From 4d161ed903e287004a39707881adbb487691dbcb Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 24 Mar 2025 09:35:35 +0000 Subject: [PATCH] Publish Advisories GHSA-3vww-r7vf-jj85 GHSA-4f2v-2gpq-qhjg GHSA-4xp6-5525-gxpx GHSA-88m2-j94x-v4fx GHSA-97q7-cqc5-x5gj GHSA-gh82-hcx7-wmwv --- .../GHSA-3vww-r7vf-jj85.json | 52 +++++++++++++++++ .../GHSA-4f2v-2gpq-qhjg.json | 52 +++++++++++++++++ .../GHSA-4xp6-5525-gxpx.json | 56 +++++++++++++++++++ .../GHSA-88m2-j94x-v4fx.json | 52 +++++++++++++++++ .../GHSA-97q7-cqc5-x5gj.json | 52 +++++++++++++++++ .../GHSA-gh82-hcx7-wmwv.json | 52 +++++++++++++++++ 6 files changed, 316 insertions(+) create mode 100644 advisories/unreviewed/2025/03/GHSA-3vww-r7vf-jj85/GHSA-3vww-r7vf-jj85.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4f2v-2gpq-qhjg/GHSA-4f2v-2gpq-qhjg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4xp6-5525-gxpx/GHSA-4xp6-5525-gxpx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-88m2-j94x-v4fx/GHSA-88m2-j94x-v4fx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-97q7-cqc5-x5gj/GHSA-97q7-cqc5-x5gj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gh82-hcx7-wmwv/GHSA-gh82-hcx7-wmwv.json diff --git a/advisories/unreviewed/2025/03/GHSA-3vww-r7vf-jj85/GHSA-3vww-r7vf-jj85.json b/advisories/unreviewed/2025/03/GHSA-3vww-r7vf-jj85/GHSA-3vww-r7vf-jj85.json new file mode 100644 index 00000000000..dde06ea0647 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3vww-r7vf-jj85/GHSA-3vww-r7vf-jj85.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vww-r7vf-jj85", + "modified": "2025-03-24T09:34:03Z", + "published": "2025-03-24T09:34:03Z", + "aliases": [ + "CVE-2025-2700" + ], + "details": "A vulnerability classified as problematic has been found in michelson Dante Editor up to 0.4.4. This affects an unknown part of the component Insert Link Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2700" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Masamuneee/3be24bf5bf2b09dc61ead2af89363f86" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300717" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300717" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.515869" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T09:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4f2v-2gpq-qhjg/GHSA-4f2v-2gpq-qhjg.json b/advisories/unreviewed/2025/03/GHSA-4f2v-2gpq-qhjg/GHSA-4f2v-2gpq-qhjg.json new file mode 100644 index 00000000000..add36442936 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4f2v-2gpq-qhjg/GHSA-4f2v-2gpq-qhjg.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f2v-2gpq-qhjg", + "modified": "2025-03-24T09:34:03Z", + "published": "2025-03-24T09:34:03Z", + "aliases": [ + "CVE-2025-2699" + ], + "details": "A vulnerability was found in GetmeUK ContentTools up to 1.6.16. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Image Handler. The manipulation of the argument onload leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2699" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Masamuneee/657f2e2b0eb5bf9b0d4dbb79f00dac37" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300716" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300716" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.515864" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T08:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4xp6-5525-gxpx/GHSA-4xp6-5525-gxpx.json b/advisories/unreviewed/2025/03/GHSA-4xp6-5525-gxpx/GHSA-4xp6-5525-gxpx.json new file mode 100644 index 00000000000..6d63097899e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4xp6-5525-gxpx/GHSA-4xp6-5525-gxpx.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xp6-5525-gxpx", + "modified": "2025-03-24T09:34:03Z", + "published": "2025-03-24T09:34:03Z", + "aliases": [ + "CVE-2025-2688" + ], + "details": "A vulnerability classified as problematic was found in TOTOLINK A3000RU up to 5.9c.5185. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ExportSyslog.sh of the component Syslog Configuration File Handler. The manipulation leads to improper access controls. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2688" + }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/TOTOLINK-A3000RU-ExportSyslog-1b953a41781f8064970dc7809a52ac6c?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300709" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300709" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.521570" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T07:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-88m2-j94x-v4fx/GHSA-88m2-j94x-v4fx.json b/advisories/unreviewed/2025/03/GHSA-88m2-j94x-v4fx/GHSA-88m2-j94x-v4fx.json new file mode 100644 index 00000000000..09e7d6445f8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-88m2-j94x-v4fx/GHSA-88m2-j94x-v4fx.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88m2-j94x-v4fx", + "modified": "2025-03-24T09:34:03Z", + "published": "2025-03-24T09:34:03Z", + "aliases": [ + "CVE-2025-2689" + ], + "details": "A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of the file symfony\\finder\\Iterator\\SortableIterator.php. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2689" + }, + { + "type": "WEB", + "url": "https://github.com/gaorenyusi/gaorenyusi/blob/main/Yii2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300710" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300710" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.521709" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T07:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-97q7-cqc5-x5gj/GHSA-97q7-cqc5-x5gj.json b/advisories/unreviewed/2025/03/GHSA-97q7-cqc5-x5gj/GHSA-97q7-cqc5-x5gj.json new file mode 100644 index 00000000000..110cda021d0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-97q7-cqc5-x5gj/GHSA-97q7-cqc5-x5gj.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97q7-cqc5-x5gj", + "modified": "2025-03-24T09:34:03Z", + "published": "2025-03-24T09:34:02Z", + "aliases": [ + "CVE-2025-2690" + ], + "details": "A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This affects the function Generate of the file phpunit\\src\\Framework\\MockObject\\MockClass.php. The manipulation leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2690" + }, + { + "type": "WEB", + "url": "https://github.com/gaorenyusi/gaorenyusi/blob/main/Yii2-2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300711" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300711" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.521718" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T08:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gh82-hcx7-wmwv/GHSA-gh82-hcx7-wmwv.json b/advisories/unreviewed/2025/03/GHSA-gh82-hcx7-wmwv/GHSA-gh82-hcx7-wmwv.json new file mode 100644 index 00000000000..4fb2dd581d6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gh82-hcx7-wmwv/GHSA-gh82-hcx7-wmwv.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh82-hcx7-wmwv", + "modified": "2025-03-24T09:34:03Z", + "published": "2025-03-24T09:34:03Z", + "aliases": [ + "CVE-2025-2701" + ], + "details": "A vulnerability classified as critical was found in AMTT Hotel Broadband Operation System 1.0. This vulnerability affects the function popen of the file /manager/network/port_setup.php. The manipulation of the argument SwitchVersion/SwitchWrite/SwitchIP/SwitchIndex/SwitchState leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2701" + }, + { + "type": "WEB", + "url": "https://github.com/zian10001/cve/blob/main/rce.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300718" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300718" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.516089" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T09:15:13Z" + } +} \ No newline at end of file