From 2de68f5a704ad9988146494e5ac6fbff5a46bca8 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 24 Feb 2025 21:33:10 +0000 Subject: [PATCH] Publish Advisories GHSA-58m3-63qv-6g2g GHSA-5hgj-5c28-fh2j GHSA-c662-3p6q-p5c7 GHSA-c8f9-2rww-56v5 GHSA-2xfx-cg6v-cwqv GHSA-3xgj-vqg4-h895 GHSA-4hmr-39vp-xfrr GHSA-4w32-c9g7-27qx GHSA-5r85-6h7f-rg3r GHSA-cw24-f6fq-7j9v GHSA-g88w-v4cq-qgcp GHSA-h697-w4ph-7pcx GHSA-pxg4-xjp7-w9c5 GHSA-rg56-94j7-hjx9 GHSA-wr88-x8cm-7cgq --- .../GHSA-58m3-63qv-6g2g.json | 6 +- .../GHSA-5hgj-5c28-fh2j.json | 6 +- .../GHSA-c662-3p6q-p5c7.json | 2 +- .../GHSA-c8f9-2rww-56v5.json | 10 +++- .../GHSA-2xfx-cg6v-cwqv.json | 4 +- .../GHSA-3xgj-vqg4-h895.json | 56 +++++++++++++++++++ .../GHSA-4hmr-39vp-xfrr.json | 40 +++++++++++++ .../GHSA-4w32-c9g7-27qx.json | 40 +++++++++++++ .../GHSA-5r85-6h7f-rg3r.json | 40 +++++++++++++ .../GHSA-cw24-f6fq-7j9v.json | 40 +++++++++++++ .../GHSA-g88w-v4cq-qgcp.json | 40 +++++++++++++ .../GHSA-h697-w4ph-7pcx.json | 40 +++++++++++++ .../GHSA-pxg4-xjp7-w9c5.json | 40 +++++++++++++ .../GHSA-rg56-94j7-hjx9.json | 40 +++++++++++++ .../GHSA-wr88-x8cm-7cgq.json | 40 +++++++++++++ 15 files changed, 436 insertions(+), 8 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-3xgj-vqg4-h895/GHSA-3xgj-vqg4-h895.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4hmr-39vp-xfrr/GHSA-4hmr-39vp-xfrr.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4w32-c9g7-27qx/GHSA-4w32-c9g7-27qx.json create mode 100644 advisories/unreviewed/2025/02/GHSA-5r85-6h7f-rg3r/GHSA-5r85-6h7f-rg3r.json create mode 100644 advisories/unreviewed/2025/02/GHSA-cw24-f6fq-7j9v/GHSA-cw24-f6fq-7j9v.json create mode 100644 advisories/unreviewed/2025/02/GHSA-g88w-v4cq-qgcp/GHSA-g88w-v4cq-qgcp.json create mode 100644 advisories/unreviewed/2025/02/GHSA-h697-w4ph-7pcx/GHSA-h697-w4ph-7pcx.json create mode 100644 advisories/unreviewed/2025/02/GHSA-pxg4-xjp7-w9c5/GHSA-pxg4-xjp7-w9c5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-rg56-94j7-hjx9/GHSA-rg56-94j7-hjx9.json create mode 100644 advisories/unreviewed/2025/02/GHSA-wr88-x8cm-7cgq/GHSA-wr88-x8cm-7cgq.json diff --git a/advisories/unreviewed/2023/03/GHSA-58m3-63qv-6g2g/GHSA-58m3-63qv-6g2g.json b/advisories/unreviewed/2023/03/GHSA-58m3-63qv-6g2g/GHSA-58m3-63qv-6g2g.json index c2c4770f50b..ff6bc42adb1 100644 --- a/advisories/unreviewed/2023/03/GHSA-58m3-63qv-6g2g/GHSA-58m3-63qv-6g2g.json +++ b/advisories/unreviewed/2023/03/GHSA-58m3-63qv-6g2g/GHSA-58m3-63qv-6g2g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-58m3-63qv-6g2g", - "modified": "2023-04-03T18:32:07Z", + "modified": "2025-02-24T21:31:43Z", "published": "2023-03-28T00:34:28Z", "aliases": [ "CVE-2022-48349" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-290" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-5hgj-5c28-fh2j/GHSA-5hgj-5c28-fh2j.json b/advisories/unreviewed/2023/03/GHSA-5hgj-5c28-fh2j/GHSA-5hgj-5c28-fh2j.json index 29eb7122cc9..1194cefa908 100644 --- a/advisories/unreviewed/2023/03/GHSA-5hgj-5c28-fh2j/GHSA-5hgj-5c28-fh2j.json +++ b/advisories/unreviewed/2023/03/GHSA-5hgj-5c28-fh2j/GHSA-5hgj-5c28-fh2j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5hgj-5c28-fh2j", - "modified": "2023-04-03T18:32:09Z", + "modified": "2025-02-24T21:31:43Z", "published": "2023-03-28T00:34:28Z", "aliases": [ "CVE-2022-48348" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-c662-3p6q-p5c7/GHSA-c662-3p6q-p5c7.json b/advisories/unreviewed/2023/03/GHSA-c662-3p6q-p5c7/GHSA-c662-3p6q-p5c7.json index 7f0202e3523..1f469eb81a0 