From 54a8a1da8dfba247a6b2c4f84eefbcd7099620e9 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 7 Jun 2025 18:34:45 +0000 Subject: [PATCH] Publish Advisories GHSA-4p69-rxmq-26c6 GHSA-7mq3-mm79-g2xj GHSA-xpmp-hffj-q43q --- .../GHSA-4p69-rxmq-26c6.json | 56 +++++++++++++++++++ .../GHSA-7mq3-mm79-g2xj.json | 56 +++++++++++++++++++ .../GHSA-xpmp-hffj-q43q.json | 56 +++++++++++++++++++ 3 files changed, 168 insertions(+) create mode 100644 advisories/unreviewed/2025/06/GHSA-4p69-rxmq-26c6/GHSA-4p69-rxmq-26c6.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7mq3-mm79-g2xj/GHSA-7mq3-mm79-g2xj.json create mode 100644 advisories/unreviewed/2025/06/GHSA-xpmp-hffj-q43q/GHSA-xpmp-hffj-q43q.json diff --git a/advisories/unreviewed/2025/06/GHSA-4p69-rxmq-26c6/GHSA-4p69-rxmq-26c6.json b/advisories/unreviewed/2025/06/GHSA-4p69-rxmq-26c6/GHSA-4p69-rxmq-26c6.json new file mode 100644 index 00000000000..e983a5f07d8 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4p69-rxmq-26c6/GHSA-4p69-rxmq-26c6.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p69-rxmq-26c6", + "modified": "2025-06-07T18:33:10Z", + "published": "2025-06-07T18:33:10Z", + "aliases": [ + "CVE-2025-5840" + ], + "details": "A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_update_customer_order.php. The manipulation of the argument uploaded_file leads to unrestricted upload. It is possible to initiate the attack remotely.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5840" + }, + { + "type": "WEB", + "url": "https://github.com/592833263/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311583" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311583" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.591425" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-07T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7mq3-mm79-g2xj/GHSA-7mq3-mm79-g2xj.json b/advisories/unreviewed/2025/06/GHSA-7mq3-mm79-g2xj/GHSA-7mq3-mm79-g2xj.json new file mode 100644 index 00000000000..3a01402777d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7mq3-mm79-g2xj/GHSA-7mq3-mm79-g2xj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mq3-mm79-g2xj", + "modified": "2025-06-07T18:33:10Z", + "published": "2025-06-07T18:33:10Z", + "aliases": [ + "CVE-2025-5838" + ], + "details": "A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. Affected by this vulnerability is an unknown functionality of the file /admin/adminprofile.php. The manipulation of the argument AdminName leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5838" + }, + { + "type": "WEB", + "url": "https://github.com/f1rstb100d/myCVE/issues/62" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311581" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311581" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.591365" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-07T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-xpmp-hffj-q43q/GHSA-xpmp-hffj-q43q.json b/advisories/unreviewed/2025/06/GHSA-xpmp-hffj-q43q/GHSA-xpmp-hffj-q43q.json new file mode 100644 index 00000000000..cefff22b404 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-xpmp-hffj-q43q/GHSA-xpmp-hffj-q43q.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpmp-hffj-q43q", + "modified": "2025-06-07T18:33:10Z", + "published": "2025-06-07T18:33:10Z", + "aliases": [ + "CVE-2025-5839" + ], + "details": "A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected by this issue is the function fromadvsetlanip of the file /goform/AdvSetLanip of the component POST Request Handler. The manipulation of the argument lanMask leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5839" + }, + { + "type": "WEB", + "url": "https://candle-throne-f75.notion.site/Tenda-AC9-fromadvsetlanip-20adf0aa11858027b7c3c2f4e44bb867" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311582" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311582" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.591369" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-07T18:15:25Z" + } +} \ No newline at end of file