Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-03-12 21:33:26 +00:00
parent ca6f582a1b
commit 240c670897
29 changed files with 409 additions and 64 deletions
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4g73-3mxf-j47w",
"modified": "2022-01-20T00:02:14Z",
"modified": "2025-03-12T21:31:26Z",
"published": "2022-01-14T00:02:17Z",
"aliases": [
"CVE-2022-23131"
],
"details": "In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g86r-9849-44wq",
"modified": "2023-03-03T18:30:27Z",
"modified": "2025-03-12T21:31:27Z",
"published": "2023-02-23T21:30:16Z",
"aliases": [
"CVE-2023-0597"
@@ -23,6 +23,10 @@
"type": "WEB",
"url": "https://git.kernel.org/linus/97e3d26b5e5f371b3ee223d94dd123e6c442ba80"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2023/07/28/1"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/07/28/1"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pf7g-97vv-qmrr",
"modified": "2023-03-03T18:30:27Z",
"modified": "2025-03-12T21:31:27Z",
"published": "2023-02-23T21:30:17Z",
"aliases": [
"CVE-2022-3219"
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2cpq-fw2c-xjfv",
"modified": "2024-04-10T21:30:34Z",
"modified": "2025-03-12T21:31:27Z",
"published": "2024-04-10T21:30:34Z",
"aliases": [
"CVE-2024-31430"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF WordPress Posts Bulk Editor and Manager Professional, realmag777 BEAR Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net.This issue affects WOLF WordPress Posts Bulk Editor and Manager Professional: from n/a through 1.0.8.1; BEAR Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net: from n/a through 1.1.4.1.\n\n",
"details": "Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF WordPress Posts Bulk Editor and Manager Professional, realmag777 BEAR Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net.This issue affects WOLF WordPress Posts Bulk Editor and Manager Professional: from n/a through 1.0.8.1; BEAR Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net: from n/a through 1.1.4.1.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4r7g-8pjm-hmjc",
"modified": "2024-04-15T09:30:54Z",
"modified": "2025-03-12T21:31:28Z",
"published": "2024-04-15T09:30:54Z",
"aliases": [
"CVE-2024-32125"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Booking Algorithms BA Book Everything.This issue affects BA Book Everything: from n/a through 1.6.4.\n\n",
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Booking Algorithms BA Book Everything.This issue affects BA Book Everything: from n/a through 1.6.4.",
"severity": [
{
"type": "CVSS_V3",
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-987j-g759-4rq3",
"modified": "2024-04-24T18:30:33Z",
"modified": "2025-03-12T21:31:28Z",
"published": "2024-04-24T18:30:33Z",
"aliases": [
"CVE-2023-51405"
],
"details": "Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BookingPress: from n/a through 1.0.74.\n\n",
"details": "Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BookingPress: from n/a through 1.0.74.",
"severity": [
{
"type": "CVSS_V3",
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-287"
"CWE-287",
"CWE-863"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ffg5-77xm-p7h2",
"modified": "2024-04-18T09:30:45Z",
"modified": "2025-03-12T21:31:28Z",
"published": "2024-04-18T09:30:45Z",
"aliases": [
"CVE-2024-32598"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Booking Algorithms BA Book Everything allows Stored XSS.This issue affects BA Book Everything: from n/a through 1.6.8.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Booking Algorithms BA Book Everything allows Stored XSS.This issue affects BA Book Everything: from n/a through 1.6.8.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v43f-6mhr-gwc4",
"modified": "2024-04-18T12:30:30Z",
"modified": "2025-03-12T21:31:28Z",
"published": "2024-04-18T12:30:30Z",
"aliases": [
"CVE-2024-32576"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Booking Algorithms BA Book Everything allows Stored XSS.This issue affects BA Book Everything: from n/a through 1.6.8.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Booking Algorithms BA Book Everything allows Stored XSS.This issue affects BA Book Everything: from n/a through 1.6.8.",
"severity": [
{
"type": "CVSS_V3",
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h5p6-2x4v-9wqh",
"modified": "2025-02-21T18:31:15Z",
"modified": "2025-03-12T21:31:28Z",
"published": "2025-02-21T18:31:15Z",
"aliases": [
"CVE-2024-55159"
],
"details": "GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the SortName parameter at /system/loginLog/list.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-21T18:15:18Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jrq6-48vf-qc9h",
"modified": "2025-02-14T00:30:45Z",
"modified": "2025-03-12T21:31:28Z",
"published": "2025-02-14T00:30:45Z",
