<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 00:46:12 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-318030</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-318030</link>
      <description>EUVD-2026-318030</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-318030</guid>
    </item>
    <item>
      <title>fkie_cve-2026-43882</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43882</link>
      <description>&lt;p&gt;WWBN AVideo is an open source video platform. In versions up to and including 29.0, the unauthenticated plugin/Scheduler/downloadICS.php endpoint passes attacker-controlled title, description, and joinURL parameters into Scheduler::downloadICS(), which builds an ICS calendar file via the ICS helper class. ICS::escape_string() (objects/ICS.php:167-169) only escapes , and ; and does NOT neutralize CR/LF, so attacker CRLF bytes inside a property value break out and inject arbitrary ICS lines — including END:VEVENT / BEGIN:VEVENT pairs that add entire attacker-controlled calendar events. Because the malicious .ics file is served from the victim&amp;#39;s trusted AVideo origin, this enables high-credibility calendar phishing: forged meetings with attacker-chosen SUMMARY, URL, LOCATION, and DESCRIPTION landing in the victim&amp;#39;s calendar after import. Commit 764db592f99e545aa86bb9a4ad664ffd14c38ba5 contains an updated fix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WWBN AVideo is an open source video platform. In versions up to and including 29.0, the unauthenticated plugin/Scheduler/downloadICS.php endpoint passes attacker-controlled title, description, and joinURL parameters into Scheduler::downloadICS(), which builds an ICS calendar file via the ICS helper class. ICS::escape_string() (objects/ICS.php:167-169) only escapes , and ; and does NOT neutralize CR/LF, so attacker CRLF bytes inside a property value break out and inject arbitrary ICS lines — including END:VEVENT / BEGIN:VEVENT pairs that add entire attacker-controlled calendar events. Because the malicious .ics file is served from the victim&amp;#39;s trusted AVideo origin, this enables high-credibility calendar phishing: forged meetings with attacker-chosen SUMMARY, URL, LOCATION, and DESCRIPTION landing in the victim&amp;#39;s calendar after import. Commit 764db592f99e545aa86bb9a4ad664ffd14c38ba5 contains an updated fix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-43882</guid>
    </item>
    <item>
      <title>GHSA-mwgh-92m2-wvhv — AVideo: Unauthenticated CRLF/ICS Injection in Scheduler downloadICS.php Allows Calendar Event Spoofing</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mwgh-92m2-wvhv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wwbn/avideo&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The unauthenticated `plugin/Scheduler/downloadICS.php` endpoint passes attacker-controlled `title`, `description`, and `joinURL` parameters into `Scheduler::downloadICS()`, which builds an ICS calendar file via the `ICS` helper class. `ICS::escape_string()` (`objects/ICS.php:167-169`) only escapes `,` and `;` and does NOT neutralize CR/LF, so attacker CRLF bytes inside a property value break out and inject arbitrary ICS lines — including `END:VEVENT` / `BEGIN:VEVENT` pairs that add entire attacker-controlled calendar events. Because the malicious `.ics` file is served from the victim&amp;#39;s trusted AVideo origin, this enables high-credibility calendar phishing: forged meetings with attacker-chosen `SUMMARY`, `URL`, `LOCATION`, and `DESCRIPTION` landing in the victim&amp;#39;s calendar after import.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Vulnerable code path&lt;/p&gt;
&lt;p&gt;**`plugin/Scheduler/downloadICS.php`** — unauthenticated entry point:&lt;/p&gt;
&lt;p&gt;```php
if(!AVideoPlugin::isEnabledByName(&amp;#39;Scheduler&amp;#39;)){
    forbiddenPage(&amp;#39;Scheduler is disabled&amp;#39;);
}
if(empty($_REQUEST[&amp;#39;title&amp;#39;])){ forbiddenPage(&amp;#39;Title cannot be empty&amp;#39;); }
if(empty($_REQUEST[&amp;#39;date_start&amp;#39;])){ forbiddenPage(&amp;#39;date_start cannot be empty&amp;#39;); }&lt;/p&gt;
&lt;p&gt;Scheduler::downloadICS($_REQUEST[&amp;#39;title&amp;#39;], $_REQUEST[&amp;#39;date_start&amp;#39;], @$_REQUEST[&amp;#39;date_end&amp;#39;],
    @$_REQUEST[&amp;#39;reminder&amp;#39;], @$_REQUEST[&amp;#39;joinURL&amp;#39;], @$_REQUEST[&amp;#39;description&amp;#39;]);
```&lt;/p&gt;
&lt;p&gt;There is no session check, no CSRF token, no user-role check — only an empty-check on `title`/`date_start` and a plugin-enabled check.&lt;/p&gt;
&lt;p&gt;**`plugin…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wwbn/avideo&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The unauthenticated `plugin/Scheduler/downloadICS.php` endpoint passes attacker-controlled `title`, `description`, and `joinURL` parameters into `Scheduler::downloadICS()`, which builds an ICS calendar file via the `ICS` helper class. `ICS::escape_string()` (`objects/ICS.php:167-169`) only escapes `,` and `;` and does NOT neutralize CR/LF, so attacker CRLF bytes inside a property value break out and inject arbitrary ICS lines — including `END:VEVENT` / `BEGIN:VEVENT` pairs that add entire attacker-controlled calendar events. Because the malicious `.ics` file is served from the victim&amp;#39;s trusted AVideo origin, this enables high-credibility calendar phishing: forged meetings with attacker-chosen `SUMMARY`, `URL`, `LOCATION`, and `DESCRIPTION` landing in the victim&amp;#39;s calendar after import.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Vulnerable code path&lt;/p&gt;
&lt;p&gt;**`plugin/Scheduler/downloadICS.php`** — unauthenticated entry point:&lt;/p&gt;
&lt;p&gt;```php
if(!AVideoPlugin::isEnabledByName(&amp;#39;Scheduler&amp;#39;)){
    forbiddenPage(&amp;#39;Scheduler is disabled&amp;#39;);
}
if(empty($_REQUEST[&amp;#39;title&amp;#39;])){ forbiddenPage(&amp;#39;Title cannot be empty&amp;#39;); }
if(empty($_REQUEST[&amp;#39;date_start&amp;#39;])){ forbiddenPage(&amp;#39;date_start cannot be empty&amp;#39;); }&lt;/p&gt;
&lt;p&gt;Scheduler::downloadICS($_REQUEST[&amp;#39;title&amp;#39;], $_REQUEST[&amp;#39;date_start&amp;#39;], @$_REQUEST[&amp;#39;date_end&amp;#39;],
    @$_REQUEST[&amp;#39;reminder&amp;#39;], @$_REQUEST[&amp;#39;joinURL&amp;#39;], @$_REQUEST[&amp;#39;description&amp;#39;]);
```&lt;/p&gt;
&lt;p&gt;There is no session check, no CSRF token, no user-role check — only an empty-check on `title`/`date_start` and a plugin-enabled check.&lt;/p&gt;
&lt;p&gt;**`plugin…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mwgh-92m2-wvhv</guid>
    </item>
  </channel>
</rss>
