From 33726584d523a674a6b43d6634f1857aa87defe7 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 26 Feb 2025 00:33:39 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-wmh3-5pfq-qpp8.json | 6 +- .../GHSA-8q86-4x73-99v8.json | 4 +- .../GHSA-gfq7-h592-v3xj.json | 15 +++-- .../GHSA-mcfj-9jjf-96q9.json | 4 +- .../GHSA-jhhw-3vhx-mm3g.json | 6 +- .../GHSA-47x9-rgw2-xh4h.json | 3 +- .../GHSA-659p-5v6v-74vw.json | 3 +- .../GHSA-6g48-x687-vqf9.json | 3 +- .../GHSA-6mf2-fq9m-xrff.json | 3 +- .../GHSA-7whm-6g5h-h96p.json | 3 +- .../GHSA-82j5-p9gh-m4p2.json | 3 +- .../GHSA-8mgr-c64f-w923.json | 3 +- .../GHSA-f9m2-cxhf-2qc5.json | 3 +- .../GHSA-hggj-xw9j-66ph.json | 2 +- .../GHSA-hx65-9q68-4gq8.json | 3 +- .../GHSA-pq6f-c6w9-6488.json | 56 +++++++++++++++++++ .../GHSA-pwj6-jrcp-fvfv.json | 3 +- .../GHSA-v26g-qqjw-5qgq.json | 2 +- .../GHSA-vcfx-799h-w73m.json | 3 +- .../GHSA-2gg3-vm5q-jcq2.json | 2 +- .../GHSA-32xx-6c3g-hvfm.json | 6 +- .../GHSA-63xm-g6f5-3cw5.json | 29 ++++++++++ .../GHSA-c46r-j7hv-8f85.json | 29 ++++++++++ .../GHSA-c7c6-hp9w-4gmf.json | 29 ++++++++++ .../GHSA-f6mr-g7jq-gx82.json | 36 ++++++++++++ .../GHSA-f754-m3x7-vr78.json | 29 ++++++++++ .../GHSA-fvx6-jx94-49qx.json | 6 +- .../GHSA-g635-4v3q-xmrq.json | 29 ++++++++++ .../GHSA-j5j2-54p5-7p3j.json | 36 ++++++++++++ .../GHSA-mmcm-44xw-5gf8.json | 36 ++++++++++++ .../GHSA-prcj-vvj7-6gm4.json | 9 ++- .../GHSA-rjgv-6mwj-prq2.json | 31 ++++++++++ .../GHSA-rpm8-r6fr-56f4.json | 36 ++++++++++++ .../GHSA-vhgx-6vv2-prcm.json | 29 ++++++++++ .../GHSA-xcx2-4699-rfv3.json | 29 ++++++++++ 35 files changed, 502 insertions(+), 27 deletions(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-pq6f-c6w9-6488/GHSA-pq6f-c6w9-6488.json create mode 100644 advisories/unreviewed/2025/02/GHSA-63xm-g6f5-3cw5/GHSA-63xm-g6f5-3cw5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-c46r-j7hv-8f85/GHSA-c46r-j7hv-8f85.json create mode 100644 advisories/unreviewed/2025/02/GHSA-c7c6-hp9w-4gmf/GHSA-c7c6-hp9w-4gmf.json create mode 100644 advisories/unreviewed/2025/02/GHSA-f6mr-g7jq-gx82/GHSA-f6mr-g7jq-gx82.json create mode 100644 advisories/unreviewed/2025/02/GHSA-f754-m3x7-vr78/GHSA-f754-m3x7-vr78.json create mode 100644 advisories/unreviewed/2025/02/GHSA-g635-4v3q-xmrq/GHSA-g635-4v3q-xmrq.json create mode 100644 advisories/unreviewed/2025/02/GHSA-j5j2-54p5-7p3j/GHSA-j5j2-54p5-7p3j.json create mode 100644 advisories/unreviewed/2025/02/GHSA-mmcm-44xw-5gf8/GHSA-mmcm-44xw-5gf8.json create mode 100644 advisories/unreviewed/2025/02/GHSA-rjgv-6mwj-prq2/GHSA-rjgv-6mwj-prq2.json create mode 100644 advisories/unreviewed/2025/02/GHSA-rpm8-r6fr-56f4/GHSA-rpm8-r6fr-56f4.json create mode 100644 advisories/unreviewed/2025/02/GHSA-vhgx-6vv2-prcm/GHSA-vhgx-6vv2-prcm.json create mode 100644 advisories/unreviewed/2025/02/GHSA-xcx2-4699-rfv3/GHSA-xcx2-4699-rfv3.json diff --git a/advisories/unreviewed/2023/03/GHSA-wmh3-5pfq-qpp8/GHSA-wmh3-5pfq-qpp8.json b/advisories/unreviewed/2023/03/GHSA-wmh3-5pfq-qpp8/GHSA-wmh3-5pfq-qpp8.json index 562f86cd513..37c37b50a86 100644 --- a/advisories/unreviewed/2023/03/GHSA-wmh3-5pfq-qpp8/GHSA-wmh3-5pfq-qpp8.json +++ b/advisories/unreviewed/2023/03/GHSA-wmh3-5pfq-qpp8/GHSA-wmh3-5pfq-qpp8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wmh3-5pfq-qpp8", - "modified": "2023-03-28T21:30:20Z", + "modified": "2025-02-26T00:32:07Z", "published": "2023-03-23T00:30:16Z", "aliases": [ "CVE-2023-27100" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://docs.netgate.com/downloads/pfSense-SA-23_05.sshguard.asc" }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/171791" + }, { "type": "WEB", "url": "https://redmine.pfsense.org/issues/13574" diff --git a/advisories/unreviewed/2024/02/GHSA-8q86-4x73-99v8/GHSA-8q86-4x73-99v8.json b/advisories/unreviewed/2024/02/GHSA-8q86-4x73-99v8/GHSA-8q86-4x73-99v8.json index ed50676929c..5712a2039d3 100644 --- a/advisories/unreviewed/2024/02/GHSA-8q86-4x73-99v8/GHSA-8q86-4x73-99v8.json +++ b/advisories/unreviewed/2024/02/GHSA-8q86-4x73-99v8/GHSA-8q86-4x73-99v8.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-8q86-4x73-99v8", - "modified": "2024-02-26T18:30:29Z", + "modified": "2025-02-26T00:32:11Z", "published": "2024-02-26T18:30:29Z", "aliases": [ "CVE-2024-0387" ], - "details": "The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.\n\n", + "details": "The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-gfq7-h592-v3xj/GHSA-gfq7-h592-v3xj.json b/advisories/unreviewed/2024/02/GHSA-gfq7-h592-v3xj/GHSA-gfq7-h592-v3xj.json index c1379d854a1..9d0c178a3e1 100644 --- a/advisories/unreviewed/2024/02/GHSA-gfq7-h592-v3xj/GHSA-gfq7-h592-v3xj.json +++ b/advisories/unreviewed/2024/02/GHSA-gfq7-h592-v3xj/GHSA-gfq7-h592-v3xj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gfq7-h592-v3xj", - "modified": "2024-03-28T09:31:12Z", + "modified": "2025-02-26T00:32:10Z", "published": "2024-02-24T00:30:20Z", "aliases": [ "CVE-2024-24681" ], "details": "Insecure AES key in Yealink Configuration Encrypt Tool below verrsion 1.2. A single, vendorwide, hardcoded AES key in the configuration tool used to encrypt provisioning documents was leaked leading to a compromise of confidentiality of provisioning documents.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-798" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-23T23:15:09Z" diff --git a/advisories/unreviewed/2024/02/GHSA-mcfj-9jjf-96q9/GHSA-mcfj-9jjf-96q9.json b/advisories/unreviewed/2024/02/GHSA-mcfj-9jjf-96q9/GHSA-mcfj-9jjf-96q9.json index 1588a8c274c..5fccf5d6e98 100644 --- a/advisories/unreviewed/2024/02/GHSA-mcfj-9jjf-96q9/GHSA-mcfj-9jjf-96q9.json +++ b/advisories/unreviewed/2024/02/GHSA-mcfj-9jjf-96q9/GHSA-mcfj-9jjf-96q9.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-jhhw-3vhx-mm3g/GHSA-jhhw-3vhx-mm3g.json b/advisories/unreviewed/2024/06/GHSA-jhhw-3vhx-mm3g/GHSA-jhhw-3vhx-mm3g.json index 8ded1593d20..94c9591af9f 100644 --- a/advisories/unreviewed/2024/06/GHSA-jhhw-3vhx-mm3g/GHSA-jhhw-3vhx-mm3g.json +++ b/advisories/unreviewed/2024/06/GHSA-jhhw-3vhx-mm3g/GHSA-jhhw-3vhx-mm3g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jhhw-3vhx-mm3g", - "modified": "2024-06-25T15:31:09Z", + "modified": "2025-02-26T00:32:11Z", "published": "2024-06-25T15:31:09Z", "aliases": [ "CVE-2023-37541" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37541" }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0119435" + }, { "type": "WEB", "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0114156" diff --git a/advisories/unreviewed/2024/12/GHSA-47x9-rgw2-xh4h/GHSA-47x9-rgw2-xh4h.json b/advisories/unreviewed/2024/12/GHSA-47x9-rgw2-xh4h/GHSA-47x9-rgw2-xh4h.json index 3eb2aedcd7c..c974f7ff561 100644 --- a/advisories/unreviewed/2024/12/GHSA-47x9-rgw2-xh4h/GHSA-47x9-rgw2-xh4h.json +++ b/advisories/unreviewed/2024/12/GHSA-47x9-rgw2-xh4h/GHSA-47x9-rgw2-xh4h.