From 20d8f5d8b649589ab8ab86e1bd341ae23981f3a3 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 5 Mar 2025 03:32:26 +0000 Subject: [PATCH] Publish Advisories GHSA-2ppf-g925-w5q9 GHSA-34wx-3jmq-rv2m GHSA-f6rm-pqpw-mh93 GHSA-hj6q-qv48-rgmf GHSA-qh47-4wjj-cqjj GHSA-rmf5-rhfv-3qrp GHSA-wqvp-j9fj-j6wf --- .../GHSA-2ppf-g925-w5q9.json | 36 ++++++++++++ .../GHSA-34wx-3jmq-rv2m.json | 56 +++++++++++++++++++ .../GHSA-f6rm-pqpw-mh93.json | 52 +++++++++++++++++ .../GHSA-hj6q-qv48-rgmf.json | 6 +- .../GHSA-qh47-4wjj-cqjj.json | 36 ++++++++++++ .../GHSA-rmf5-rhfv-3qrp.json | 52 +++++++++++++++++ .../GHSA-wqvp-j9fj-j6wf.json | 56 +++++++++++++++++++ 7 files changed, 293 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-2ppf-g925-w5q9/GHSA-2ppf-g925-w5q9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-34wx-3jmq-rv2m/GHSA-34wx-3jmq-rv2m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f6rm-pqpw-mh93/GHSA-f6rm-pqpw-mh93.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qh47-4wjj-cqjj/GHSA-qh47-4wjj-cqjj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rmf5-rhfv-3qrp/GHSA-rmf5-rhfv-3qrp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wqvp-j9fj-j6wf/GHSA-wqvp-j9fj-j6wf.json diff --git a/advisories/unreviewed/2025/03/GHSA-2ppf-g925-w5q9/GHSA-2ppf-g925-w5q9.json b/advisories/unreviewed/2025/03/GHSA-2ppf-g925-w5q9/GHSA-2ppf-g925-w5q9.json new file mode 100644 index 00000000000..76b241088ff --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2ppf-g925-w5q9/GHSA-2ppf-g925-w5q9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2ppf-g925-w5q9", + "modified": "2025-03-05T03:30:51Z", + "published": "2025-03-05T03:30:51Z", + "aliases": [ + "CVE-2024-0141" + ], + "details": "NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the GPU vBIOS that may allow a malicious actor with tenant level GPU access to write to an unsupported registry causing a bad state. A successful exploit of this vulnerability may lead to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0141" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5561" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-782" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-05T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-34wx-3jmq-rv2m/GHSA-34wx-3jmq-rv2m.json b/advisories/unreviewed/2025/03/GHSA-34wx-3jmq-rv2m/GHSA-34wx-3jmq-rv2m.json new file mode 100644 index 00000000000..0799bec44b9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-34wx-3jmq-rv2m/GHSA-34wx-3jmq-rv2m.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34wx-3jmq-rv2m", + "modified": "2025-03-05T03:30:51Z", + "published": "2025-03-05T03:30:51Z", + "aliases": [ + "CVE-2025-1966" + ], + "details": "A vulnerability classified as critical was found in PHPGurukul Pre-School Enrollment System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1966" + }, + { + "type": "WEB", + "url": "https://github.com/SECWG/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298567" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298567" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.512039" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-05T02:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f6rm-pqpw-mh93/GHSA-f6rm-pqpw-mh93.json b/advisories/unreviewed/2025/03/GHSA-f6rm-pqpw-mh93/GHSA-f6rm-pqpw-mh93.json new file mode 100644 index 00000000000..699bbdbda9f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f6rm-pqpw-mh93/GHSA-f6rm-pqpw-mh93.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6rm-pqpw-mh93", + "modified": "2025-03-05T03:30:51Z", + "published": "2025-03-05T03:30:51Z", + "aliases": [ + "CVE-2025-1964" + ], + "details": "A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been rated as critical. This issue affects some unknown processing of the file /booknow.php?roomname=Duplex. The manipulation of the argument checkin leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1964" + }, + { + "type": "WEB", + "url": "https://github.com/ubfbuz3/cve/issues/3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298565" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298565" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.511471" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-05T01:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hj6q-qv48-rgmf/GHSA-hj6q-qv48-rgmf.json b/advisories/unreviewed/2025/03/GHSA-hj6q-qv48-rgmf/GHSA-hj6q-qv48-rgmf.json index ed16c28e53b..9da8f5ad8a4 100644 --- a/advisories/unreviewed/2025/03/GHSA-hj6q-qv48-rgmf/GHSA-hj6q-qv48-rgmf.json +++ b/advisories/unreviewed/2025/03/GHSA-hj6q-qv48-rgmf/GHSA-hj6q-qv48-rgmf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hj6q-qv48-rgmf", - "modified": "2025-03-01T18:30:40Z", + "modified": "2025-03-05T03:30:51Z", "published": "2025-03-01T18:30:40Z", "aliases": [ "CVE-2025-1800" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://github.com/sjwszt/CVE/blob/main/CVE_1.md" }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10354" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.298030" diff --git a/advisories/unreviewed/2025/03/GHSA-qh47-4wjj-cqjj/GHSA-qh47-4wjj-cqjj.json b/advisories/unreviewed/2025/03/GHSA-qh47-4wjj-cqjj/GHSA-qh47-4wjj-cqjj.json new file mode 100644 index 00000000000..bd6c4676886 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qh47-4wjj-cqjj/GHSA-qh47-4wjj-cqjj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qh47-4wjj-cqjj", + "modified": "2025-03-05T03:30:51Z", + "published": "2025-03-05T03:30:51Z", + "aliases": [ + "CVE-2024-0114" + ], + "details": "NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administrative access on the BMC to access the HMC as an administrator. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0114" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5561" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1244" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-05T02:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rmf5-rhfv-3qrp/GHSA-rmf5-rhfv-3qrp.json b/advisories/unreviewed/2025/03/GHSA-rmf5-rhfv-3qrp/GHSA-rmf5-rhfv-3qrp.json new file mode 100644 index 00000000000..ddb9c2d4b40 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rmf5-rhfv-3qrp/GHSA-rmf5-rhfv-3qrp.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmf5-rhfv-3qrp", + "modified": "2025-03-05T03:30:51Z", + "published": "2025-03-05T03:30:51Z", + "aliases": [ + "CVE-2025-1965" + ], + "details": "A vulnerability classified as critical has been found in projectworlds Online Hotel Booking 1.0. Affected is an unknown function of the file /admin/login.php. The manipulation of the argument emailusername leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1965" + }, + { + "type": "WEB", + "url": "https://github.com/ubfbuz3/cve/issues/4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298566" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298566" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.511473" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-05T01:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wqvp-j9fj-j6wf/GHSA-wqvp-j9fj-j6wf.json b/advisories/unreviewed/2025/03/GHSA-wqvp-j9fj-j6wf/GHSA-wqvp-j9fj-j6wf.json new file mode 100644 index 00000000000..11161026112 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wqvp-j9fj-j6wf/GHSA-wqvp-j9fj-j6wf.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqvp-j9fj-j6wf", + "modified": "2025-03-05T03:30:51Z", + "published": "2025-03-05T03:30:51Z", + "aliases": [ + "CVE-2025-1967" + ], + "details": "A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0. Affected by this issue is some unknown functionality of the file /user_dashboard/donor.php. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1967" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/intercpt/XSS1/blob/main/XSS.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298568" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298568" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.512163" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-05T02:15:36Z" + } +} \ No newline at end of file