From 67fc1d84eb63b59ac245e3cbbce48f65a29ec85d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 27 Mar 2025 06:33:42 +0000 Subject: [PATCH] Publish Advisories GHSA-4mfg-2x7v-qfcr GHSA-535f-6cw7-vm9r GHSA-5jpq-rg6x-9vcr GHSA-5rqf-7xxv-3745 GHSA-66gc-mxg2-m27r GHSA-6r4j-qmf2-w7hf GHSA-78c4-7995-c6rm GHSA-79q3-hfvr-74f2 GHSA-hxxp-q9fq-m2jc GHSA-jqq8-q6f3-qfxh GHSA-jx77-f473-8cp6 GHSA-m55r-wvj5-r84g GHSA-p27c-x3w3-m9pm GHSA-pxrg-c4w2-rfrm GHSA-qcq7-2gff-cqjv GHSA-r9g3-6m6x-rjvm --- .../GHSA-4mfg-2x7v-qfcr.json | 25 +++++++++ .../GHSA-535f-6cw7-vm9r.json | 56 +++++++++++++++++++ .../GHSA-5jpq-rg6x-9vcr.json | 56 +++++++++++++++++++ .../GHSA-5rqf-7xxv-3745.json | 36 ++++++++++++ .../GHSA-66gc-mxg2-m27r.json | 25 +++++++++ .../GHSA-6r4j-qmf2-w7hf.json | 25 +++++++++ .../GHSA-78c4-7995-c6rm.json | 44 +++++++++++++++ .../GHSA-79q3-hfvr-74f2.json | 25 +++++++++ .../GHSA-hxxp-q9fq-m2jc.json | 25 +++++++++ .../GHSA-jqq8-q6f3-qfxh.json | 36 ++++++++++++ .../GHSA-jx77-f473-8cp6.json | 25 +++++++++ .../GHSA-m55r-wvj5-r84g.json | 52 +++++++++++++++++ .../GHSA-p27c-x3w3-m9pm.json | 25 +++++++++ .../GHSA-pxrg-c4w2-rfrm.json | 25 +++++++++ .../GHSA-qcq7-2gff-cqjv.json | 25 +++++++++ .../GHSA-r9g3-6m6x-rjvm.json | 44 +++++++++++++++ 16 files changed, 549 insertions(+) create mode 100644 advisories/unreviewed/2025/03/GHSA-4mfg-2x7v-qfcr/GHSA-4mfg-2x7v-qfcr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-535f-6cw7-vm9r/GHSA-535f-6cw7-vm9r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5jpq-rg6x-9vcr/GHSA-5jpq-rg6x-9vcr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5rqf-7xxv-3745/GHSA-5rqf-7xxv-3745.json create mode 100644 advisories/unreviewed/2025/03/GHSA-66gc-mxg2-m27r/GHSA-66gc-mxg2-m27r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6r4j-qmf2-w7hf/GHSA-6r4j-qmf2-w7hf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-78c4-7995-c6rm/GHSA-78c4-7995-c6rm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-79q3-hfvr-74f2/GHSA-79q3-hfvr-74f2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hxxp-q9fq-m2jc/GHSA-hxxp-q9fq-m2jc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jqq8-q6f3-qfxh/GHSA-jqq8-q6f3-qfxh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jx77-f473-8cp6/GHSA-jx77-f473-8cp6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m55r-wvj5-r84g/GHSA-m55r-wvj5-r84g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p27c-x3w3-m9pm/GHSA-p27c-x3w3-m9pm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pxrg-c4w2-rfrm/GHSA-pxrg-c4w2-rfrm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qcq7-2gff-cqjv/GHSA-qcq7-2gff-cqjv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r9g3-6m6x-rjvm/GHSA-r9g3-6m6x-rjvm.json diff --git a/advisories/unreviewed/2025/03/GHSA-4mfg-2x7v-qfcr/GHSA-4mfg-2x7v-qfcr.json b/advisories/unreviewed/2025/03/GHSA-4mfg-2x7v-qfcr/GHSA-4mfg-2x7v-qfcr.json new file mode 100644 index 00000000000..cc04529e8a3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4mfg-2x7v-qfcr/GHSA-4mfg-2x7v-qfcr.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mfg-2x7v-qfcr", + "modified": "2025-03-27T06:32:04Z", + "published": "2025-03-27T06:32:04Z", + "aliases": [ + "CVE-2025-31111" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31111" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T04:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-535f-6cw7-vm9r/GHSA-535f-6cw7-vm9r.json b/advisories/unreviewed/2025/03/GHSA-535f-6cw7-vm9r/GHSA-535f-6cw7-vm9r.json new file mode 100644 index 00000000000..c1f4f6cf29d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-535f-6cw7-vm9r/GHSA-535f-6cw7-vm9r.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-535f-6cw7-vm9r", + "modified": "2025-03-27T06:32:04Z", + "published": "2025-03-27T06:32:04Z", + "aliases": [ + "CVE-2025-2835" + ], + "details": "A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been declared as problematic. Affected by this vulnerability is the function autoLink of the file com/zyd/blog/controller/RestApiController.java. The manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2835" + }, + { + "type": "WEB", + "url": "https://github.com/zhangyd-c/OneBlog/issues/36" + }, + { + "type": "WEB", + "url": "https://github.com/zhangyd-c/OneBlog/issues/36#issue-2923097259" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.301471" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.301471" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.521815" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T04:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5jpq-rg6x-9vcr/GHSA-5jpq-rg6x-9vcr.json b/advisories/unreviewed/2025/03/GHSA-5jpq-rg6x-9vcr/GHSA-5jpq-rg6x-9vcr.json new file mode 100644 index 00000000000..fc65d7d7ebe --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5jpq-rg6x-9vcr/GHSA-5jpq-rg6x-9vcr.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jpq-rg6x-9vcr", + "modified": "2025-03-27T06:32:04Z", + "published": "2025-03-27T06:32:03Z", + "aliases": [ + "CVE-2025-2833" + ], + "details": "A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been classified as problematic. Affected is an unknown function of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2833" + }, + { + "type": "WEB", + "url": "https://github.com/zhangyd-c/OneBlog/issues/35" + }, + { + "type": "WEB", + "url": "https://github.com/zhangyd-c/OneBlog/issues/35#issue-2914268214" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.301470" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.301470" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.521813" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T04:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5rqf-7xxv-3745/GHSA-5rqf-7xxv-3745.json b/advisories/unreviewed/2025/03/GHSA-5rqf-7xxv-3745/GHSA-5rqf-7xxv-3745.json new file mode 100644 index 00000000000..bde1ae7c7de --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5rqf-7xxv-3745/GHSA-5rqf-7xxv-3745.