From 01168cec7b4f91591b68ef076f85ab8f9d49b2c2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sun, 18 May 2025 15:31:54 +0000 Subject: [PATCH] Publish Advisories GHSA-735j-4gjq-vc2q GHSA-7rcm-4jcj-r4q6 GHSA-g5c7-vx95-6r2v GHSA-phwm-q22c-gqgm GHSA-rc3j-9c9w-j5qc GHSA-v8g8-7xq6-7fpp GHSA-w5x3-j5vg-94wj --- .../GHSA-735j-4gjq-vc2q.json | 56 +++++++++++++++++++ .../GHSA-7rcm-4jcj-r4q6.json | 44 +++++++++++++++ .../GHSA-g5c7-vx95-6r2v.json | 56 +++++++++++++++++++ .../GHSA-phwm-q22c-gqgm.json | 56 +++++++++++++++++++ .../GHSA-rc3j-9c9w-j5qc.json | 56 +++++++++++++++++++ .../GHSA-v8g8-7xq6-7fpp.json | 56 +++++++++++++++++++ .../GHSA-w5x3-j5vg-94wj.json | 56 +++++++++++++++++++ 7 files changed, 380 insertions(+) create mode 100644 advisories/unreviewed/2025/05/GHSA-735j-4gjq-vc2q/GHSA-735j-4gjq-vc2q.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7rcm-4jcj-r4q6/GHSA-7rcm-4jcj-r4q6.json create mode 100644 advisories/unreviewed/2025/05/GHSA-g5c7-vx95-6r2v/GHSA-g5c7-vx95-6r2v.json create mode 100644 advisories/unreviewed/2025/05/GHSA-phwm-q22c-gqgm/GHSA-phwm-q22c-gqgm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rc3j-9c9w-j5qc/GHSA-rc3j-9c9w-j5qc.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v8g8-7xq6-7fpp/GHSA-v8g8-7xq6-7fpp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-w5x3-j5vg-94wj/GHSA-w5x3-j5vg-94wj.json diff --git a/advisories/unreviewed/2025/05/GHSA-735j-4gjq-vc2q/GHSA-735j-4gjq-vc2q.json b/advisories/unreviewed/2025/05/GHSA-735j-4gjq-vc2q/GHSA-735j-4gjq-vc2q.json new file mode 100644 index 00000000000..debbb6ee65f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-735j-4gjq-vc2q/GHSA-735j-4gjq-vc2q.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-735j-4gjq-vc2q", + "modified": "2025-05-18T15:30:20Z", + "published": "2025-05-18T15:30:20Z", + "aliases": [ + "CVE-2025-4882" + ], + "details": "A vulnerability was found in itsourcecode Restaurant Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/team_update.php. The manipulation of the argument team leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4882" + }, + { + "type": "WEB", + "url": "https://github.com/Cherish-Ink/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309435" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309435" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.576285" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-18T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7rcm-4jcj-r4q6/GHSA-7rcm-4jcj-r4q6.json b/advisories/unreviewed/2025/05/GHSA-7rcm-4jcj-r4q6/GHSA-7rcm-4jcj-r4q6.json new file mode 100644 index 00000000000..3f4f7090cef --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7rcm-4jcj-r4q6/GHSA-7rcm-4jcj-r4q6.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rcm-4jcj-r4q6", + "modified": "2025-05-18T15:30:20Z", + "published": "2025-05-18T15:30:20Z", + "aliases": [ + "CVE-2025-48219" + ], + "details": "O2 UK through 2025-05-17 allows subscribers to determine the Cell ID of other subscribers by initiating an IMS (IP Multimedia Subsystem) call and then reading the utran-cell-id-3gpp field of a Cellular-Network-Info SIP header, aka an ECI (E-UTRAN Cell Identity) leak. The Cell ID might be usable to identify a cell location via crowdsourced data, and might correspond to a small physical area (e.g., if the called party is in a city centre). Removal of the Cellular-Network-Info header is mentioned in section 4.4.19 of ETSI TS 124 229.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48219" + }, + { + "type": "WEB", + "url": "https://mastdatabase.co.uk/blog/2025/05/o2-expose-customer-location-call-4g" + }, + { + "type": "WEB", + "url": "https://news.ycombinator.com/item?id=44014046" + }, + { + "type": "WEB", + "url": "https://www.etsi.org/deliver/etsi_ts/124200_124299/124229/15.10.00_60/ts_124229v151000p.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-18T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g5c7-vx95-6r2v/GHSA-g5c7-vx95-6r2v.json b/advisories/unreviewed/2025/05/GHSA-g5c7-vx95-6r2v/GHSA-g5c7-vx95-6r2v.json new file mode 100644 index 00000000000..c6f118a78fb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g5c7-vx95-6r2v/GHSA-g5c7-vx95-6r2v.