Publish Advisories

GHSA-2h27-gcg3-7h2g
GHSA-9v5v-3jhc-pffj
GHSA-hf2c-qrvg-6988
GHSA-m7gm-v253-56hh
This commit is contained in:
advisory-database[bot]
2025-05-11 03:32:00 +00:00
parent b08202fa51
commit 3ec9682fe8
4 changed files with 184 additions and 0 deletions
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2h27-gcg3-7h2g",
"modified": "2025-05-11T03:30:28Z",
"published": "2025-05-11T03:30:28Z",
"aliases": [
"CVE-2025-4527"
],
"details": "A vulnerability has been found in Dígitro NGC Explorer 3.44.15 and classified as problematic. This vulnerability affects unknown code of the component Password Transmission Handler. The manipulation leads to client-side enforcement of server-side security. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4527"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.308272"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.308272"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.565308"
}
],
"database_specific": {
"cwe_ids": [
"CWE-602"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-11T03:15:24Z"
}
}
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9v5v-3jhc-pffj",
"modified": "2025-05-11T03:30:28Z",
"published": "2025-05-11T03:30:28Z",
"aliases": [
"CVE-2025-4528"
],
"details": "A vulnerability was found in Dígitro NGC Explorer up to 3.44.15 and classified as problematic. This issue affects some unknown processing. The manipulation leads to session expiration. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4528"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.308273"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.308273"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.565309"
}
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-11T03:15:24Z"
}
}
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hf2c-qrvg-6988",
"modified": "2025-05-11T03:30:27Z",
"published": "2025-05-11T03:30:27Z",
"aliases": [
"CVE-2025-4526"
],
"details": "A vulnerability, which was classified as problematic, was found in Dígitro NGC Explorer 3.44.15. This affects an unknown part of the component Configuration Page. The manipulation leads to missing password field masking. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4526"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.308271"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.308271"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.565307"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-11T01:15:52Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m7gm-v253-56hh",
"modified": "2025-05-11T03:30:28Z",
"published": "2025-05-11T03:30:28Z",
"aliases": [
"CVE-2025-47828"
],
"details": "Lumi H5P-Nodejs-library before 9.3.3 omits a sanitizeHtml call for plain text strings.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47828"
},
{
"type": "WEB",
"url": "https://github.com/Lumieducation/H5P-Nodejs-library/pull/3894"
},
{
"type": "WEB",
"url": "https://github.com/Lumieducation/H5P-Nodejs-library/compare/v9.3.2...v9.3.3"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-11T03:15:23Z"
}
}