<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 07:14:15 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-317321</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-317321</link>
      <description>EUVD-2026-317321</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-317321</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42845</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42845</link>
      <description>&lt;p&gt;The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0 , there is an unauthenticated page-content overwrite via file upload (GHSA-w4rc-p66m-x6qq). Public form uploads now strip path components from the POST-supplied filename and hard-block page-content extensions (`md`, `yaml`, `yml`, `json`, `twig`, `ini`) regardless of the configurable dangerous-extensions list. A permissive `accept` policy combined with the default `destination: self@` could otherwise let an attacker overwrite the page&amp;#39;s own `.md` and pivot to super-admin via a `process: save` action. This vulnerability is fixed in 9.1.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0 , there is an unauthenticated page-content overwrite via file upload (GHSA-w4rc-p66m-x6qq). Public form uploads now strip path components from the POST-supplied filename and hard-block page-content extensions (`md`, `yaml`, `yml`, `json`, `twig`, `ini`) regardless of the configurable dangerous-extensions list. A permissive `accept` policy combined with the default `destination: self@` could otherwise let an attacker overwrite the page&amp;#39;s own `.md` and pivot to super-admin via a `process: save` action. This vulnerability is fixed in 9.1.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42845</guid>
    </item>
    <item>
      <title>GHSA-w4rc-p66m-x6qq — Grav Form Plugin has an Anonymous Page Content Overwrite via Form File Upload filename Override</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w4rc-p66m-x6qq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: getgrav/grav-plugin-form&lt;/p&gt;
&lt;p&gt;### Summary
(Tested on Form 9.0.3 released on April, 28th)&lt;/p&gt;
&lt;p&gt;The Form plugin&amp;#39;s file upload handler at `user/plugins/form/classes/Form.php:583` accepts a POST-supplied `filename` parameter (`$filename = $post[&amp;#39;filename&amp;#39;] ?? $upload[&amp;#39;file&amp;#39;][&amp;#39;name&amp;#39;]`) that overrides the original uploaded filename. The override passes through `Utils::checkFilename()`, which blocks only a narrow extension list (`.php*`, `.htm*`, `.js`, `.exe`). Markdown (`.md`) is **not** blocked.&lt;/p&gt;
&lt;p&gt;A page&amp;#39;s directory under `user/pages/` contains its `.md` content file (e.g. `default.md`, `form.md`). When a form&amp;#39;s file upload field has `accept: [&amp;#39;*&amp;#39;]` (or any policy that admits text files), an unauthenticated visitor can:&lt;/p&gt;
&lt;p&gt;1. Upload **arbitrary content** with **`filename=form.md`** (or other page-content filenames),
2. Submit the form to trigger `Form::copyFiles()`, which **overwrites the page&amp;#39;s own `.md` file**.&lt;/p&gt;
&lt;p&gt;### Details
**Vulnerable code path**&lt;/p&gt;
&lt;p&gt;`user/plugins/form/classes/Form.php:580-606` (in `uploadFiles()`):
```php
$grav-&amp;gt;fireEvent(&amp;#39;onFormUploadSettings&amp;#39;, new Event([&amp;#39;settings&amp;#39; =&amp;gt; &amp;amp;$settings, &amp;#39;post&amp;#39; =&amp;gt; $post]));&lt;/p&gt;
&lt;p&gt;$upload = json_decode(json_encode($this-&amp;gt;normalizeFiles($_FILES[&amp;#39;data&amp;#39;], $settings-&amp;gt;name)), true);
$filename = $post[&amp;#39;filename&amp;#39;] ?? $upload[&amp;#39;file&amp;#39;][&amp;#39;name&amp;#39;];           // ← POST-controlled
// ...
if (!Utils::checkFilename($filename)) {                              // ← extension blocklist only
    return [&amp;#39;status&amp;#39; =&amp;gt; &amp;#39;error&amp;#39;, &amp;#39;message&amp;#39; =&amp;gt; &amp;#39;Bad filename&amp;#39;];
}
```&lt;/p&gt;
&lt;p&gt;`Utils::checkFilename()` (`system/src…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: getgrav/grav-plugin-form&lt;/p&gt;
&lt;p&gt;### Summary
(Tested on Form 9.0.3 released on April, 28th)&lt;/p&gt;
&lt;p&gt;The Form plugin&amp;#39;s file upload handler at `user/plugins/form/classes/Form.php:583` accepts a POST-supplied `filename` parameter (`$filename = $post[&amp;#39;filename&amp;#39;] ?? $upload[&amp;#39;file&amp;#39;][&amp;#39;name&amp;#39;]`) that overrides the original uploaded filename. The override passes through `Utils::checkFilename()`, which blocks only a narrow extension list (`.php*`, `.htm*`, `.js`, `.exe`). Markdown (`.md`) is **not** blocked.&lt;/p&gt;
&lt;p&gt;A page&amp;#39;s directory under `user/pages/` contains its `.md` content file (e.g. `default.md`, `form.md`). When a form&amp;#39;s file upload field has `accept: [&amp;#39;*&amp;#39;]` (or any policy that admits text files), an unauthenticated visitor can:&lt;/p&gt;
&lt;p&gt;1. Upload **arbitrary content** with **`filename=form.md`** (or other page-content filenames),
2. Submit the form to trigger `Form::copyFiles()`, which **overwrites the page&amp;#39;s own `.md` file**.&lt;/p&gt;
&lt;p&gt;### Details
**Vulnerable code path**&lt;/p&gt;
&lt;p&gt;`user/plugins/form/classes/Form.php:580-606` (in `uploadFiles()`):
```php
$grav-&amp;gt;fireEvent(&amp;#39;onFormUploadSettings&amp;#39;, new Event([&amp;#39;settings&amp;#39; =&amp;gt; &amp;amp;$settings, &amp;#39;post&amp;#39; =&amp;gt; $post]));&lt;/p&gt;
&lt;p&gt;$upload = json_decode(json_encode($this-&amp;gt;normalizeFiles($_FILES[&amp;#39;data&amp;#39;], $settings-&amp;gt;name)), true);
$filename = $post[&amp;#39;filename&amp;#39;] ?? $upload[&amp;#39;file&amp;#39;][&amp;#39;name&amp;#39;];           // ← POST-controlled
// ...
if (!Utils::checkFilename($filename)) {                              // ← extension blocklist only
    return [&amp;#39;status&amp;#39; =&amp;gt; &amp;#39;error&amp;#39;, &amp;#39;message&amp;#39; =&amp;gt; &amp;#39;Bad filename&amp;#39;];
}
```&lt;/p&gt;
&lt;p&gt;`Utils::checkFilename()` (`system/src…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w4rc-p66m-x6qq</guid>
    </item>
  </channel>
</rss>
