<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 12:16:20 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-322754</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322754</link>
      <description>EUVD-2026-322754</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322754</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45610</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45610</link>
      <description>&lt;p&gt;WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/LoginControl/set.json.php accepts POST type=set2FA value=false, calls LoginControl::setUser2FA(User::getId(), false) on the session-authenticated user, and returns. There is no forbidIfIsUntrustedRequest() call, no isTokenValid() check, no X-CSRF-Token/SameSite enforcement, and no re-authentication step. A cross-origin page that the victim visits while logged into the AVideo dashboard issues the POST via a hidden form (or fetch without credentials:&amp;#34;omit&amp;#34;) and disables the victim&amp;#39;s 2FA in one request.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/LoginControl/set.json.php accepts POST type=set2FA value=false, calls LoginControl::setUser2FA(User::getId(), false) on the session-authenticated user, and returns. There is no forbidIfIsUntrustedRequest() call, no isTokenValid() check, no X-CSRF-Token/SameSite enforcement, and no re-authentication step. A cross-origin page that the victim visits while logged into the AVideo dashboard issues the POST via a hidden form (or fetch without credentials:&amp;#34;omit&amp;#34;) and disables the victim&amp;#39;s 2FA in one request.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45610</guid>
    </item>
    <item>
      <title>GHSA-3mv2-vmwh-rwfx — AVideo: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FA</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3mv2-vmwh-rwfx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: WWBN/AVideo&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;**Type:** Cross-site request forgery on the 2FA toggle. `plugin/LoginControl/set.json.php` accepts `POST type=set2FA value=false`, calls `LoginControl::setUser2FA(User::getId(), false)` on the session-authenticated user, and returns. There is no `forbidIfIsUntrustedRequest()` call, no `isTokenValid()` check, no `X-CSRF-Token`/`SameSite` enforcement, and no re-authentication step. A cross-origin page that the victim visits while logged into the AVideo dashboard issues the POST via a hidden form (or `fetch` without `credentials:&amp;#34;omit&amp;#34;`) and disables the victim&amp;#39;s 2FA in one request. The next phishing/credential-stuffing attempt against that account no longer needs the second factor.
**File:** `plugin/LoginControl/set.json.php`, lines 1-37.
**Root cause:** the developer relied on the `User::isLogged()` check at line 9 as the only auth, then dispatched directly into `LoginControl::setUser2FA(User::getId(), $value==&amp;#39;true&amp;#39;)`. Other AVideo state-changing endpoints in the same codebase (`videoUpdateUsage.json.php`, `videoStatus.json.php`, `videoRotate.json.php`, etc.) call `forbidIfIsUntrustedRequest(&amp;#39;&amp;lt;name&amp;gt;&amp;#39;)` to compare `Origin`/`Referer` against the AVideo domain; this endpoint simply omits the call. The session cookie carries the user&amp;#39;s identity on every cross-origin POST, so any attacker page can speak for the logged-in user on this endpoint.&lt;/p&gt;
&lt;p&gt;## Affected Code&lt;/p&gt;
&lt;p&gt;**File:** `plugin/LoginControl/set.json.php`, lines 1-37.&lt;/p&gt;
&lt;p&gt;```php
&amp;lt;?php
require_once &amp;#39;../../videos/configur…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: WWBN/AVideo&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;**Type:** Cross-site request forgery on the 2FA toggle. `plugin/LoginControl/set.json.php` accepts `POST type=set2FA value=false`, calls `LoginControl::setUser2FA(User::getId(), false)` on the session-authenticated user, and returns. There is no `forbidIfIsUntrustedRequest()` call, no `isTokenValid()` check, no `X-CSRF-Token`/`SameSite` enforcement, and no re-authentication step. A cross-origin page that the victim visits while logged into the AVideo dashboard issues the POST via a hidden form (or `fetch` without `credentials:&amp;#34;omit&amp;#34;`) and disables the victim&amp;#39;s 2FA in one request. The next phishing/credential-stuffing attempt against that account no longer needs the second factor.
**File:** `plugin/LoginControl/set.json.php`, lines 1-37.
**Root cause:** the developer relied on the `User::isLogged()` check at line 9 as the only auth, then dispatched directly into `LoginControl::setUser2FA(User::getId(), $value==&amp;#39;true&amp;#39;)`. Other AVideo state-changing endpoints in the same codebase (`videoUpdateUsage.json.php`, `videoStatus.json.php`, `videoRotate.json.php`, etc.) call `forbidIfIsUntrustedRequest(&amp;#39;&amp;lt;name&amp;gt;&amp;#39;)` to compare `Origin`/`Referer` against the AVideo domain; this endpoint simply omits the call. The session cookie carries the user&amp;#39;s identity on every cross-origin POST, so any attacker page can speak for the logged-in user on this endpoint.&lt;/p&gt;
&lt;p&gt;## Affected Code&lt;/p&gt;
&lt;p&gt;**File:** `plugin/LoginControl/set.json.php`, lines 1-37.&lt;/p&gt;
&lt;p&gt;```php
&amp;lt;?php
require_once &amp;#39;../../videos/configur…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3mv2-vmwh-rwfx</guid>
    </item>
  </channel>
</rss>
