From 585035d84ef57e64b8d00ed96fa9ca32aabd592b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 22 Mar 2025 15:32:08 +0000 Subject: [PATCH] Publish Advisories GHSA-cvwm-qh2r-q68h GHSA-m6hj-x59q-53qg GHSA-3w22-q3jv-89jw GHSA-r89w-9fr4-c7c9 GHSA-4wjh-chq6-qh88 GHSA-7f2m-jpcp-wjgr GHSA-48xq-vmgv-hxqw GHSA-f69c-c87p-g4rh GHSA-r8vg-fpvm-r7hh GHSA-6wm8-q34j-2mc2 GHSA-fwj7-p878-r668 GHSA-pc6x-4v99-366p GHSA-2v55-9vh6-3j74 GHSA-6rw4-c297-m856 GHSA-8fx6-mj35-8hj9 GHSA-fmxw-76xq-cmqq GHSA-jxq2-9wwx-p5rm GHSA-xwcv-8394-675h --- .../GHSA-cvwm-qh2r-q68h.json | 4 +- .../GHSA-m6hj-x59q-53qg.json | 4 +- .../GHSA-3w22-q3jv-89jw.json | 4 +- .../GHSA-r89w-9fr4-c7c9.json | 1 + .../GHSA-4wjh-chq6-qh88.json | 1 + .../GHSA-7f2m-jpcp-wjgr.json | 11 +++- .../GHSA-48xq-vmgv-hxqw.json | 3 +- .../GHSA-f69c-c87p-g4rh.json | 4 +- .../GHSA-r8vg-fpvm-r7hh.json | 4 +- .../GHSA-6wm8-q34j-2mc2.json | 1 + .../GHSA-fwj7-p878-r668.json | 1 + .../GHSA-pc6x-4v99-366p.json | 3 +- .../GHSA-2v55-9vh6-3j74.json | 56 +++++++++++++++++++ .../GHSA-6rw4-c297-m856.json | 56 +++++++++++++++++++ .../GHSA-8fx6-mj35-8hj9.json | 48 ++++++++++++++++ .../GHSA-fmxw-76xq-cmqq.json | 35 ++++++++++++ .../GHSA-jxq2-9wwx-p5rm.json | 56 +++++++++++++++++++ .../GHSA-xwcv-8394-675h.json | 44 +++++++++++++++ 18 files changed, 325 insertions(+), 11 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-2v55-9vh6-3j74/GHSA-2v55-9vh6-3j74.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6rw4-c297-m856/GHSA-6rw4-c297-m856.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8fx6-mj35-8hj9/GHSA-8fx6-mj35-8hj9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fmxw-76xq-cmqq/GHSA-fmxw-76xq-cmqq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jxq2-9wwx-p5rm/GHSA-jxq2-9wwx-p5rm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xwcv-8394-675h/GHSA-xwcv-8394-675h.json diff --git a/advisories/unreviewed/2024/02/GHSA-cvwm-qh2r-q68h/GHSA-cvwm-qh2r-q68h.json b/advisories/unreviewed/2024/02/GHSA-cvwm-qh2r-q68h/GHSA-cvwm-qh2r-q68h.json index 23e46e42d8d..b3ec988d7f4 100644 --- a/advisories/unreviewed/2024/02/GHSA-cvwm-qh2r-q68h/GHSA-cvwm-qh2r-q68h.json +++ b/advisories/unreviewed/2024/02/GHSA-cvwm-qh2r-q68h/GHSA-cvwm-qh2r-q68h.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-cvwm-qh2r-q68h", - "modified": "2024-10-17T15:31:06Z", + "modified": "2025-03-22T15:30:34Z", "published": "2024-02-13T18:38:23Z", "aliases": [ "CVE-2023-20570" ], - "details": "Insufficient verification of data authenticity in\nthe configuration state machine may allow a local attacker to potentially load\narbitrary bitstreams.\n\n\n\n\n\n", + "details": "Insufficient verification of data authenticity in\nthe configuration state machine may allow a local attacker to potentially load\narbitrary bitstreams.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/07/GHSA-m6hj-x59q-53qg/GHSA-m6hj-x59q-53qg.json b/advisories/unreviewed/2024/07/GHSA-m6hj-x59q-53qg/GHSA-m6hj-x59q-53qg.json index c7c3de40a74..761a67ccaa2 100644 --- a/advisories/unreviewed/2024/07/GHSA-m6hj-x59q-53qg/GHSA-m6hj-x59q-53qg.json +++ b/advisories/unreviewed/2024/07/GHSA-m6hj-x59q-53qg/GHSA-m6hj-x59q-53qg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-3w22-q3jv-89jw/GHSA-3w22-q3jv-89jw.json b/advisories/unreviewed/2024/09/GHSA-3w22-q3jv-89jw/GHSA-3w22-q3jv-89jw.json index 4bdba91343d..ee44c7ee1f0 100644 --- a/advisories/unreviewed/2024/09/GHSA-3w22-q3jv-89jw/GHSA-3w22-q3jv-89jw.json +++ b/advisories/unreviewed/2024/09/GHSA-3w22-q3jv-89jw/GHSA-3w22-q3jv-89jw.json @@ -53,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-r89w-9fr4-c7c9/GHSA-r89w-9fr4-c7c9.json b/advisories/unreviewed/2024/09/GHSA-r89w-9fr4-c7c9/GHSA-r89w-9fr4-c7c9.json index 09c968ebd1f..c74770a7969 100644 --- a/advisories/unreviewed/2024/09/GHSA-r89w-9fr4-c7c9/GHSA-r89w-9fr4-c7c9.json +++ b/advisories/unreviewed/2024/09/GHSA-r89w-9fr4-c7c9/GHSA-r89w-9fr4-c7c9.