<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 05:37:51 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-58303 — FoF Pretty Mail 1.1.2 Server Side Template Injection via Email Template Settings</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-58303</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Flarum FriendsofFlarum Pretty Mail&lt;/p&gt;
&lt;p&gt;FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject malicious code into email templates. Attackers can execute system commands by inserting crafted template expressions that trigger arbitrary code execution during email generation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Flarum FriendsofFlarum Pretty Mail&lt;/p&gt;
&lt;p&gt;FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject malicious code into email templates. Attackers can execute system commands by inserting crafted template expressions that trigger arbitrary code execution during email generation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-58303</guid>
    </item>
  </channel>
</rss>