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-659p-5v6v-74vw/GHSA-659p-5v6v-74vw.json b/advisories/unreviewed/2024/12/GHSA-659p-5v6v-74vw/GHSA-659p-5v6v-74vw.json index e83a1aaca25..612b6c723ae 100644 --- a/advisories/unreviewed/2024/12/GHSA-659p-5v6v-74vw/GHSA-659p-5v6v-74vw.json +++ b/advisories/unreviewed/2024/12/GHSA-659p-5v6v-74vw/GHSA-659p-5v6v-74vw.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-6g48-x687-vqf9/GHSA-6g48-x687-vqf9.json b/advisories/unreviewed/2025/01/GHSA-6g48-x687-vqf9/GHSA-6g48-x687-vqf9.json index d99f24fefbb..c66ff0ade38 100644 --- a/advisories/unreviewed/2025/01/GHSA-6g48-x687-vqf9/GHSA-6g48-x687-vqf9.json +++ b/advisories/unreviewed/2025/01/GHSA-6g48-x687-vqf9/GHSA-6g48-x687-vqf9.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-6mf2-fq9m-xrff/GHSA-6mf2-fq9m-xrff.json b/advisories/unreviewed/2025/01/GHSA-6mf2-fq9m-xrff/GHSA-6mf2-fq9m-xrff.json index 9d916552f87..e12c6b2e2a7 100644 --- a/advisories/unreviewed/2025/01/GHSA-6mf2-fq9m-xrff/GHSA-6mf2-fq9m-xrff.json +++ b/advisories/unreviewed/2025/01/GHSA-6mf2-fq9m-xrff/GHSA-6mf2-fq9m-xrff.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-7whm-6g5h-h96p/GHSA-7whm-6g5h-h96p.json b/advisories/unreviewed/2025/01/GHSA-7whm-6g5h-h96p/GHSA-7whm-6g5h-h96p.json index 17ac01db219..0815471e60d 100644 --- a/advisories/unreviewed/2025/01/GHSA-7whm-6g5h-h96p/GHSA-7whm-6g5h-h96p.json +++ b/advisories/unreviewed/2025/01/GHSA-7whm-6g5h-h96p/GHSA-7whm-6g5h-h96p.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-82j5-p9gh-m4p2/GHSA-82j5-p9gh-m4p2.json b/advisories/unreviewed/2025/01/GHSA-82j5-p9gh-m4p2/GHSA-82j5-p9gh-m4p2.json index 576f10a8180..1d550f107fd 100644 --- a/advisories/unreviewed/2025/01/GHSA-82j5-p9gh-m4p2/GHSA-82j5-p9gh-m4p2.json +++ b/advisories/unreviewed/2025/01/GHSA-82j5-p9gh-m4p2/GHSA-82j5-p9gh-m4p2.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-8mgr-c64f-w923/GHSA-8mgr-c64f-w923.json b/advisories/unreviewed/2025/01/GHSA-8mgr-c64f-w923/GHSA-8mgr-c64f-w923.json index e58d4cbfde7..efd3ee18932 100644 --- a/advisories/unreviewed/2025/01/GHSA-8mgr-c64f-w923/GHSA-8mgr-c64f-w923.json +++ b/advisories/unreviewed/2025/01/GHSA-8mgr-c64f-w923/GHSA-8mgr-c64f-w923.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-f9m2-cxhf-2qc5/GHSA-f9m2-cxhf-2qc5.json b/advisories/unreviewed/2025/01/GHSA-f9m2-cxhf-2qc5/GHSA-f9m2-cxhf-2qc5.json index 2a558e9a995..9394b31b8a8 100644 --- a/advisories/unreviewed/2025/01/GHSA-f9m2-cxhf-2qc5/GHSA-f9m2-cxhf-2qc5.json +++ b/advisories/unreviewed/2025/01/GHSA-f9m2-cxhf-2qc5/GHSA-f9m2-cxhf-2qc5.