From 0f298ebfde33e44d48980c7e05c5f69e185adb60 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 17 May 2025 12:32:18 +0000 Subject: [PATCH] Publish Advisories GHSA-5mv8-rhrv-42gh GHSA-hg47-49fq-q324 GHSA-2qg7-wwhv-wp5v GHSA-3264-h8mv-qcrp GHSA-4cmr-35q3-c969 GHSA-4fg5-cfp9-9q4x GHSA-8hrx-2qh8-5m5m GHSA-p3qh-35p5-286g GHSA-q55j-hjhh-8278 GHSA-qgqc-rq6c-2qmp GHSA-vp4m-3qw3-rfpq --- .../GHSA-5mv8-rhrv-42gh.json | 15 ++++- .../GHSA-hg47-49fq-q324.json | 15 ++++- .../GHSA-2qg7-wwhv-wp5v.json | 56 +++++++++++++++++++ .../GHSA-3264-h8mv-qcrp.json | 56 +++++++++++++++++++ .../GHSA-4cmr-35q3-c969.json | 56 +++++++++++++++++++ .../GHSA-4fg5-cfp9-9q4x.json | 40 +++++++++++++ .../GHSA-8hrx-2qh8-5m5m.json | 52 +++++++++++++++++ .../GHSA-p3qh-35p5-286g.json | 56 +++++++++++++++++++ .../GHSA-q55j-hjhh-8278.json | 44 +++++++++++++++ .../GHSA-qgqc-rq6c-2qmp.json | 48 ++++++++++++++++ .../GHSA-vp4m-3qw3-rfpq.json | 56 +++++++++++++++++++ 11 files changed, 492 insertions(+), 2 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-2qg7-wwhv-wp5v/GHSA-2qg7-wwhv-wp5v.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3264-h8mv-qcrp/GHSA-3264-h8mv-qcrp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-4cmr-35q3-c969/GHSA-4cmr-35q3-c969.json create mode 100644 advisories/unreviewed/2025/05/GHSA-4fg5-cfp9-9q4x/GHSA-4fg5-cfp9-9q4x.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8hrx-2qh8-5m5m/GHSA-8hrx-2qh8-5m5m.json create mode 100644 advisories/unreviewed/2025/05/GHSA-p3qh-35p5-286g/GHSA-p3qh-35p5-286g.json create mode 100644 advisories/unreviewed/2025/05/GHSA-q55j-hjhh-8278/GHSA-q55j-hjhh-8278.json create mode 100644 advisories/unreviewed/2025/05/GHSA-qgqc-rq6c-2qmp/GHSA-qgqc-rq6c-2qmp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vp4m-3qw3-rfpq/GHSA-vp4m-3qw3-rfpq.json diff --git a/advisories/unreviewed/2023/02/GHSA-5mv8-rhrv-42gh/GHSA-5mv8-rhrv-42gh.json b/advisories/unreviewed/2023/02/GHSA-5mv8-rhrv-42gh/GHSA-5mv8-rhrv-42gh.json index 76c0a574887..a58ac470002 100644 --- a/advisories/unreviewed/2023/02/GHSA-5mv8-rhrv-42gh/GHSA-5mv8-rhrv-42gh.json +++ b/advisories/unreviewed/2023/02/GHSA-5mv8-rhrv-42gh/GHSA-5mv8-rhrv-42gh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5mv8-rhrv-42gh", - "modified": "2023-03-01T00:30:36Z", + "modified": "2025-05-17T12:31:07Z", "published": "2023-02-27T12:30:24Z", "aliases": [ "CVE-2023-1061" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], @@ -30,10 +34,19 @@ { "type": "WEB", "url": "https://vuldb.com/?id.221825" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.95223" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" } ], "database_specific": { "cwe_ids": [ + "CWE-74", "CWE-89" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/02/GHSA-hg47-49fq-q324/GHSA-hg47-49fq-q324.json b/advisories/unreviewed/2023/02/GHSA-hg47-49fq-q324/GHSA-hg47-49fq-q324.json index c96ce50e278..2b7070772fc 100644 --- a/advisories/unreviewed/2023/02/GHSA-hg47-49fq-q324/GHSA-hg47-49fq-q324.json +++ b/advisories/unreviewed/2023/02/GHSA-hg47-49fq-q324/GHSA-hg47-49fq-q324.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hg47-49fq-q324", - "modified": "2023-03-01T00:30:36Z", + "modified": "2025-05-17T12:31:07Z", "published": "2023-02-27T12:30:24Z", "aliases": [ "CVE-2023-1059" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], @@ -30,10 +34,19 @@ { "type": "WEB", "url": "https://vuldb.com/?id.221824" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.95222" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" } ], "database_specific": { "cwe_ids": [ + "CWE-74", "CWE-89" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/05/GHSA-2qg7-wwhv-wp5v/GHSA-2qg7-wwhv-wp5v.json b/advisories/unreviewed/2025/05/GHSA-2qg7-wwhv-wp5v/GHSA-2qg7-wwhv-wp5v.json new file mode 100644 index 00000000000..b6806c99db7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2qg7-wwhv-wp5v/GHSA-2qg7-wwhv-wp5v.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qg7-wwhv-wp5v", + "modified": "2025-05-17T12:31:08Z", + "published": "2025-05-17T12:31:08Z", + "aliases": [ + "CVE-2025-4826" + ], + "details": "A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This issue affects some unknown processing of the file /boafrm/formWirelessTbl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4826" + }, + { + "type": "WEB", + "url": "https://github.com/CH13hh/tmp_store_cc/blob/main/toto/5.