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-269" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/10/GHSA-4wjh-chq6-qh88/GHSA-4wjh-chq6-qh88.json b/advisories/unreviewed/2024/10/GHSA-4wjh-chq6-qh88/GHSA-4wjh-chq6-qh88.json index 905380ae490..ca0770b0f5b 100644 --- a/advisories/unreviewed/2024/10/GHSA-4wjh-chq6-qh88/GHSA-4wjh-chq6-qh88.json +++ b/advisories/unreviewed/2024/10/GHSA-4wjh-chq6-qh88/GHSA-4wjh-chq6-qh88.json @@ -42,6 +42,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-89" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/10/GHSA-7f2m-jpcp-wjgr/GHSA-7f2m-jpcp-wjgr.json b/advisories/unreviewed/2024/10/GHSA-7f2m-jpcp-wjgr/GHSA-7f2m-jpcp-wjgr.json index 33383bb1899..59f2f6c9993 100644 --- a/advisories/unreviewed/2024/10/GHSA-7f2m-jpcp-wjgr/GHSA-7f2m-jpcp-wjgr.json +++ b/advisories/unreviewed/2024/10/GHSA-7f2m-jpcp-wjgr/GHSA-7f2m-jpcp-wjgr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7f2m-jpcp-wjgr", - "modified": "2024-10-11T15:30:32Z", + "modified": "2025-03-22T15:30:34Z", "published": "2024-10-11T15:30:32Z", "aliases": [ "CVE-2024-45317" ], "details": "A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated attacker to cause the SMA1000 server-side application to make requests to an unintended IP address.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-918" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-11T13:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-48xq-vmgv-hxqw/GHSA-48xq-vmgv-hxqw.json b/advisories/unreviewed/2025/01/GHSA-48xq-vmgv-hxqw/GHSA-48xq-vmgv-hxqw.json index de209afc596..c6fe7ce15a4 100644 --- a/advisories/unreviewed/2025/01/GHSA-48xq-vmgv-hxqw/GHSA-48xq-vmgv-hxqw.json +++ b/advisories/unreviewed/2025/01/GHSA-48xq-vmgv-hxqw/GHSA-48xq-vmgv-hxqw.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-770" + "CWE-770", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-f69c-c87p-g4rh/GHSA-f69c-c87p-g4rh.json b/advisories/unreviewed/2025/01/GHSA-f69c-c87p-g4rh/GHSA-f69c-c87p-g4rh.json index 7a12316bb40..c195cce3c7f 100644 --- a/advisories/unreviewed/2025/01/GHSA-f69c-c87p-g4rh/GHSA-f69c-c87p-g4rh.json +++ b/advisories/unreviewed/2025/01/GHSA-f69c-c87p-g4rh/GHSA-f69c-c87p-g4rh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-r8vg-fpvm-r7hh/GHSA-r8vg-fpvm-r7hh.json b/advisories/unreviewed/2025/01/GHSA-r8vg-fpvm-r7hh/GHSA-r8vg-fpvm-r7hh.json index 724aeb9aa1d..653b8834a94 100644 --- a/advisories/unreviewed/2025/01/GHSA-r8vg-fpvm-r7hh/GHSA-r8vg-fpvm-r7hh.json +++ b/advisories/unreviewed/2025/01/GHSA-r8vg-fpvm-r7hh/GHSA-r8vg-fpvm-r7hh.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-476" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-6wm8-q34j-2mc2/GHSA-6wm8-q34j-2mc2.json b/advisories/unreviewed/2025/02/GHSA-6wm8-q34j-2mc2/GHSA-6wm8-q34j-2mc2.json index 773df106f0c..802ba01c327 100644 --- a/advisories/unreviewed/2025/02/GHSA-6wm8-q34j-2mc2/GHSA-6wm8-q34j-2mc2.json +++ b/advisories/unreviewed/2025/02/GHSA-6wm8-q34j-2mc2/GHSA-6wm8-q34j-2mc2.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-617" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/02/GHSA-fwj7-p878-r668/GHSA-fwj7-p878-r668.json b/advisories/unreviewed/2025/02/GHSA-fwj7-p878-r668/GHSA-fwj7-p878-r668.json index 22fc080d9b3..37b3c8d90de 100644 --- a/advisories/unreviewed/2025/02/GHSA-fwj7-p878-r668/GHSA-fwj7-p878-r668.json +++ b/advisories/unreviewed/2025/02/GHSA-fwj7-p878-r668/GHSA-fwj7-p878-r668.