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-hggj-xw9j-66ph/GHSA-hggj-xw9j-66ph.json b/advisories/unreviewed/2025/01/GHSA-hggj-xw9j-66ph/GHSA-hggj-xw9j-66ph.json index bce9063393f..bdbb3333441 100644 --- a/advisories/unreviewed/2025/01/GHSA-hggj-xw9j-66ph/GHSA-hggj-xw9j-66ph.json +++ b/advisories/unreviewed/2025/01/GHSA-hggj-xw9j-66ph/GHSA-hggj-xw9j-66ph.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hggj-xw9j-66ph", - "modified": "2025-01-07T06:32:16Z", + "modified": "2025-02-26T00:32:16Z", "published": "2025-01-07T06:32:16Z", "aliases": [ "CVE-2024-9702" diff --git a/advisories/unreviewed/2025/01/GHSA-hx65-9q68-4gq8/GHSA-hx65-9q68-4gq8.json b/advisories/unreviewed/2025/01/GHSA-hx65-9q68-4gq8/GHSA-hx65-9q68-4gq8.json index 357b7237efc..3142d071875 100644 --- a/advisories/unreviewed/2025/01/GHSA-hx65-9q68-4gq8/GHSA-hx65-9q68-4gq8.json +++ b/advisories/unreviewed/2025/01/GHSA-hx65-9q68-4gq8/GHSA-hx65-9q68-4gq8.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-pq6f-c6w9-6488/GHSA-pq6f-c6w9-6488.json b/advisories/unreviewed/2025/01/GHSA-pq6f-c6w9-6488/GHSA-pq6f-c6w9-6488.json new file mode 100644 index 00000000000..1664beeb1b0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pq6f-c6w9-6488/GHSA-pq6f-c6w9-6488.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq6f-c6w9-6488", + "modified": "2025-02-26T00:32:12Z", + "published": "2025-01-03T03:30:29Z", + "aliases": [ + "CVE-2025-0175" + ], + "details": "A vulnerability was found in code-projects Online Shop 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /view.php. The manipulation of the argument name/details leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0175" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://gist.github.com/th4s1s/fc65dafa7237cc66a18ef6005075c31b" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290104" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290104" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.473333" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-03T01:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pwj6-jrcp-fvfv/GHSA-pwj6-jrcp-fvfv.json b/advisories/unreviewed/2025/01/GHSA-pwj6-jrcp-fvfv/GHSA-pwj6-jrcp-fvfv.json index 3f91b707535..e3a07d0d05d 100644 --- a/advisories/unreviewed/2025/01/GHSA-pwj6-jrcp-fvfv/GHSA-pwj6-jrcp-fvfv.json +++ b/advisories/unreviewed/2025/01/GHSA-pwj6-jrcp-fvfv/GHSA-pwj6-jrcp-fvfv.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-v26g-qqjw-5qgq/GHSA-v26g-qqjw-5qgq.json b/advisories/unreviewed/2025/01/GHSA-v26g-qqjw-5qgq/GHSA-v26g-qqjw-5qgq.json index 935bca37c6d..fbabbb4b6f2 100644 --- a/advisories/unreviewed/2025/01/GHSA-v26g-qqjw-5qgq/GHSA-v26g-qqjw-5qgq.json +++ b/advisories/unreviewed/2025/01/GHSA-v26g-qqjw-5qgq/GHSA-v26g-qqjw-5qgq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v26g-qqjw-5qgq", - "modified": "2025-01-04T09:35:20Z", + "modified": "2025-02-26T00:32:15Z", "published": "2025-01-04T09:35:20Z", "aliases": [ "CVE-2024-11930" diff --git a/advisories/unreviewed/2025/01/GHSA-vcfx-799h-w73m/GHSA-vcfx-799h-w73m.json b/advisories/unreviewed/2025/01/GHSA-vcfx-799h-w73m/GHSA-vcfx-799h-w73m.json index 5465509db6c..95d8eebffdc 100644 --- a/advisories/unreviewed/2025/01/GHSA-vcfx-799h-w73m/GHSA-vcfx-799h-w73m.json +++ b/advisories/unreviewed/2025/01/GHSA-vcfx-799h-w73m/GHSA-vcfx-799h-w73m.