100644 --- a/advisories/unreviewed/2023/03/GHSA-c662-3p6q-p5c7/GHSA-c662-3p6q-p5c7.json +++ b/advisories/unreviewed/2023/03/GHSA-c662-3p6q-p5c7/GHSA-c662-3p6q-p5c7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c662-3p6q-p5c7", - "modified": "2023-04-04T03:30:17Z", + "modified": "2025-02-24T21:31:43Z", "published": "2023-03-28T00:34:28Z", "aliases": [ "CVE-2022-3116" diff --git a/advisories/unreviewed/2023/03/GHSA-c8f9-2rww-56v5/GHSA-c8f9-2rww-56v5.json b/advisories/unreviewed/2023/03/GHSA-c8f9-2rww-56v5/GHSA-c8f9-2rww-56v5.json index 1ee044fca06..d6ba25cb7ab 100644 --- a/advisories/unreviewed/2023/03/GHSA-c8f9-2rww-56v5/GHSA-c8f9-2rww-56v5.json +++ b/advisories/unreviewed/2023/03/GHSA-c8f9-2rww-56v5/GHSA-c8f9-2rww-56v5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c8f9-2rww-56v5", - "modified": "2023-04-03T18:32:08Z", + "modified": "2025-02-24T21:31:42Z", "published": "2023-03-27T21:30:26Z", "aliases": [ "CVE-2021-3923" @@ -23,13 +23,19 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2019643" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/all/20220204100036.GA12348%40kili" + }, { "type": "WEB", "url": "https://lore.kernel.org/all/20220204100036.GA12348@kili" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-2xfx-cg6v-cwqv/GHSA-2xfx-cg6v-cwqv.json b/advisories/unreviewed/2025/02/GHSA-2xfx-cg6v-cwqv/GHSA-2xfx-cg6v-cwqv.json index 5726800647a..dafa672e59a 100644 --- a/advisories/unreviewed/2025/02/GHSA-2xfx-cg6v-cwqv/GHSA-2xfx-cg6v-cwqv.json +++ b/advisories/unreviewed/2025/02/GHSA-2xfx-cg6v-cwqv/GHSA-2xfx-cg6v-cwqv.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-3xgj-vqg4-h895/GHSA-3xgj-vqg4-h895.json b/advisories/unreviewed/2025/02/GHSA-3xgj-vqg4-h895/GHSA-3xgj-vqg4-h895.json new file mode 100644 index 00000000000..5303a4f356f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3xgj-vqg4-h895/GHSA-3xgj-vqg4-h895.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xgj-vqg4-h895", + "modified": "2025-02-24T21:31:44Z", + "published": "2025-02-24T21:31:43Z", + "aliases": [ + "CVE-2025-27364" + ], + "details": "In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the server. This allows remote attackers to execute arbitrary code on the server that Caldera is running on via a crafted web request to the Caldera server API used for compiling and downloading of Caldera's Sandcat or Manx agent (implants). This web request can use the gcc -extldflags linker flag with sub-commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27364" + }, + { + "type": "WEB", + "url": "https://github.com/mitre/caldera/pull/3129" + }, + { + "type": "WEB", + "url": "https://github.com/mitre/caldera/pull/3131/commits/61de40f92a595bed462372a5e676c2e5a32d1050" + }, + { + "type": "WEB", + "url": "https://github.com/mitre/caldera/commit/35bc06e42e19fe7efbc008999b9f993b1b7109c0" + }, + { + "type": "WEB", + "url": "https://github.com/mitre/caldera/releases" + }, + { + "type": "WEB", + "url": "https://github.com/mitre/caldera/security" + }, + { + "type": "WEB", + "url": "https://medium.com/@mitrecaldera/mitre-caldera-security-advisory-remote-code-execution-cve-2025-27364-5f679e2e2a0e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4hmr-39vp-xfrr/GHSA-4hmr-39vp-xfrr.json b/advisories/unreviewed/2025/02/GHSA-4hmr-39vp-xfrr/GHSA-4hmr-39vp-xfrr.json new file mode 100644 index 00000000000..bbcca8c6119 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4hmr-39vp-xfrr/GHSA-4hmr-39vp-xfrr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hmr-39vp-xfrr", + "modified": "2025-02-24T21:31:44Z", + "published": "2025-02-24T21:31:44Z", + "aliases": [ + "CVE-2025-26525" + ], + "details": "Insufficient sanitizing in the TeX notation filter resulted in an \narbitrary file read risk on sites where pdfTeX is available (such as \nthose with TeX Live installed).