Publish Advisories

GHSA-8cv2-v24w-8j7h
GHSA-9879-4r59-96j2
GHSA-c57h-rx24-vf52
GHSA-cqmw-qrqr-v255
GHSA-g3qr-3fvc-4fm6
GHSA-h236-32wj-mg7x
GHSA-h7vp-w2vp-6c97
This commit is contained in:
advisory-database[bot]
2025-04-05 21:32:19 +00:00
parent 3bc8a2027a
commit 5634a02437
7 changed files with 256 additions and 1 deletions
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8cv2-v24w-8j7h",
"modified": "2025-04-05T21:30:23Z",
"published": "2025-04-05T21:30:23Z",
"aliases": [
"CVE-2025-3303"
],
"details": "A vulnerability, which was classified as critical, has been found in code-projects Patient Record Management System 1.0. Affected by this issue is some unknown functionality of the file /birthing_record.php. The manipulation of the argument itr_no leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3303"
},
{
"type": "WEB",
"url": "https://code-projects.org"
},
{
"type": "WEB",
"url": "https://github.com/hyfhacker/cve/blob/main/README.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.303500"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.303500"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.549644"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-05T21:15:40Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9879-4r59-96j2",
"modified": "2025-04-05T21:30:23Z",
"published": "2025-04-05T21:30:22Z",
"aliases": [
"CVE-2025-32357"
],
"details": "In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that they have no permission for.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32357"
},
{
"type": "WEB",
"url": "https://zammad.com/en/advisories/zaa-2025-04"
}
],
"database_specific": {
"cwe_ids": [
"CWE-288"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-05T21:15:39Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c57h-rx24-vf52",
"modified": "2025-04-05T06:30:19Z",
"modified": "2025-04-05T21:30:22Z",
"published": "2025-04-03T21:32:59Z",
"aliases": [
"CVE-2025-31161"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31161"
},
{
"type": "WEB",
"url": "https://attackerkb.com/topics/k0EgiL9Psz/cve-2025-2825/rapid7-analysis"
},
{
"type": "WEB",
"url": "https://crushftp.com/crush11wiki/Wiki.jsp?page=Update#section-Update-VulnerabilityInfo"
@@ -38,6 +42,10 @@
{
"type": "WEB",
"url": "https://www.huntress.com/blog/crushftp-cve-2025-31161-auth-bypass-and-post-exploitation"
},
{
"type": "WEB",
"url": "https://www.infosecurity-magazine.com/news/crushftp-flaw-exploited-disclosure"
}
],
"database_specific": {
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cqmw-qrqr-v255",
"modified": "2025-04-05T21:30:23Z",
"published": "2025-04-05T21:30:23Z",
"aliases": [
"CVE-2025-32360"
],
"details": "In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and work on shared article drafts. However, a logged in customer was able to see details about shared drafts for their customer tickets in the browser console, which may contain confidential information, and also to manipulate them via API.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32360"
},
{
"type": "WEB",
"url": "https://zammad.com/en/advisories/zaa-2025-03"
}
],
"database_specific": {
"cwe_ids": [
"CWE-402"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-05T21:15:40Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g3qr-3fvc-4fm6",
"modified": "2025-04-05T21:30:23Z",
"published": "2025-04-05T21:30:23Z",
"aliases": [
"CVE-2025-32359"
],
"details": "In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor authentication configuration, users need to re-authenticate with their current password first. However, this change was enforced in Zammad only on the front end level, and not when using the API directly.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32359"
},
{
"type": "WEB",
"url": "https://zammad.com/en/advisories/zaa-2025-02"
}
],
"database_specific": {
"cwe_ids": [
"CWE-602"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-05T21:15:40Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h236-32wj-mg7x",
"modified": "2025-04-05T21:30:22Z",
"published": "2025-04-05T21:30:22Z",
"aliases": [
"CVE-2024-56370"
],
"details": "Net::Xero 0.044 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions.\n\nSpecifically Net::Xero uses the Data::Random library which specifically states that it is \"Useful mostly for test programs\". Data::Random uses the rand() function.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56370"
},
{
"type": "WEB",
"url": "https://metacpan.org/release/BAREFOOT/Data-Random-0.13/source/lib/Data/Random.pm#L537"
},
{
"type": "WEB",
"url": "https://metacpan.org/release/ELLIOTT/Net-Xero-0.44/source/lib/Net/Xero.pm#L58"
},
{
"type": "WEB",
"url": "https://metacpan.org/release/ELLIOTT/Net-Xero-0.44/source/lib/Net/Xero.pm#L9"
},
{
"type": "WEB",
"url": "https://perldoc.perl.org/functions/rand"
},
{
"type": "WEB",
"url": "https://security.metacpan.org/docs/guides/random-data-for-security.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-338"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-05T19:15:38Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h7vp-w2vp-6c97",
"modified": "2025-04-05T21:30:22Z",
"published": "2025-04-05T21:30:22Z",
"aliases": [
"CVE-2025-32358"
],
"details": "In Zammad 6.4.x before 6.4.2, SSRF can occur. Authenticated admin users can enable webhooks in Zammad, which are triggered as POST requests when certain conditions are met. If a webhook endpoint returned a redirect response, Zammad would follow it automatically with another GET request. This could be abused by an attacker to cause GET requests for example in the local network.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32358"
},
{
"type": "WEB",
"url": "https://zammad.com/en/advisories/zaa-2025-01"
}
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-05T21:15:40Z"
}
}