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-2gg3-vm5q-jcq2/GHSA-2gg3-vm5q-jcq2.json b/advisories/unreviewed/2025/02/GHSA-2gg3-vm5q-jcq2/GHSA-2gg3-vm5q-jcq2.json index 7a39e71dbf8..a1dd8046ec4 100644 --- a/advisories/unreviewed/2025/02/GHSA-2gg3-vm5q-jcq2/GHSA-2gg3-vm5q-jcq2.json +++ b/advisories/unreviewed/2025/02/GHSA-2gg3-vm5q-jcq2/GHSA-2gg3-vm5q-jcq2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2gg3-vm5q-jcq2", - "modified": "2025-02-25T18:31:24Z", + "modified": "2025-02-26T00:32:19Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-1067" diff --git a/advisories/unreviewed/2025/02/GHSA-32xx-6c3g-hvfm/GHSA-32xx-6c3g-hvfm.json b/advisories/unreviewed/2025/02/GHSA-32xx-6c3g-hvfm/GHSA-32xx-6c3g-hvfm.json index 06707f99cb3..73abdff63f1 100644 --- a/advisories/unreviewed/2025/02/GHSA-32xx-6c3g-hvfm/GHSA-32xx-6c3g-hvfm.json +++ b/advisories/unreviewed/2025/02/GHSA-32xx-6c3g-hvfm/GHSA-32xx-6c3g-hvfm.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-32xx-6c3g-hvfm", - "modified": "2025-02-19T09:33:29Z", + "modified": "2025-02-26T00:32:18Z", "published": "2025-02-19T09:33:29Z", "aliases": [ "CVE-2025-1132" ], "details": "A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within the EN_tyid parameter. The parameter is directly inserted into an SQL query without proper sanitization, allowing attackers to inject malicious SQL commands. Please note that the vulnerability requires Administrator permissions. This flaw can potentially allow attackers to delay the response, indicating the presence of an SQL injection vulnerability. While it is a time-based blind injection, it can be exploited to gain insights into the underlying database, and with further exploitation, sensitive data could be retrieved.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:H/U:Red" diff --git a/advisories/unreviewed/2025/02/GHSA-63xm-g6f5-3cw5/GHSA-63xm-g6f5-3cw5.json b/advisories/unreviewed/2025/02/GHSA-63xm-g6f5-3cw5/GHSA-63xm-g6f5-3cw5.json new file mode 100644 index 00000000000..4ca9884deea --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-63xm-g6f5-3cw5/GHSA-63xm-g6f5-3cw5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63xm-g6f5-3cw5", + "modified": "2025-02-26T00:32:20Z", + "published": "2025-02-26T00:32:20Z", + "aliases": [ + "CVE-2025-25516" + ], + "details": "Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25516" + }, + { + "type": "WEB", + "url": "https://github.com/Colorado-all/cve/blob/main/seacms/seacms%20V13.3-sql-2.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-c46r-j7hv-8f85/GHSA-c46r-j7hv-8f85.json b/advisories/unreviewed/2025/02/GHSA-c46r-j7hv-8f85/GHSA-c46r-j7hv-8f85.json new file mode 100644 index 00000000000..8e8eb354c8e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-c46r-j7hv-8f85/GHSA-c46r-j7hv-8f85.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c46r-j7hv-8f85", + "modified": "2025-02-26T00:32:21Z", + "published": "2025-02-26T00:32:21Z", + "aliases": [ + "CVE-2025-25521" + ], + "details": "Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25521" + }, + { + "type": "WEB", + "url": "https://github.com/Colorado-all/cve/blob/main/seacms/seacms%20V13.3-sql-3.