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5c7-vx95-6r2v", + "modified": "2025-05-18T15:30:20Z", + "published": "2025-05-18T15:30:20Z", + "aliases": [ + "CVE-2025-4884" + ], + "details": "A vulnerability was found in itsourcecode Restaurant Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/assign_save.php. The manipulation of the argument team leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4884" + }, + { + "type": "WEB", + "url": "https://github.com/arpcyber555/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309437" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309437" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.577363" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-18T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-phwm-q22c-gqgm/GHSA-phwm-q22c-gqgm.json b/advisories/unreviewed/2025/05/GHSA-phwm-q22c-gqgm/GHSA-phwm-q22c-gqgm.json new file mode 100644 index 00000000000..9c727dfa5da --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-phwm-q22c-gqgm/GHSA-phwm-q22c-gqgm.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phwm-q22c-gqgm", + "modified": "2025-05-18T15:30:20Z", + "published": "2025-05-18T15:30:20Z", + "aliases": [ + "CVE-2025-4881" + ], + "details": "A vulnerability was found in itsourcecode Restaurant Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/user_save.php. The manipulation of the argument username/name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4881" + }, + { + "type": "WEB", + "url": "https://github.com/Cherish-Ink/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309434" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309434" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.576284" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-18T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rc3j-9c9w-j5qc/GHSA-rc3j-9c9w-j5qc.json b/advisories/unreviewed/2025/05/GHSA-rc3j-9c9w-j5qc/GHSA-rc3j-9c9w-j5qc.json new file mode 100644 index 00000000000..64f2b4632e9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rc3j-9c9w-j5qc/GHSA-rc3j-9c9w-j5qc.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rc3j-9c9w-j5qc", + "modified": "2025-05-18T15:30:20Z", + "published": "2025-05-18T15:30:20Z", + "aliases": [ + "CVE-2025-4883" + ], + "details": "A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been declared as critical. This vulnerability affects the function ctxz_asp of the file /ctxz.asp of the component Connection Limit Page. The manipulation of the argument def/defTcp/defUdp/defIcmp/defOther leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4883" + }, + { + "type": "WEB", + "url": "https://github.com/Yhuanhuan01/DI-8100_Vulnerability_Report/blob/main/DI-8100-Vulnerability_Report_ctxz.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309436" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309436" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.576392" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-18T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v8g8-7xq6-7fpp/GHSA-v8g8-7xq6-7fpp.json b/advisories/unreviewed/2025/05/GHSA-v8g8-7xq6-7fpp/GHSA-v8g8-7xq6-7fpp.json new file mode 100644 index 00000000000..38f99d2cb0d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v8g8-7xq6-7fpp/GHSA-v8g8-7xq6-7fpp.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8g8-7xq6-7fpp", + "modified": "2025-05-18T15:30:20Z", + "published": "2025-05-18T15:30:20Z", + "aliases": [ + "CVE-2025-4875" + ], + "details": "A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4875" + }, + { + "type": "WEB", + "url": "https://github.com/arpcyber040/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309418" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309418" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.576265" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-18T13:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w5x3-j5vg-94wj/GHSA-w5x3-j5vg-94wj.json b/advisories/unreviewed/2025/05/GHSA-w5x3-j5vg-94wj/GHSA-w5x3-j5vg-94wj.json new file mode 100644 index 00000000000..609cfcf34f1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w5x3-j5vg-94wj/GHSA-w5x3-j5vg-94wj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5x3-j5vg-94wj", + "modified": "2025-05-18T15:30:20Z", + "published": "2025-05-18T15:30:20Z", + "aliases": [ + "CVE-2025-4880" + ], + "details": "A vulnerability has been found in PHPGurukul News Portal 4.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/aboutus.php. The manipulation of the argument pagetitle leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4880" + }, + { + "type": "WEB", + "url": "https://github.com/Schatten-42/MyCVE/issues/8" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309433" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309433" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.576264" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-18T13:15:32Z" + } +} \ No newline at end of file