Publish Advisories

GHSA-9j78-3xph-pxmf
GHSA-cp87-ch4g-957j
GHSA-cv9w-4qgc-5w82
GHSA-x8q6-cchr-p7m6
This commit is contained in:
advisory-database[bot]
2025-02-23 15:32:24 +00:00
parent b94a5b27a3
commit 4464330e5f
4 changed files with 228 additions and 0 deletions
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9j78-3xph-pxmf",
"modified": "2025-02-23T15:30:58Z",
"published": "2025-02-23T15:30:58Z",
"aliases": [
"CVE-2025-1586"
],
"details": "A vulnerability was found in code-projects Blood Bank System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /Blood/A-.php. The manipulation of the argument Bloodname leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1586"
},
{
"type": "WEB",
"url": "https://code-projects.org"
},
{
"type": "WEB",
"url": "https://github.com/1337g/bloodbanksystem_poc/blob/main/xss-gu(1).pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.296566"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.296566"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.505124"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-23T15:15:09Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cp87-ch4g-957j",
"modified": "2025-02-23T15:30:58Z",
"published": "2025-02-23T15:30:58Z",
"aliases": [
"CVE-2025-1587"
],
"details": "A vulnerability was found in SourceCodester Telecom Billing Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file main.cpp of the component Add New Record. The manipulation of the argument name leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1587"
},
{
"type": "WEB",
"url": "https://github.com/wshRE/CVE/issues/1"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.296567"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.296567"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.505363"
},
{
"type": "WEB",
"url": "https://www.sourcecodester.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-23T15:15:10Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cv9w-4qgc-5w82",
"modified": "2025-02-23T15:30:58Z",
"published": "2025-02-23T15:30:58Z",
"aliases": [
"CVE-2025-1585"
],
"details": "A vulnerability, which was classified as problematic, has been found in otale tale up to 2.0.5. This issue affects the function OptionsService of the file src/main/resources/templates/themes/default/partial/header.html. The manipulation of the argument logo_url leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1585"
},
{
"type": "WEB",
"url": "https://github.com/dragonkeep/cve/blob/main/Tale_Blog_xss.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.296561"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.296561"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.504937"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-23T14:15:09Z"
}
}
@@ -0,0 +1,64 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x8q6-cchr-p7m6",
"modified": "2025-02-23T15:30:58Z",
"published": "2025-02-23T15:30:58Z",
"aliases": [
"CVE-2025-1584"
],
"details": "A vulnerability classified as problematic was found in opensolon Solon up to 3.0.8. This vulnerability affects unknown code of the file solon-projects/solon-web/solon-web-staticfiles/src/main/java/org/noear/solon/web/staticfiles/StaticMappings.java. The manipulation leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.0.9 is able to address this issue. The name of the patch is f46e47fd1f8455b9467d7ead3cdb0509115b2ef1. It is recommended to upgrade the affected component.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1584"
},
{
"type": "WEB",
"url": "https://github.com/opensolon/solon/issues/332"
},
{
"type": "WEB",
"url": "https://github.com/opensolon/solon/issues/332#issue-2866229828"
},
{
"type": "WEB",
"url": "https://github.com/opensolon/solon/issues/332#issuecomment-2674330700"
},
{
"type": "WEB",
"url": "https://github.com/opensolon/solon/commit/f46e47fd1f8455b9467d7ead3cdb0509115b2ef1"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.296560"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.296560"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.504454"
}
],
"database_specific": {
"cwe_ids": [
"CWE-23"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-23T13:15:09Z"
}
}