Publish Advisories

GHSA-3q2g-cq44-pjqq
GHSA-4xfg-8977-37fx
GHSA-f3ff-gxqf-prhc
GHSA-x43h-8pfv-xx24
This commit is contained in:
advisory-database[bot]
2025-03-18 09:33:22 +00:00
parent 80f50ce97d
commit 3451f8ab5d
4 changed files with 168 additions and 0 deletions
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3q2g-cq44-pjqq",
"modified": "2025-03-18T09:31:49Z",
"published": "2025-03-18T09:31:49Z",
"aliases": [
"CVE-2025-2262"
],
"details": "The The Logo Slider Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.7.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2262"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/gs-logo-slider/trunk/includes/shortcode-builder/builder.php#L31"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/gs-logo-slider/trunk/includes/shortcode-builder/builder.php#L51"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/gs-logo-slider/trunk/includes/shortcode-builder/builder.php#L65"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3256441"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3c7cc2d2-8de4-453b-b4dc-48f75b151078?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-18T07:15:33Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4xfg-8977-37fx",
"modified": "2025-03-18T09:31:49Z",
"published": "2025-03-18T09:31:49Z",
"aliases": [
"CVE-2025-25220"
],
"details": "Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.1_1101. If this vulnerability is exploited, an arbitrary OS command may be executed by a remote authenticated attacker.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25220"
},
{
"type": "WEB",
"url": "https://fsi-plusf.jp/news/25031701.html"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN11230428"
}
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-18T09:15:13Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f3ff-gxqf-prhc",
"modified": "2025-03-18T09:31:49Z",
"published": "2025-03-18T09:31:49Z",
"aliases": [
"CVE-2025-24306"
],
"details": "Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.0_1101. If this vulnerability is exploited, an arbitrary OS command may be executed by a remote authenticated attacker with an administrative privilege.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24306"
},
{
"type": "WEB",
"url": "https://fsi-plusf.jp/news/25031701.html"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN11230428"
}
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-18T09:15:13Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x43h-8pfv-xx24",
"modified": "2025-03-18T09:31:49Z",
"published": "2025-03-18T09:31:49Z",
"aliases": [
"CVE-2025-0755"
],
"details": "The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result in a final BSON document which exceeds the maximum allowable size (INT32_MAX), resulting in a segmentation fault and possible application crash. This issue affected libbson versions prior to 1.27.5, MongoDB Server v8.0 versions prior to 8.0.1 and MongoDB Server v7.0 versions prior to 7.0.16",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0755"
},
{
"type": "WEB",
"url": "https://jira.mongodb.org/browse/SERVER-94461"
}
],
"database_specific": {
"cwe_ids": [
"CWE-122"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-18T09:15:11Z"
}
}