diff --git a/advisories/unreviewed/2025/03/GHSA-hj6q-qv48-rgmf/GHSA-hj6q-qv48-rgmf.json b/advisories/unreviewed/2025/03/GHSA-hj6q-qv48-rgmf/GHSA-hj6q-qv48-rgmf.json new file mode 100644 index 00000000000..ed16c28e53b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hj6q-qv48-rgmf/GHSA-hj6q-qv48-rgmf.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj6q-qv48-rgmf", + "modified": "2025-03-01T18:30:40Z", + "published": "2025-03-01T18:30:40Z", + "aliases": [ + "CVE-2025-1800" + ], + "details": "A vulnerability has been found in D-Link DAR-7000 3.2 and classified as critical. This vulnerability affects the function get_ip_addr_details of the file /view/vpn/sxh_vpn/sxh_vpnlic.php of the component HTTP POST Request Handler. The manipulation of the argument ethname leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1800" + }, + { + "type": "WEB", + "url": "https://github.com/sjwszt/CVE/blob/main/CVE_1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298030" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298030" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.502971" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-01T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w96f-mfj2-5p98/GHSA-w96f-mfj2-5p98.json b/advisories/unreviewed/2025/03/GHSA-w96f-mfj2-5p98/GHSA-w96f-mfj2-5p98.json new file mode 100644 index 00000000000..51b959f2b0c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w96f-mfj2-5p98/GHSA-w96f-mfj2-5p98.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w96f-mfj2-5p98", + "modified": "2025-03-01T18:30:40Z", + "published": "2025-03-01T18:30:39Z", + "aliases": [ + "CVE-2025-1799" + ], + "details": "A vulnerability, which was classified as critical, was found in Zorlan SkyCaiji 2.9. This affects the function previewAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation of the argument data leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1799" + }, + { + "type": "WEB", + "url": "https://github.com/sheratan4/cve/issues/6" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298029" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298029" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.502650" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-01T18:15:34Z" + } +} \ No newline at end of file