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-862" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/02/GHSA-pc6x-4v99-366p/GHSA-pc6x-4v99-366p.json b/advisories/unreviewed/2025/02/GHSA-pc6x-4v99-366p/GHSA-pc6x-4v99-366p.json index 0e1c64ea4e8..46668ee2600 100644 --- a/advisories/unreviewed/2025/02/GHSA-pc6x-4v99-366p/GHSA-pc6x-4v99-366p.json +++ b/advisories/unreviewed/2025/02/GHSA-pc6x-4v99-366p/GHSA-pc6x-4v99-366p.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-276" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-2v55-9vh6-3j74/GHSA-2v55-9vh6-3j74.json b/advisories/unreviewed/2025/03/GHSA-2v55-9vh6-3j74/GHSA-2v55-9vh6-3j74.json new file mode 100644 index 00000000000..8367b57936e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2v55-9vh6-3j74/GHSA-2v55-9vh6-3j74.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v55-9vh6-3j74", + "modified": "2025-03-22T15:30:36Z", + "published": "2025-03-22T15:30:36Z", + "aliases": [ + "CVE-2025-2619" + ], + "details": "A vulnerability, which was classified as critical, was found in D-Link DAP-1620 1.03. This affects the function check_dws_cookie of the file /storage of the component Cookie Handler. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2619" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300621" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300621" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.518968" + }, + { + "type": "WEB", + "url": "https://witty-maiasaura-083.notion.site/D-link-DAP-1620-check_dws_cookie-Vulnerability-1b4b2f2a6361805ca74fdf4949385ade" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-22T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6rw4-c297-m856/GHSA-6rw4-c297-m856.json b/advisories/unreviewed/2025/03/GHSA-6rw4-c297-m856/GHSA-6rw4-c297-m856.json new file mode 100644 index 00000000000..bcf9848df24 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6rw4-c297-m856/GHSA-6rw4-c297-m856.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rw4-c297-m856", + "modified": "2025-03-22T15:30:36Z", + "published": "2025-03-22T15:30:36Z", + "aliases": [ + "CVE-2025-2618" + ], + "details": "A vulnerability, which was classified as critical, has been found in D-Link DAP-1620 1.03. Affected by this issue is the function set_ws_action of the file /dws/api/ of the component Path Handler. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2618" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300620" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300620" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.518963" + }, + { + "type": "WEB", + "url": "https://witty-maiasaura-083.notion.site/D-link-DAP-1620-set_ws_action-Vulnerability-1afb2f2a6361804e86dcde1e78ea2a8e" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-22T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8fx6-mj35-8hj9/GHSA-8fx6-mj35-8hj9.json b/advisories/unreviewed/2025/03/GHSA-8fx6-mj35-8hj9/GHSA-8fx6-mj35-8hj9.json new file mode 100644 index 00000000000..df2f4bb74b3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8fx6-mj35-8hj9/GHSA-8fx6-mj35-8hj9.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fx6-mj35-8hj9", + "modified": "2025-03-22T15:30:36Z", + "published": "2025-03-22T15:30:36Z", + "aliases": [ + "CVE-2025-2617" + ], + "details": "A vulnerability classified as problematic was found in yangyouwang 杨有旺 crud 简约后台管理系统 1.0.0. Affected by this vulnerability is an unknown functionality of the component Department Page. