; Dataflow - Profiles. This vulnerability is fixed in 20.18.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42458</guid>
    </item>
    <item>
      <title>GHSA-x8jv-q8j2-487c — Magento LTS: Reflected XSS - Import -&gt; Data Flow (profiles)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x8jv-q8j2-487c</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: openmage/magento-lts&lt;/p&gt;
&lt;p&gt;A reflected XSS vulnerability was found under admin panel -&amp;gt;  System -&amp;gt; Import/Export -&amp;gt; Dataflow -  Profiles.&lt;/p&gt;
&lt;p&gt;## Steps to produce&lt;/p&gt;
&lt;p&gt;+ Login to  the admin panel&lt;/p&gt;
&lt;p&gt;+ Go to the path   `System -&amp;gt; Import/Export -&amp;gt; Dataflow -  Profiles`&lt;/p&gt;
&lt;p&gt;+ Select profile direction as `Import`.&lt;/p&gt;
&lt;p&gt;+ Click on `Import Customers`&lt;/p&gt;
&lt;p&gt;+ Upload the file.&lt;/p&gt;
&lt;p&gt;File Link: [customer_20260212_204335.csv](https://github.com/user-attachments/files/25629638/customer_20260212_204335.csv)&lt;/p&gt;
&lt;p&gt;+ Go back to `Run profile`.&lt;/p&gt;
&lt;p&gt;+ Select the uploaded file and Click on `Run in Popup`.&lt;/p&gt;
&lt;p&gt;+ One can see a URL like this&lt;/p&gt;
&lt;p&gt;```
https://demo-admin.openmage.org/index.php/admin/system_convert_gui/run/id/6/key/40dbbb2e93f45f0463c57ff733352f4f/files/import-20260215151125-1_customer_20260212_204335.csv/
```&lt;/p&gt;
&lt;p&gt;+ One can see the filename getting reflection in HTML tags.&lt;/p&gt;
&lt;p&gt;+ Inject an HTML tag and observe.&lt;/p&gt;
&lt;p&gt;```
https://demo-admin.openmage.org/index.php/admin/system_convert_gui/run/id/6/key/40dbbb2e93f45f0463c57ff733352f4f/files/&amp;#34;&amp;gt;&amp;lt;h3&amp;gt;hacked&amp;lt;/h3&amp;gt;/
```&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1796&amp;#34; height=&amp;#34;302&amp;#34; alt=&amp;#34;image (3)&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/502330b0-fa73-4b90-a81f-6216a98e474a&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;+ One can see the tag is getting executed.&lt;/p&gt;
&lt;p&gt;+  Proceed for XSS.&lt;/p&gt;
&lt;p&gt;```
https://demo-admin.openmage.org/index.php/admin/system_convert_gui/run/id/6/key/40dbbb2e93f45f0463c57ff733352f4f/files/%3CScRiPt%20%3Eprompt(document.cookie)%3C%2FScRiPt%3E
```&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1670&amp;#34; height=&amp;#34;562&amp;#34; alt=&amp;#34;image (4)&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/98a75081-fa8c-4483-9078-0…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: openmage/magento-lts&lt;/p&gt;
&lt;p&gt;A reflected XSS vulnerability was found under admin panel -&amp;gt;  System -&amp;gt; Import/Export -&amp;gt; Dataflow -  Profiles.&lt;/p&gt;
&lt;p&gt;## Steps to produce&lt;/p&gt;
&lt;p&gt;+ Login to  the admin panel&lt;/p&gt;
&lt;p&gt;+ Go to the path   `System -&amp;gt; Import/Export -&amp;gt; Dataflow -  Profiles`&lt;/p&gt;
&lt;p&gt;+ Select profile direction as `Import`.&lt;/p&gt;
&lt;p&gt;+ Click on `Import Customers`&lt;/p&gt;
&lt;p&gt;+ Upload the file.&lt;/p&gt;
&lt;p&gt;File Link: [customer_20260212_204335.csv](https://github.com/user-attachments/files/25629638/customer_20260212_204335.csv)&lt;/p&gt;
&lt;p&gt;+ Go back to `Run profile`.&lt;/p&gt;
&lt;p&gt;+ Select the uploaded file and Click on `Run in Popup`.&lt;/p&gt;
&lt;p&gt;+ One can see a URL like this&lt;/p&gt;
&lt;p&gt;```
https://demo-admin.openmage.org/index.php/admin/system_convert_gui/run/id/6/key/40dbbb2e93f45f0463c57ff733352f4f/files/import-20260215151125-1_customer_20260212_204335.csv/
```&lt;/p&gt;
&lt;p&gt;+ One can see the filename getting reflection in HTML tags.&lt;/p&gt;
&lt;p&gt;+ Inject an HTML tag and observe.&lt;/p&gt;
&lt;p&gt;```
https://demo-admin.openmage.org/index.php/admin/system_convert_gui/run/id/6/key/40dbbb2e93f45f0463c57ff733352f4f/files/&amp;#34;&amp;gt;&amp;lt;h3&amp;gt;hacked&amp;lt;/h3&amp;gt;/
```&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1796&amp;#34; height=&amp;#34;302&amp;#34; alt=&amp;#34;image (3)&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/502330b0-fa73-4b90-a81f-6216a98e474a&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;+ One can see the tag is getting executed.&lt;/p&gt;
&lt;p&gt;+  Proceed for XSS.&lt;/p&gt;
&lt;p&gt;```
https://demo-admin.openmage.org/index.php/admin/system_convert_gui/run/id/6/key/40dbbb2e93f45f0463c57ff733352f4f/files/%3CScRiPt%20%3Eprompt(document.cookie)%3C%2FScRiPt%3E
```&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1670&amp;#34; height=&amp;#34;562&amp;#34; alt=&amp;#34;image (4)&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/98a75081-fa8c-4483-9078-0…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x8jv-q8j2-487c</guid>
    </item>
  </channel>
</rss>
