diff --git a/advisories/unreviewed/2025/03/GHSA-9rjp-j2f3-hgr2/GHSA-9rjp-j2f3-hgr2.json b/advisories/unreviewed/2025/03/GHSA-9rjp-j2f3-hgr2/GHSA-9rjp-j2f3-hgr2.json new file mode 100644 index 00000000000..6b86bebb20b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9rjp-j2f3-hgr2/GHSA-9rjp-j2f3-hgr2.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rjp-j2f3-hgr2", + "modified": "2025-03-24T03:30:25Z", + "published": "2025-03-24T03:30:25Z", + "aliases": [ + "CVE-2025-2677" + ], + "details": "A vulnerability has been found in PHPGurukul Bank Locker Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /changeidproof.php. The manipulation of the argument editid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2677" + }, + { + "type": "WEB", + "url": "https://github.com/ARPANET-cyber/CVE/issues/6" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300694" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300694" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.521444" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T02:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g442-92pc-f29g/GHSA-g442-92pc-f29g.json b/advisories/unreviewed/2025/03/GHSA-g442-92pc-f29g/GHSA-g442-92pc-f29g.json new file mode 100644 index 00000000000..b4c73c2f353 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g442-92pc-f29g/GHSA-g442-92pc-f29g.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g442-92pc-f29g", + "modified": "2025-03-24T03:30:25Z", + "published": "2025-03-24T03:30:25Z", + "aliases": [ + "CVE-2025-2679" + ], + "details": "A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /contact-us.php. The manipulation of the argument pagetitle leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2679" + }, + { + "type": "WEB", + "url": "https://github.com/ARPANET-cyber/CVE/issues/8" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300696" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300696" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.521447" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T03:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r5jj-c2fp-rwxc/GHSA-r5jj-c2fp-rwxc.json b/advisories/unreviewed/2025/03/GHSA-r5jj-c2fp-rwxc/GHSA-r5jj-c2fp-rwxc.json new file mode 100644 index 00000000000..878b37a11ae --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r5jj-c2fp-rwxc/GHSA-r5jj-c2fp-rwxc.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5jj-c2fp-rwxc", + "modified": "2025-03-24T03:30:25Z", + "published": "2025-03-24T03:30:25Z", + "aliases": [ + "CVE-2025-2676" + ], + "details": "A vulnerability, which was classified as critical, was found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file /add-subadmin.php. The manipulation of the argument sadminusername leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2676" + }, + { + "type": "WEB", + "url": "https://github.com/ARPANET-cyber/CVE/issues/5" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300693" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300693" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.521443" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T01:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w992-x2xp-7wxj/GHSA-w992-x2xp-7wxj.json b/advisories/unreviewed/2025/03/GHSA-w992-x2xp-7wxj/GHSA-w992-x2xp-7wxj.json new file mode 100644 index 00000000000..3be69e932b9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w992-x2xp-7wxj/GHSA-w992-x2xp-7wxj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w992-x2xp-7wxj", + "modified": "2025-03-24T03:30:25Z", + "published": "2025-03-24T03:30:25Z", + "aliases": [ + "CVE-2025-2678" + ], + "details": "A vulnerability was found in PHPGurukul Bank Locker Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /changeimage1.php. The manipulation of the argument editid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2678" + }, + { + "type": "WEB", + "url": "https://github.com/ARPANET-cyber/CVE/issues/7" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300695" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300695" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.521445" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T03:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x4cg-7qf4-6q2m/GHSA-x4cg-7qf4-6q2m.json b/advisories/unreviewed/2025/03/GHSA-x4cg-7qf4-6q2m/GHSA-x4cg-7qf4-6q2m.json new file mode 100644 index 00000000000..89a2f9916bd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x4cg-7qf4-6q2m/GHSA-x4cg-7qf4-6q2m.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4cg-7qf4-6q2m", + "modified": "2025-03-24T03:30:25Z", + "published": "2025-03-24T03:30:25Z", + "aliases": [ + "CVE-2025-2675" + ], + "details": "A vulnerability, which was classified as critical, has been found in PHPGurukul Bank Locker Management System 1.0. Affected by this issue is some unknown functionality of the file /add-lockertype.php. The manipulation of the argument lockerprice leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2675" + }, + { + "type": "WEB", + "url": "https://github.com/ARPANET-cyber/CVE/issues/4" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300692" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300692" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.521442" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T01:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xf28-r428-32c6/GHSA-xf28-r428-32c6.json b/advisories/unreviewed/2025/03/GHSA-xf28-r428-32c6/GHSA-xf28-r428-32c6.json new file mode 100644 index 00000000000..0a4a098c2a2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xf28-r428-32c6/GHSA-xf28-r428-32c6.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xf28-r428-32c6", + "modified": "2025-03-24T03:30:26Z", + "published": "2025-03-24T03:30:26Z", + "aliases": [ + "CVE-2025-2680" + ], + "details": "A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /edit-assign-locker.php?ltid=1. The manipulation of the argument mobilenumber leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2680" + }, + { + "type": "WEB", + "url": "https://github.com/ARPANET-cyber/CVE/issues/9" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300697" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300697" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.521448" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T03:15:15Z" + } +} \ No newline at end of file