"aliases": [
"CVE-2025-22961"
],
"details": "A critical information disclosure vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters due to Incorrect Access Control (CWE-284). Unauthenticated attackers can directly access sensitive database backup files (snapshot_users.db) via publicly exposed URLs (/logs/devcfg/snapshot/ and /logs/devcfg/user/). Exploiting this vulnerability allows retrieval of sensitive user data, including login credentials, potentially leading to full system compromise.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-200"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-13T23:15:11Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pq8f-mw6x-f2j2",
"modified": "2025-02-26T18:30:38Z",
"modified": "2025-03-12T21:31:28Z",
"published": "2025-02-26T18:30:38Z",
"aliases": [
"CVE-2025-25462"
],
"details": "A SQL Injection vulnerability was found in /admin/add-propertytype.php in PHPGurukul Land Record System Project in PHP v1.0 allows remote attackers to execute arbitrary code via the propertytype POST request parameter.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-26T16:15:16Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-29qq-gf32-fj2m",
"modified": "2025-03-10T21:31:12Z",
"modified": "2025-03-12T21:31:29Z",
"published": "2025-03-10T21:31:12Z",
"aliases": [
"CVE-2025-26695"
],
"details": "When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested email address. This vulnerability affects Thunderbird < 136 and Thunderbird < 128.8.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
@@ -29,7 +34,7 @@
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-10T19:15:40Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2j99-5q75-3f57",
"modified": "2025-03-11T21:30:34Z",
"modified": "2025-03-12T21:31:29Z",
"published": "2025-03-11T18:32:19Z",
"aliases": [
"CVE-2025-24201"
],
"details": "An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in visionOS 2.3.2, iOS 18.3.2 and iPadOS 18.3.2, macOS Sequoia 15.3.2. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.).",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-11T18:15:30Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3j25-3c73-vg7p",
"modified": "2025-03-10T15:30:47Z",
"modified": "2025-03-12T21:31:28Z",
"published": "2025-03-10T15:30:47Z",
"aliases": [
"CVE-2025-25615"
],
"details": "Unifiedtransform 2.0 is vulnerable to Incorrect Access Control which allows viewing attendance list for all class sections.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-10T14:15:24Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-42rw-qp74-jqxj",
"modified": "2025-03-10T15:30:47Z",
"modified": "2025-03-12T21:31:28Z",
"published": "2025-03-10T15:30:47Z",
"aliases": [
"CVE-2024-57492"
],
"details": "An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the round_up_to_page funciton.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L"
}
],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-1262"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-10T14:15:24Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-48hh-v7xg-xpgq",
"modified": "2025-03-10T15:30:48Z",
"modified": "2025-03-12T21:31:28Z",
"published": "2025-03-10T15:30:47Z",
"aliases": [
"CVE-2025-25616"
],
"details": "Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The affected endpoint is /exams/edit-rule?exam_rule_id=1.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-284"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-10T14:15:25Z"
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4gx3-p432-m8m7",
"modified": "2025-03-12T21:31:29Z",
"published": "2025-03-12T21:31:29Z",
"aliases": [
"CVE-2025-0118"
],
"details": "A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticated user. However, to exploit this vulnerability, the authenticated user must navigate to a malicious page during the GlobalProtect SAML login process on a Windows device.\n\nThis issue does not apply to the GlobalProtect app on other (non-Windows) platforms.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0118"
},
{
"type": "WEB",
"url": "https://security.paloaltonetworks.com/CVE-2025-0118"
}
],
"database_specific": {
"cwe_ids": [
"CWE-618"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-12T19:15:38Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8g77-54rh-46hx",
"modified": "2025-03-12T21:31:29Z",
"published": "2025-03-12T21:31:29Z",
"aliases": [
"CVE-2025-25975"
],
"details": "An issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys function",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25975"
},
{
"type": "WEB",
"url": "https://github.com/jonschlinkert/parse-git-config/issues/14"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-12T19:15:40Z"
}
}

Some files were not shown because too many files have changed in this diff Show More