Publish Advisories

GHSA-4hg3-3xxj-v749
GHSA-4r48-rxwv-p6qh
GHSA-5fww-m73j-6p23
GHSA-fxw9-g6g5-mfqx
GHSA-ppcr-7c68-6c88
This commit is contained in:
advisory-database[bot]
2025-03-22 00:32:36 +00:00
parent f29b5de977
commit 47ac18410a
5 changed files with 185 additions and 1 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4hg3-3xxj-v749",
"modified": "2025-03-17T06:30:25Z",
"modified": "2025-03-22T00:31:11Z",
"published": "2025-03-17T06:30:25Z",
"aliases": [
"CVE-2025-2361"
@@ -34,6 +34,10 @@
{
"type": "WEB",
"url": "https://vuldb.com/?submit.514024"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/03/21/2"
}
],
"database_specific": {
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4r48-rxwv-p6qh",
"modified": "2025-03-22T00:31:11Z",
"published": "2025-03-22T00:31:11Z",
"aliases": [
"CVE-2025-2608"
],
"details": "A vulnerability classified as critical has been found in PHPGurukul Banquet Booking System 1.2. This affects an unknown part of the file /admin/view-user-queries.php. The manipulation of the argument viewid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2608"
},
{
"type": "WEB",
"url": "https://github.com/emano888/cve/issues/1"
},
{
"type": "WEB",
"url": "https://phpgurukul.com"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.300591"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.300591"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.518587"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-21T22:15:26Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5fww-m73j-6p23",
"modified": "2025-03-22T00:31:11Z",
"published": "2025-03-22T00:31:11Z",
"aliases": [
"CVE-2025-2610"
],
"details": "Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protected/components/MagnusLog.Php.\n\nThis issue affects MagnusBilling: through 7.3.0.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2610"
},
{
"type": "WEB",
"url": "https://github.com/magnussolution/magnusbilling7/commit/f0f083c76157e31149ae58342342fb1bf1629e22"
},
{
"type": "WEB",
"url": "https://chocapikk.com/posts/2025/magnusbilling"
},
{
"type": "WEB",
"url": "https://vulncheck.com/advisories/magnusbilling-alarm-xss"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-21T23:15:21Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fxw9-g6g5-mfqx",
"modified": "2025-03-22T00:31:11Z",
"published": "2025-03-22T00:31:11Z",
"aliases": [
"CVE-2025-2609"
],
"details": "Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read\" cross-site scripting This vulnerability is associated with program files protected/components/MagnusLog.Php.\n\nThis issue affects MagnusBilling: through 7.3.0.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2609"
},
{
"type": "WEB",
"url": "https://github.com/magnussolution/magnusbilling7/commit/f0f083c76157e31149ae58342342fb1bf1629e22"
},
{
"type": "WEB",
"url": "https://chocapikk.com/posts/2025/magnusbilling"
},
{
"type": "WEB",
"url": "https://vulncheck.com/advisories/magnusbilling-logs-xss"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-21T23:15:21Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ppcr-7c68-6c88",
"modified": "2025-03-22T00:31:11Z",
"published": "2025-03-22T00:31:11Z",
"aliases": [
"CVE-2025-26500"
],
"details": ": Uncontrolled Resource Consumption vulnerability in Wind River Systems VxWorks 7 on VxWorks allows Excessive Allocation.  \n\nSpecifically crafted USB packets may lead to the system becoming unavailable\n\nThis issue affects VxWorks 7: from 22.06 through 24.03.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26500"
},
{
"type": "WEB",
"url": "https://support2.windriver.com/index.php?page=cve&on=view&id=CVE-2025-26500"
}
],
"database_specific": {
"cwe_ids": [
"CWE-400"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-21T23:15:21Z"
}
}