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26525" + }, + { + "type": "WEB", + "url": "https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84136" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=466141" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4w32-c9g7-27qx/GHSA-4w32-c9g7-27qx.json b/advisories/unreviewed/2025/02/GHSA-4w32-c9g7-27qx/GHSA-4w32-c9g7-27qx.json new file mode 100644 index 00000000000..e72cf3425b6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4w32-c9g7-27qx/GHSA-4w32-c9g7-27qx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w32-c9g7-27qx", + "modified": "2025-02-24T21:31:44Z", + "published": "2025-02-24T21:31:44Z", + "aliases": [ + "CVE-2025-26530" + ], + "details": "The question bank filter required additional sanitizing to prevent a reflected XSS risk.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26530" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=466146" + }, + { + "type": "WEB", + "url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84146" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5r85-6h7f-rg3r/GHSA-5r85-6h7f-rg3r.json b/advisories/unreviewed/2025/02/GHSA-5r85-6h7f-rg3r/GHSA-5r85-6h7f-rg3r.json new file mode 100644 index 00000000000..5d4a66f9e10 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5r85-6h7f-rg3r/GHSA-5r85-6h7f-rg3r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r85-6h7f-rg3r", + "modified": "2025-02-24T21:31:44Z", + "published": "2025-02-24T21:31:44Z", + "aliases": [ + "CVE-2025-26527" + ], + "details": "Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26527" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=466143" + }, + { + "type": "WEB", + "url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-83941" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1230" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cw24-f6fq-7j9v/GHSA-cw24-f6fq-7j9v.json b/advisories/unreviewed/2025/02/GHSA-cw24-f6fq-7j9v/GHSA-cw24-f6fq-7j9v.json new file mode 100644 index 00000000000..5f4ea2698fd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cw24-f6fq-7j9v/GHSA-cw24-f6fq-7j9v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cw24-f6fq-7j9v", + "modified": "2025-02-24T21:31:44Z", + "published": "2025-02-24T21:31:44Z", + "aliases": [ + "CVE-2025-26532" + ], + "details": "Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26532" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=466149" + }, + { + "type": "WEB", + "url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84003" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g88w-v4cq-qgcp/GHSA-g88w-v4cq-qgcp.json b/advisories/unreviewed/2025/02/GHSA-g88w-v4cq-qgcp/GHSA-g88w-v4cq-qgcp.json new file mode 100644 index 00000000000..b0ee4a89ad8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g88w-v4cq-qgcp/GHSA-g88w-v4cq-qgcp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g88w-v4cq-qgcp", + "modified": "2025-02-24T21:31:44Z", + "published": "2025-02-24T21:31:44Z", + "aliases": [ + "CVE-2025-26531" + ], + "details": "Insufficient capability checks made it possible to disable badges a user does not have permission to