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-c7c6-hp9w-4gmf/GHSA-c7c6-hp9w-4gmf.json b/advisories/unreviewed/2025/02/GHSA-c7c6-hp9w-4gmf/GHSA-c7c6-hp9w-4gmf.json new file mode 100644 index 00000000000..a78c5c2b668 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-c7c6-hp9w-4gmf/GHSA-c7c6-hp9w-4gmf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7c6-hp9w-4gmf", + "modified": "2025-02-26T00:32:20Z", + "published": "2025-02-26T00:32:20Z", + "aliases": [ + "CVE-2025-25520" + ], + "details": "Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25520" + }, + { + "type": "WEB", + "url": "https://github.com/Colorado-all/cve/blob/main/seacms/seacms%20V13.3-sql-4.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f6mr-g7jq-gx82/GHSA-f6mr-g7jq-gx82.json b/advisories/unreviewed/2025/02/GHSA-f6mr-g7jq-gx82/GHSA-f6mr-g7jq-gx82.json new file mode 100644 index 00000000000..12770fb46f9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f6mr-g7jq-gx82/GHSA-f6mr-g7jq-gx82.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6mr-g7jq-gx82", + "modified": "2025-02-26T00:32:19Z", + "published": "2025-02-26T00:32:19Z", + "aliases": [ + "CVE-2025-0514" + ], + "details": "Improper Input Validation vulnerability in The Document Foundation LibreOffice allows Windows Executable hyperlink targets to be executed unconditionally on activation.This issue affects LibreOffice: from 24.8 before < 24.8.5.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:L/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0514" + }, + { + "type": "WEB", + "url": "https://www.libreoffice.org/about-us/security/advisories/cve-2025-0514" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f754-m3x7-vr78/GHSA-f754-m3x7-vr78.json b/advisories/unreviewed/2025/02/GHSA-f754-m3x7-vr78/GHSA-f754-m3x7-vr78.json new file mode 100644 index 00000000000..f9aeb2c83d8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f754-m3x7-vr78/GHSA-f754-m3x7-vr78.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f754-m3x7-vr78", + "modified": "2025-02-26T00:32:20Z", + "published": "2025-02-26T00:32:20Z", + "aliases": [ + "CVE-2025-25515" + ], + "details": "Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25515" + }, + { + "type": "WEB", + "url": "https://github.com/Colorado-all/cve/blob/main/seacms/seacms%20V13.3-sql-5.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T22:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fvx6-jx94-49qx/GHSA-fvx6-jx94-49qx.json b/advisories/unreviewed/2025/02/GHSA-fvx6-jx94-49qx/GHSA-fvx6-jx94-49qx.json index a798ca87e0e..9e722601251 100644 --- a/advisories/unreviewed/2025/02/GHSA-fvx6-jx94-49qx/GHSA-fvx6-jx94-49qx.json +++ b/advisories/unreviewed/2025/02/GHSA-fvx6-jx94-49qx/GHSA-fvx6-jx94-49qx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fvx6-jx94-49qx", - "modified": "2025-02-25T21:31:40Z", + "modified": "2025-02-26T00:32:19Z", "published": "2025-02-25T06:30:52Z", "aliases": [ "CVE-2025-22210" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22210" }, + { + "type": "WEB", + "url": "https://github.com/AdamWallwork/CVEs/tree/main/2025/CVE-2025-22210" + }, { "type": "WEB", "url": "https://www.hikashop.com" diff --git