From 56abaa8ce8698829c3dd9d69d467f59ee5501d9d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 15 Feb 2025 09:31:58 +0000 Subject: [PATCH] Publish Advisories GHSA-6j8j-86h8-528v GHSA-9v7f-8fcp-rxqx GHSA-g6w7-7678-67j9 GHSA-m4pp-r8qf-wcpc GHSA-r4hg-45fp-r477 GHSA-v48v-77qp-6x97 --- .../GHSA-6j8j-86h8-528v.json | 31 +++++++++++ .../GHSA-9v7f-8fcp-rxqx.json | 31 +++++++++++ .../GHSA-g6w7-7678-67j9.json | 52 +++++++++++++++++++ .../GHSA-m4pp-r8qf-wcpc.json | 48 +++++++++++++++++ .../GHSA-r4hg-45fp-r477.json | 44 ++++++++++++++++ .../GHSA-v48v-77qp-6x97.json | 44 ++++++++++++++++ 6 files changed, 250 insertions(+) create mode 100644 advisories/unreviewed/2025/02/GHSA-6j8j-86h8-528v/GHSA-6j8j-86h8-528v.json create mode 100644 advisories/unreviewed/2025/02/GHSA-9v7f-8fcp-rxqx/GHSA-9v7f-8fcp-rxqx.json create mode 100644 advisories/unreviewed/2025/02/GHSA-g6w7-7678-67j9/GHSA-g6w7-7678-67j9.json create mode 100644 advisories/unreviewed/2025/02/GHSA-m4pp-r8qf-wcpc/GHSA-m4pp-r8qf-wcpc.json create mode 100644 advisories/unreviewed/2025/02/GHSA-r4hg-45fp-r477/GHSA-r4hg-45fp-r477.json create mode 100644 advisories/unreviewed/2025/02/GHSA-v48v-77qp-6x97/GHSA-v48v-77qp-6x97.json diff --git a/advisories/unreviewed/2025/02/GHSA-6j8j-86h8-528v/GHSA-6j8j-86h8-528v.json b/advisories/unreviewed/2025/02/GHSA-6j8j-86h8-528v/GHSA-6j8j-86h8-528v.json new file mode 100644 index 00000000000..34fdbb781dd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6j8j-86h8-528v/GHSA-6j8j-86h8-528v.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j8j-86h8-528v", + "modified": "2025-02-15T09:30:29Z", + "published": "2025-02-15T09:30:29Z", + "aliases": [ + "CVE-2025-22208" + ], + "details": "A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'filter_email' parameter in the GDPR Erase Data Request search feature.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22208" + }, + { + "type": "WEB", + "url": "https://joomsky.com/js-jobs-joomla" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-15T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9v7f-8fcp-rxqx/GHSA-9v7f-8fcp-rxqx.json b/advisories/unreviewed/2025/02/GHSA-9v7f-8fcp-rxqx/GHSA-9v7f-8fcp-rxqx.json new file mode 100644 index 00000000000..a188952b339 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9v7f-8fcp-rxqx/GHSA-9v7f-8fcp-rxqx.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v7f-8fcp-rxqx", + "modified": "2025-02-15T09:30:29Z", + "published": "2025-02-15T09:30:29Z", + "aliases": [ + "CVE-2025-22209" + ], + "details": "A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'searchpaymentstatus' parameter in the Employer Payment History search feature.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22209" + }, + { + "type": "WEB", + "url": "https://joomsky.com/js-jobs-joomla" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-15T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g6w7-7678-67j9/GHSA-g6w7-7678-67j9.json b/advisories/unreviewed/2025/02/GHSA-g6w7-7678-67j9/GHSA-g6w7-7678-67j9.json new file mode 100644 index 00000000000..65108db2221 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g6w7-7678-67j9/GHSA-g6w7-7678-67j9.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6w7-7678-67j9", + "modified": "2025-02-15T09:30:29Z", + "published": "2025-02-15T09:30:29Z", + "aliases": [ + "CVE-2025-0935" + ], + "details": "The Media Library Folders plugin for WordPress is vulnerable to unauthorized plugin settings change due to a missing capability check on several AJAX actions in all versions up to, and including, 8.3.0. This makes it possible for authenticated attackers, with Author-level access and above, to change plugin settings related to things such as IP-blocking.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0935" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/media-library-plus/trunk/media-library-plus.php#L6296" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/media-library-plus/trunk/media-library-plus.php#L697" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/media-library-plus/trunk/media-library-plus.php#L7198" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3234676/media-library-plus/trunk/media-library-plus.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6f810102-cf25-4898-a3a6-3cdc9a96aaea?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-15T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m4pp-r8qf-wcpc/GHSA-m4pp-r8qf-wcpc.json b/advisories/unreviewed/2025/02/GHSA-m4pp-r8qf-wcpc/GHSA-m4pp-r8qf-wcpc.json new file mode 100644 index 00000000000..3deb6cf195b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m4pp-r8qf-wcpc/GHSA-m4pp-r8qf-wcpc.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4pp-r8qf-wcpc", + "modified": "2025-02-15T09:30:28Z", + "published": "2025-02-15T09:30:28Z", + "aliases": [ + "CVE-2024-13563" + ], + "details": "The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's forgot-password shortcode in all versions up to, and including, 3.2.30 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13563" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/front-end-only-users/trunk/Shortcodes/Insert_Forgot_Password.php#L61" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3240349" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/front-end-only-users" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/51f3497f-c599-4d47-bd5a-94e1679a0025?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-15T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r4hg-45fp-r477/GHSA-r4hg-45fp-r477.json b/advisories/unreviewed/2025/02/GHSA-r4hg-45fp-r477/GHSA-r4hg-45fp-r477.json new file mode 100644 index 00000000000..2a3fafb23bf --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r4hg-45fp-r477/GHSA-r4hg-45fp-r477.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4hg-45fp-r477", + "modified": "2025-02-15T09:30:28Z", + "published": "2025-02-15T09:30:28Z", + "aliases": [ + "CVE-2024-13525" + ], + "details": "The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via Shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including emails as well as hashed passwords of any user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13525" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/emails-verification-for-woocommerce/tags/2.9.2/includes/class-alg-wc-ev-core.php#L990" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3232261%40emails-verification-for-woocommerce%2Ftrunk&old=3230854%40emails-verification-for-woocommerce%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a63a41d1-b9b0-43a9-a6e0-761f3b8d9d4a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-15T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v48v-77qp-6x97/GHSA-v48v-77qp-6x97.json b/advisories/unreviewed/2025/02/GHSA-v48v-77qp-6x97/GHSA-v48v-77qp-6x97.json new file mode 100644 index 00000000000..4e5207c7311 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v48v-77qp-6x97/GHSA-v48v-77qp-6x97.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v48v-77qp-6x97", + "modified": "2025-02-15T09:30:28Z", + "published": "2025-02-15T09:30:28Z", + "aliases": [ + "CVE-2024-13513" + ], + "details": "The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.2.3 via the logging functionality. This makes it possible for unauthenticated attackers to extract sensitive data including the plugin's clientToken, which in turn can be used to change user account information including emails and account type. This allows attackers to then change account passwords resulting in a complete site takeover. Version 2.4.2.3 disabled logging but left sites with existing log files vulnerable.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13513" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/oliver-pos/trunk/includes/models/class-pos-bridge-user.php#L373" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3234731%40oliver-pos%2Ftrunk&old=3056051%40oliver-pos%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bf6b7d8d-fb13-4eb4-b0b4-d0a10ad2a21e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-15T08:15:07Z" + } +} \ No newline at end of file