<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 20:36:48 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-317250</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-317250</link>
      <description>EUVD-2026-317250</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-317250</guid>
    </item>
    <item>
      <title>fkie_cve-2026-43873</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43873</link>
      <description>&lt;p&gt;WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/CloneSite/cloneClient.json.php echoes the local CloneSite shared secret ($objClone-&amp;gt;myKey, a constant md5($global[&amp;#39;systemRootPath&amp;#39;] . $global[&amp;#39;salt&amp;#39;])) into the HTTP response body on every unauthenticated request. The unauthenticated error branch was intended to reject non-admin callers without a valid key, but the rejection message interpolates the expected key before die(). When the victim has CloneSite configured with a remote cloneSiteURL (standard federation/backup setup), the leaked myKey is exactly the credential that authenticates the victim to that remote server&amp;#39;s cloneServer.json.php, allowing the attacker to impersonate the victim and trigger a full mysqldump of the remote&amp;#39;s database to the remote&amp;#39;s public videos/clones/ directory Commit e6566f56a28f4556b2a0a09d03717a719dcb49da contains an updated fix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/CloneSite/cloneClient.json.php echoes the local CloneSite shared secret ($objClone-&amp;gt;myKey, a constant md5($global[&amp;#39;systemRootPath&amp;#39;] . $global[&amp;#39;salt&amp;#39;])) into the HTTP response body on every unauthenticated request. The unauthenticated error branch was intended to reject non-admin callers without a valid key, but the rejection message interpolates the expected key before die(). When the victim has CloneSite configured with a remote cloneSiteURL (standard federation/backup setup), the leaked myKey is exactly the credential that authenticates the victim to that remote server&amp;#39;s cloneServer.json.php, allowing the attacker to impersonate the victim and trigger a full mysqldump of the remote&amp;#39;s database to the remote&amp;#39;s public videos/clones/ directory Commit e6566f56a28f4556b2a0a09d03717a719dcb49da contains an updated fix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-43873</guid>
    </item>
    <item>
      <title>GHSA-qm9p-p5pw-jrx2 — AVideo: Unauthenticated Disclosure of CloneSite `myKey` via Error Echo in `cloneClient.json.php` Enables Cross-Site DB…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qm9p-p5pw-jrx2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wwbn/avideo&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`plugin/CloneSite/cloneClient.json.php` echoes the local CloneSite shared secret (`$objClone-&amp;gt;myKey`, a constant `md5($global[&amp;#39;systemRootPath&amp;#39;] . $global[&amp;#39;salt&amp;#39;])`) into the HTTP response body on every unauthenticated request. The unauthenticated error branch was intended to reject non-admin callers without a valid key, but the rejection message interpolates the expected key before `die()`. When the victim has CloneSite configured with a remote `cloneSiteURL` (standard federation/backup setup), the leaked `myKey` is exactly the credential that authenticates the victim to that remote server&amp;#39;s `cloneServer.json.php`, allowing the attacker to impersonate the victim and trigger a full `mysqldump` of the remote&amp;#39;s database to the remote&amp;#39;s public `videos/clones/` directory.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### 1. The leak (`plugin/CloneSite/cloneClient.json.php:51-60`)&lt;/p&gt;
&lt;p&gt;```php
$objCloneOriginal = $objClone;
$argv[1] = preg_replace(&amp;#34;/[^A-Za-z0-9 ]/&amp;#34;, &amp;#39;&amp;#39;, empty($argv[1])?&amp;#39;&amp;#39;:$argv[1]);&lt;/p&gt;
&lt;p&gt;if (empty($objClone) || empty($argv[1]) || $objClone-&amp;gt;myKey !== $argv[1]) {
    if (!User::isAdmin()) {
        $resp-&amp;gt;msg = &amp;#34;You can&amp;#39;t do this&amp;#34;;
        $log-&amp;gt;add(&amp;#34;Clone: {$resp-&amp;gt;msg}&amp;#34;);
        echo &amp;#34;$objClone-&amp;gt;myKey !== $argv[1]&amp;#34;;   // &amp;lt;-- interpolates myKey
        die(json_encode($resp));
    }
}
```&lt;/p&gt;
&lt;p&gt;Under PHP&amp;#39;s web SAPI, the script-scope `$argv` global is not populated from the query string (only `$_SERVER[&amp;#39;argv&amp;#39;]` is populated, and only when `register_argc_argv=On`). Verified on this host (PHP 8.4.16,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wwbn/avideo&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`plugin/CloneSite/cloneClient.json.php` echoes the local CloneSite shared secret (`$objClone-&amp;gt;myKey`, a constant `md5($global[&amp;#39;systemRootPath&amp;#39;] . $global[&amp;#39;salt&amp;#39;])`) into the HTTP response body on every unauthenticated request. The unauthenticated error branch was intended to reject non-admin callers without a valid key, but the rejection message interpolates the expected key before `die()`. When the victim has CloneSite configured with a remote `cloneSiteURL` (standard federation/backup setup), the leaked `myKey` is exactly the credential that authenticates the victim to that remote server&amp;#39;s `cloneServer.json.php`, allowing the attacker to impersonate the victim and trigger a full `mysqldump` of the remote&amp;#39;s database to the remote&amp;#39;s public `videos/clones/` directory.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### 1. The leak (`plugin/CloneSite/cloneClient.json.php:51-60`)&lt;/p&gt;
&lt;p&gt;```php
$objCloneOriginal = $objClone;
$argv[1] = preg_replace(&amp;#34;/[^A-Za-z0-9 ]/&amp;#34;, &amp;#39;&amp;#39;, empty($argv[1])?&amp;#39;&amp;#39;:$argv[1]);&lt;/p&gt;
&lt;p&gt;if (empty($objClone) || empty($argv[1]) || $objClone-&amp;gt;myKey !== $argv[1]) {
    if (!User::isAdmin()) {
        $resp-&amp;gt;msg = &amp;#34;You can&amp;#39;t do this&amp;#34;;
        $log-&amp;gt;add(&amp;#34;Clone: {$resp-&amp;gt;msg}&amp;#34;);
        echo &amp;#34;$objClone-&amp;gt;myKey !== $argv[1]&amp;#34;;   // &amp;lt;-- interpolates myKey
        die(json_encode($resp));
    }
}
```&lt;/p&gt;
&lt;p&gt;Under PHP&amp;#39;s web SAPI, the script-scope `$argv` global is not populated from the query string (only `$_SERVER[&amp;#39;argv&amp;#39;]` is populated, and only when `register_argc_argv=On`). Verified on this host (PHP 8.4.16,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qm9p-p5pw-jrx2</guid>
    </item>
  </channel>
</rss>
