Publish Advisories

GHSA-c6qp-pc37-g43r
GHSA-p97c-7hc4-x66c
This commit is contained in:
advisory-database[bot]
2025-05-23 09:32:03 +00:00
parent e9cc559f61
commit 154f376306
2 changed files with 112 additions and 0 deletions
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c6qp-pc37-g43r",
"modified": "2025-05-23T09:30:26Z",
"published": "2025-05-23T09:30:26Z",
"aliases": [
"CVE-2025-47149"
],
"details": "The optional feature 'Anti-Virus & Sandbox' of i-FILTER contains an issue with improper pattern file validation. If exploited, the product may treat an unauthorized pattern file as an authorized. If the product uses a specially crafted pattern file, information in the server where the product is running may be retrieved, and/or cause a denial of service (DoS) condition.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47149"
},
{
"type": "WEB",
"url": "https://download.daj.co.jp/support/detail/?page=releasenote_content&division=6&id=1057"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN68079883"
}
],
"database_specific": {
"cwe_ids": [
"CWE-348"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T09:15:20Z"
}
}
@@ -0,0 +1,68 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p97c-7hc4-x66c",
"modified": "2025-05-23T09:30:27Z",
"published": "2025-05-23T09:30:27Z",
"aliases": [
"CVE-2025-5096"
],
"details": "The TablePress plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the 'data-caption', 'data-s-content-padding', 'data-s-title', and 'data-footer' data-attributes in all versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5096"
},
{
"type": "WEB",
"url": "https://github.com/DataTables/DataTablesSrc/commit/d278ed307035cb8740d2fad86b7cbb995380f7bb"
},
{
"type": "WEB",
"url": "https://github.com/DataTables/DataTablesSrc/commit/d558328106bef2d48dfc4cf78581dd106f5c1077"
},
{
"type": "WEB",
"url": "https://datatables.net"
},
{
"type": "WEB",
"url": "https://github.com/DataTables/DataTablesSrc/blob/29539c40504365bc4be0599e4b0739cf270a2e09/js/core/core.constructor.js#L329"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/tablepress/tags/3.1.2/js/jquery.datatables.min.js"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3298453/tablepress"
},
{
"type": "WEB",
"url": "https://tablepress.org/release-announcement-tablepress-3-1-3"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/tablepress/#developers"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cd2dfa02-0404-4300-a5ed-6326f9df6d30?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T09:15:21Z"
}
}