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309287" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309287" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.574597" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T11:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3264-h8mv-qcrp/GHSA-3264-h8mv-qcrp.json b/advisories/unreviewed/2025/05/GHSA-3264-h8mv-qcrp/GHSA-3264-h8mv-qcrp.json new file mode 100644 index 00000000000..0992e8198e9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3264-h8mv-qcrp/GHSA-3264-h8mv-qcrp.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3264-h8mv-qcrp", + "modified": "2025-05-17T12:31:08Z", + "published": "2025-05-17T12:31:08Z", + "aliases": [ + "CVE-2025-4824" + ], + "details": "A vulnerability classified as critical has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This affects an unknown part of the file /boafrm/formWsc of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4824" + }, + { + "type": "WEB", + "url": "https://github.com/CH13hh/tmp_store_cc/blob/main/toto/2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309285" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309285" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.574594" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4cmr-35q3-c969/GHSA-4cmr-35q3-c969.json b/advisories/unreviewed/2025/05/GHSA-4cmr-35q3-c969/GHSA-4cmr-35q3-c969.json new file mode 100644 index 00000000000..68a9d167b1a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4cmr-35q3-c969/GHSA-4cmr-35q3-c969.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cmr-35q3-c969", + "modified": "2025-05-17T12:31:08Z", + "published": "2025-05-17T12:31:08Z", + "aliases": [ + "CVE-2025-4825" + ], + "details": "A vulnerability classified as critical was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This vulnerability affects unknown code of the file /boafrm/formDMZ of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4825" + }, + { + "type": "WEB", + "url": "https://github.com/CH13hh/tmp_store_cc/blob/main/toto/4.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309286" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309286" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.574596" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4fg5-cfp9-9q4x/GHSA-4fg5-cfp9-9q4x.json b/advisories/unreviewed/2025/05/GHSA-4fg5-cfp9-9q4x/GHSA-4fg5-cfp9-9q4x.json new file mode 100644 index 00000000000..616f0b6a87f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4fg5-cfp9-9q4x/GHSA-4fg5-cfp9-9q4x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fg5-cfp9-9q4x", + "modified": "2025-05-17T12:31:08Z", + "published": "2025-05-17T12:31:08Z", + "aliases": [ + "CVE-2025-3527" + ], + "details": "The EventON Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'assets/lib/settings/settings.js' file in all versions up to, and including, 4.9.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 4.9.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3527" + }, + { + "type": "WEB", + "url": "https://codecanyon.net/item/eventon-wordpress-event-calendar-plugin/1211017#item-description__change-log" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/549ca9cf-0183-4c19-9bd5-b6d55a69df31?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8hrx-2qh8-5m5m/GHSA-8hrx-2qh8-5m5m.json b/advisories/unreviewed/2025/05/GHSA-8hrx-2qh8-5m5m/GHSA-8hrx-2qh8-5m5m.json new file mode 100644 index 00000000000..939d65c5f6c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8hrx-2qh8-5m5m/GHSA-8hrx-2qh8-5m5m.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hrx-2qh8-5m5m", + "modified": "2025-05-17T12:31:07Z", + "published": "2025-05-17T12:31:07Z", + "aliases": [ + "CVE-2025-4610" + ], + "details": "The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_user_memberships shortcode in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4610" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-members/tags/3.5.2/includes/class-wp-members-products.php#L115" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-members/tags/3.5.2/includes/class-wp-members-products.php#L660" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?old_path=%2Fwp-members&old=3240295&new_path=%2Fwp-members&new=3293207&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wp-members/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3ff96d74-8f20-49a6-bd02-0bfe3498b599?