a/advisories/unreviewed/2025/02/GHSA-g635-4v3q-xmrq/GHSA-g635-4v3q-xmrq.json b/advisories/unreviewed/2025/02/GHSA-g635-4v3q-xmrq/GHSA-g635-4v3q-xmrq.json new file mode 100644 index 00000000000..ca290c3ea62 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g635-4v3q-xmrq/GHSA-g635-4v3q-xmrq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g635-4v3q-xmrq", + "modified": "2025-02-26T00:32:20Z", + "published": "2025-02-26T00:32:20Z", + "aliases": [ + "CVE-2025-25517" + ], + "details": "Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25517" + }, + { + "type": "WEB", + "url": "https://github.com/Colorado-all/cve/blob/main/seacms/seacms%20V13.3-sql-7.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j5j2-54p5-7p3j/GHSA-j5j2-54p5-7p3j.json b/advisories/unreviewed/2025/02/GHSA-j5j2-54p5-7p3j/GHSA-j5j2-54p5-7p3j.json new file mode 100644 index 00000000000..80498d95a9e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-j5j2-54p5-7p3j/GHSA-j5j2-54p5-7p3j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5j2-54p5-7p3j", + "modified": "2025-02-26T00:32:21Z", + "published": "2025-02-26T00:32:21Z", + "aliases": [ + "CVE-2025-0760" + ], + "details": "A Credential Disclosure vulnerability exists where an administrator could extract the stored SMTP account credentials due to lack of encryption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0760" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/tns-2025-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T00:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mmcm-44xw-5gf8/GHSA-mmcm-44xw-5gf8.json b/advisories/unreviewed/2025/02/GHSA-mmcm-44xw-5gf8/GHSA-mmcm-44xw-5gf8.json new file mode 100644 index 00000000000..90a2496c860 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mmcm-44xw-5gf8/GHSA-mmcm-44xw-5gf8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmcm-44xw-5gf8", + "modified": "2025-02-26T00:32:21Z", + "published": "2025-02-26T00:32:21Z", + "aliases": [ + "CVE-2025-1091" + ], + "details": "A Broken Authorization schema exists where any authenticated user could download IOA script and configuration files if the URL is known.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1091" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/tns-2025-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T00:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-prcj-vvj7-6gm4/GHSA-prcj-vvj7-6gm4.json b/advisories/unreviewed/2025/02/GHSA-prcj-vvj7-6gm4/GHSA-prcj-vvj7-6gm4.json index 331c89885c7..5b921ad073a 100644 --- a/advisories/unreviewed/2025/02/GHSA-prcj-vvj7-6gm4/GHSA-prcj-vvj7-6gm4.json +++ b/advisories/unreviewed/2025/02/GHSA-prcj-vvj7-6gm4/GHSA-prcj-vvj7-6gm4.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-prcj-vvj7-6gm4", - "modified": "2025-02-19T09:33:29Z", + "modified": "2025-02-26T00:32:18Z", "published": "2025-02-19T09:33:29Z", "aliases": [ "CVE-2025-1024" ], "details": "A vulnerability exists in ChurchCRM 5.13.0 that allows an attacker to execute arbitrary JavaScript in a victim's browser via Reflected Cross-Site Scripting (XSS) in the EditEventAttendees.php page. This requires Administration privileges and affects the EID parameter. The flaw allows an attacker to steal session cookies, perform actions on behalf of an authenticated user, and gain unauthorized access to the application.