From 527f01c31eb5312080c70dc34580361633cb22dc Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 1 Mar 2025 18:32:10 +0000 Subject: [PATCH] Publish Advisories GHSA-hj6q-qv48-rgmf GHSA-w96f-mfj2-5p98 --- .../GHSA-hj6q-qv48-rgmf.json | 56 +++++++++++++++++++ .../GHSA-w96f-mfj2-5p98.json | 52 +++++++++++++++++ 2 files changed, 108 insertions(+) create mode 100644 advisories/unreviewed/2025/03/GHSA-hj6q-qv48-rgmf/GHSA-hj6q-qv48-rgmf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w96f-mfj2-5p98/GHSA-w96f-mfj2-5p98.json diff --git a/advisories/unreviewed/2025/03/GHSA-hj6q-qv48-rgmf/GHSA-hj6q-qv48-rgmf.json b/advisories/unreviewed/2025/03/GHSA-hj6q-qv48-rgmf/GHSA-hj6q-qv48-rgmf.json new file mode 100644 index 00000000000..ed16c28e53b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hj6q-qv48-rgmf/GHSA-hj6q-qv48-rgmf.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj6q-qv48-rgmf", + "modified": "2025-03-01T18:30:40Z", + "published": "2025-03-01T18:30:40Z", + "aliases": [ + "CVE-2025-1800" + ], + "details": "A vulnerability has been found in D-Link DAR-7000 3.2 and classified as critical. This vulnerability affects the function get_ip_addr_details of the file /view/vpn/sxh_vpn/sxh_vpnlic.php of the component HTTP POST Request Handler. The manipulation of the argument ethname leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1800" + }, + { + "type": "WEB", + "url": "https://github.com/sjwszt/CVE/blob/main/CVE_1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298030" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298030" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.502971" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-01T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w96f-mfj2-5p98/GHSA-w96f-mfj2-5p98.json b/advisories/unreviewed/2025/03/GHSA-w96f-mfj2-5p98/GHSA-w96f-mfj2-5p98.json new file mode 100644 index 00000000000..51b959f2b0c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w96f-mfj2-5p98/GHSA-w96f-mfj2-5p98.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w96f-mfj2-5p98", + "modified": "2025-03-01T18:30:40Z", + "published": "2025-03-01T18:30:39Z", + "aliases": [ + "CVE-2025-1799" + ], + "details": "A vulnerability, which was classified as critical, was found in Zorlan SkyCaiji 2.9. This affects the function previewAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation of the argument data leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1799" + }, + { + "type": "WEB", + "url": "https://github.com/sheratan4/cve/issues/6" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298029" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298029" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.502650" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-01T18:15:34Z" + } +} \ No newline at end of file