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T10:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p3qh-35p5-286g/GHSA-p3qh-35p5-286g.json b/advisories/unreviewed/2025/05/GHSA-p3qh-35p5-286g/GHSA-p3qh-35p5-286g.json new file mode 100644 index 00000000000..af2ce4b3703 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p3qh-35p5-286g/GHSA-p3qh-35p5-286g.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3qh-35p5-286g", + "modified": "2025-05-17T12:31:08Z", + "published": "2025-05-17T12:31:08Z", + "aliases": [ + "CVE-2025-4669" + ], + "details": "The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpbc shortcode in all versions up to, and including, 10.11.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4669" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/booking/trunk/core/lib/wpdev-booking-class.php#L248" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/booking/trunk/core/lib/wpdev-booking-class.php#L445" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/booking/trunk/core/lib/wpdev-booking-class.php#L789" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3293836" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/booking/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f4e43d66-04f4-4adb-93da-75e02d1c714e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T12:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q55j-hjhh-8278/GHSA-q55j-hjhh-8278.json b/advisories/unreviewed/2025/05/GHSA-q55j-hjhh-8278/GHSA-q55j-hjhh-8278.json new file mode 100644 index 00000000000..ae5801600e5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q55j-hjhh-8278/GHSA-q55j-hjhh-8278.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q55j-hjhh-8278", + "modified": "2025-05-17T12:31:08Z", + "published": "2025-05-17T12:31:08Z", + "aliases": [ + "CVE-2025-3888" + ], + "details": "The Jupiter X Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File inclusion in all versions up to, and including, 4.8.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the page with the included SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3888" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/jupiterx-core/trunk/includes/extensions/raven/includes/modules/inline-svg/widgets/inline-svg.php#L304" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3292376" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f36f1ea5-62f7-48f0-a8d3-a56e0c9915d7?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qgqc-rq6c-2qmp/GHSA-qgqc-rq6c-2qmp.json b/advisories/unreviewed/2025/05/GHSA-qgqc-rq6c-2qmp/GHSA-qgqc-rq6c-2qmp.json new file mode 100644 index 00000000000..795a1421981 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qgqc-rq6c-2qmp/GHSA-qgqc-rq6c-2qmp.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgqc-rq6c-2qmp", + "modified": "2025-05-17T12:31:08Z", + "published": "2025-05-17T12:31:08Z", + "aliases": [ + "CVE-2024-13613" + ], + "details": "The Wise Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.3 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory which can contain file attachments included in chat messages. The vulnerability was partially patched in version 3.3.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13613" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wise-chat/trunk/src/services/WiseChatAttachmentsService.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3268074" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3288680" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f70dabb4-3ae6-43cf-86e2-62ac1454b697?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vp4m-3qw3-rfpq/GHSA-vp4m-3qw3-rfpq.json b/advisories/unreviewed/2025/05/GHSA-vp4m-3qw3-rfpq/GHSA-vp4m-3qw3-rfpq.json new file mode 100644 index 00000000000..a944d18aaaa --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vp4m-3qw3-rfpq/GHSA-vp4m-3qw3-rfpq.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp4m-3qw3-rfpq", + "modified": "2025-05-17T12:31:08Z", + "published": "2025-05-17T12:31:07Z", + "aliases": [ + "CVE-2025-4823" + ], + "details": "A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Affected by this issue is the function submit-url of the file /boafrm/formReflashClientTbl of the component HTTP POST Request Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4823" + }, + { + "type": "WEB", + "url": "https://github.com/CH13hh/tmp_store_cc/blob/main/toto/1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309284" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309284" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.574593" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-17T10:15:21Z" + } +} \ No newline at end of file