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:L/U:Amber" @@ -26,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-rjgv-6mwj-prq2/GHSA-rjgv-6mwj-prq2.json b/advisories/unreviewed/2025/02/GHSA-rjgv-6mwj-prq2/GHSA-rjgv-6mwj-prq2.json new file mode 100644 index 00000000000..65300aa5259 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rjgv-6mwj-prq2/GHSA-rjgv-6mwj-prq2.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjgv-6mwj-prq2", + "modified": "2025-02-26T00:32:19Z", + "published": "2025-02-26T00:32:19Z", + "aliases": [ + "CVE-2025-22211" + ], + "details": "A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the country management area in backend.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22211" + }, + { + "type": "WEB", + "url": "https://www.webdesigner-profi.de" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rpm8-r6fr-56f4/GHSA-rpm8-r6fr-56f4.json b/advisories/unreviewed/2025/02/GHSA-rpm8-r6fr-56f4/GHSA-rpm8-r6fr-56f4.json new file mode 100644 index 00000000000..3c6ebb411d6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rpm8-r6fr-56f4/GHSA-rpm8-r6fr-56f4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpm8-r6fr-56f4", + "modified": "2025-02-26T00:32:21Z", + "published": "2025-02-26T00:32:21Z", + "aliases": [ + "CVE-2024-30150" + ], + "details": "HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure and potential for Server-Side Request Forgery (SSRF) and Denial of Service(DOS) attacks from unauthenticated users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30150" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0119368" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vhgx-6vv2-prcm/GHSA-vhgx-6vv2-prcm.json b/advisories/unreviewed/2025/02/GHSA-vhgx-6vv2-prcm/GHSA-vhgx-6vv2-prcm.json new file mode 100644 index 00000000000..c3cf6f7154e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vhgx-6vv2-prcm/GHSA-vhgx-6vv2-prcm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhgx-6vv2-prcm", + "modified": "2025-02-26T00:32:20Z", + "published": "2025-02-26T00:32:20Z", + "aliases": [ + "CVE-2025-25519" + ], + "details": "Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25519" + }, + { + "type": "WEB", + "url": "https://github.com/Colorado-all/cve/blob/main/seacms/seacms%20V13.3-sql-8.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xcx2-4699-rfv3/GHSA-xcx2-4699-rfv3.json b/advisories/unreviewed/2025/02/GHSA-xcx2-4699-rfv3/GHSA-xcx2-4699-rfv3.json new file mode 100644 index 00000000000..d2c49dde29b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xcx2-4699-rfv3/GHSA-xcx2-4699-rfv3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcx2-4699-rfv3", + "modified": "2025-02-26T00:32:19Z", + "published": "2025-02-26T00:32:19Z", + "aliases": [ + "CVE-2025-25514" + ], + "details": "Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25514" + }, + { + "type": "WEB", + "url": "https://github.com/Colorado-all/cve/blob/main/seacms/seacms%20V13.3-sql-6.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-25T22:15:23Z" + } +} \ No newline at end of file