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2617" + }, + { + "type": "WEB", + "url": "https://gitee.com/yangyouwang/crud/issues/IBSPOX" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300619" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300619" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-22T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fmxw-76xq-cmqq/GHSA-fmxw-76xq-cmqq.json b/advisories/unreviewed/2025/03/GHSA-fmxw-76xq-cmqq/GHSA-fmxw-76xq-cmqq.json new file mode 100644 index 00000000000..5b28a2c0e40 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fmxw-76xq-cmqq/GHSA-fmxw-76xq-cmqq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmxw-76xq-cmqq", + "modified": "2025-03-22T15:30:36Z", + "published": "2025-03-22T15:30:36Z", + "aliases": [ + "CVE-2025-26796" + ], + "details": "** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie.\n\nThis issue affects Apache Oozie: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26796" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/fzrmsslnrpl0vpp0jr73fosmfjv4omdq" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/03/21/1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-22T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jxq2-9wwx-p5rm/GHSA-jxq2-9wwx-p5rm.json b/advisories/unreviewed/2025/03/GHSA-jxq2-9wwx-p5rm/GHSA-jxq2-9wwx-p5rm.json new file mode 100644 index 00000000000..24073bbd1e6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jxq2-9wwx-p5rm/GHSA-jxq2-9wwx-p5rm.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxq2-9wwx-p5rm", + "modified": "2025-03-22T15:30:36Z", + "published": "2025-03-22T15:30:36Z", + "aliases": [ + "CVE-2025-2620" + ], + "details": "A vulnerability has been found in D-Link DAP-1620 1.03 and classified as critical. This vulnerability affects the function mod_graph_auth_uri_handler of the file /storage of the component Authentication Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2620" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300622" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300622" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.518969" + }, + { + "type": "WEB", + "url": "https://witty-maiasaura-083.notion.site/D-link-DAP-1620-mod_graph_auth_uri_handler-Vulnerability-1afb2f2a6361809ea7f2dc4df3b85f1f" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-22T15:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xwcv-8394-675h/GHSA-xwcv-8394-675h.json b/advisories/unreviewed/2025/03/GHSA-xwcv-8394-675h/GHSA-xwcv-8394-675h.json new file mode 100644 index 00000000000..976ef7d27ee --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xwcv-8394-675h/GHSA-xwcv-8394-675h.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwcv-8394-675h", + "modified": "2025-03-22T15:30:36Z", + "published": "2025-03-22T15:30:36Z", + "aliases": [ + "CVE-2025-2186" + ], + "details": "The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to SQL Injection via the ‘automationId’ parameter in all versions up to, and including, 3.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2186" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-marketing-automations/trunk/includes/api/wc/class-bwfan-api-get-automation-dynamic-coupon.php#L50" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3257474" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/88f8fa25-e3d5-4dfd-aae5-68b5880ffd53?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-22T13:15:35Z" + } +} \ No newline at end of file