access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26531" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=466148" + }, + { + "type": "WEB", + "url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84239" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h697-w4ph-7pcx/GHSA-h697-w4ph-7pcx.json b/advisories/unreviewed/2025/02/GHSA-h697-w4ph-7pcx/GHSA-h697-w4ph-7pcx.json new file mode 100644 index 00000000000..dc0a32c40de --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h697-w4ph-7pcx/GHSA-h697-w4ph-7pcx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h697-w4ph-7pcx", + "modified": "2025-02-24T21:31:44Z", + "published": "2025-02-24T21:31:44Z", + "aliases": [ + "CVE-2025-26528" + ], + "details": "The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26528" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=466144" + }, + { + "type": "WEB", + "url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-82896" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pxg4-xjp7-w9c5/GHSA-pxg4-xjp7-w9c5.json b/advisories/unreviewed/2025/02/GHSA-pxg4-xjp7-w9c5/GHSA-pxg4-xjp7-w9c5.json new file mode 100644 index 00000000000..7e198d0852c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pxg4-xjp7-w9c5/GHSA-pxg4-xjp7-w9c5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxg4-xjp7-w9c5", + "modified": "2025-02-24T21:31:44Z", + "published": "2025-02-24T21:31:44Z", + "aliases": [ + "CVE-2025-26526" + ], + "details": "Separate Groups mode restrictions were not factored into permission \nchecks before allowing viewing or deletion of responses in Feedback \nactivities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26526" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=466142" + }, + { + "type": "WEB", + "url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-79976" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rg56-94j7-hjx9/GHSA-rg56-94j7-hjx9.json b/advisories/unreviewed/2025/02/GHSA-rg56-94j7-hjx9/GHSA-rg56-94j7-hjx9.json new file mode 100644 index 00000000000..cb62f77b23c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rg56-94j7-hjx9/GHSA-rg56-94j7-hjx9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg56-94j7-hjx9", + "modified": "2025-02-24T21:31:44Z", + "published": "2025-02-24T21:31:44Z", + "aliases": [ + "CVE-2025-26533" + ], + "details": "An SQL injection risk was identified in the module list filter within course search.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26533" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=466150" + }, + { + "type": "WEB", + "url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84271" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wr88-x8cm-7cgq/GHSA-wr88-x8cm-7cgq.json b/advisories/unreviewed/2025/02/GHSA-wr88-x8cm-7cgq/GHSA-wr88-x8cm-7cgq.json new file mode 100644 index 00000000000..a04f35a2641 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wr88-x8cm-7cgq/GHSA-wr88-x8cm-7cgq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr88-x8cm-7cgq", + "modified": "2025-02-24T21:31:44Z", + "published": "2025-02-24T21:31:44Z", + "aliases": [ + "CVE-2025-26529" + ], + "details": "Description information displayed in the site administration live log \nrequired additional sanitizing to prevent a stored XSS risk.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26529" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=466145" + }, + { + "type": "WEB", + "url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84145" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T20:15:33Z" + } +} \ No newline at end of file