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rqf-7xxv-3745", + "modified": "2025-03-27T06:32:04Z", + "published": "2025-03-27T06:32:04Z", + "aliases": [ + "CVE-2025-31165" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in the Logbug module of NightWolf Penetration Testing Platform 1.2.2 allows attackers to execute JavaScript through the markdown editor feature.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31165" + }, + { + "type": "WEB", + "url": "https://bug.report.night-wolf.io/changelogs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T04:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-66gc-mxg2-m27r/GHSA-66gc-mxg2-m27r.json b/advisories/unreviewed/2025/03/GHSA-66gc-mxg2-m27r/GHSA-66gc-mxg2-m27r.json new file mode 100644 index 00000000000..af187f01a3c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-66gc-mxg2-m27r/GHSA-66gc-mxg2-m27r.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66gc-mxg2-m27r", + "modified": "2025-03-27T06:32:04Z", + "published": "2025-03-27T06:32:04Z", + "aliases": [ + "CVE-2025-31110" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31110" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T04:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6r4j-qmf2-w7hf/GHSA-6r4j-qmf2-w7hf.json b/advisories/unreviewed/2025/03/GHSA-6r4j-qmf2-w7hf/GHSA-6r4j-qmf2-w7hf.json new file mode 100644 index 00000000000..71a792e254b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6r4j-qmf2-w7hf/GHSA-6r4j-qmf2-w7hf.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r4j-qmf2-w7hf", + "modified": "2025-03-27T06:32:04Z", + "published": "2025-03-27T06:32:04Z", + "aliases": [ + "CVE-2025-31106" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31106" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T04:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-78c4-7995-c6rm/GHSA-78c4-7995-c6rm.json b/advisories/unreviewed/2025/03/GHSA-78c4-7995-c6rm/GHSA-78c4-7995-c6rm.json new file mode 100644 index 00000000000..da1de6f3efa --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-78c4-7995-c6rm/GHSA-78c4-7995-c6rm.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78c4-7995-c6rm", + "modified": "2025-03-27T06:32:04Z", + "published": "2025-03-27T06:32:04Z", + "aliases": [ + "CVE-2025-2685" + ], + "details": "The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘table-name’ parameter in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2685" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/tablepress/trunk/views/class-all-tables-list-table.php#L242" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3261229" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e285849f-886e-49ba-bb43-8c67655fe239?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T06:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-79q3-hfvr-74f2/GHSA-79q3-hfvr-74f2.json b/advisories/unreviewed/2025/03/GHSA-79q3-hfvr-74f2/GHSA-79q3-hfvr-74f2.json new file mode 100644 index 00000000000..2d6ff2dd982 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-79q3-hfvr-74f2/GHSA-79q3-hfvr-74f2.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79q3-hfvr-74f2", + "modified": "2025-03-27T06:32:04Z", + "published": "2025-03-27T06:32:04Z", + "aliases": [ + "CVE-2025-31113" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31113" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T04:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hxxp-q9fq-m2jc/GHSA-hxxp-q9fq-m2jc.json b/advisories/unreviewed/2025/03/GHSA-hxxp-q9fq-m2jc/GHSA-hxxp-q9fq-m2jc.json new file mode 100644 index 00000000000..87bc931c05a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hxxp-q9fq-m2jc/GHSA-hxxp-q9fq-m2jc.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxxp-q9fq-m2jc", + "modified": "2025-03-27T06:32:04Z", + "published": "2025-03-27T06:32:04Z", + "aliases": [ + "CVE-2025-31109" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31109" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T04:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jqq8-q6f3-qfxh/GHSA-jqq8-q6f3-qfxh.json b/advisories/unreviewed/2025/03/GHSA-jqq8-q6f3-qfxh/GHSA-jqq8-q6f3-qfxh.json new file mode 100644 index 00000000000..4132a3a5ab2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jqq8-q6f3-qfxh/GHSA-jqq8-q6f3-qfxh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqq8-q6f3-qfxh", + "modified": "2025-03-27T06:32:04Z", + "published": "2025-03-27T06:32:04Z", + "aliases": [ + "CVE-2025-0273" + ], + "details": "HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be read by a local user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0273" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120138" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T05:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jx77-f473-8cp6/GHSA-jx77-f473-8cp6.json b/advisories/unreviewed/2025/03/GHSA-jx77-f473-8cp6/GHSA-jx77-f473-8cp6.json new file mode 100644 index 00000000000..1d6d2509701 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jx77-f473-8cp6/GHSA-jx77-f473-8cp6.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jx77-f473-8cp6", + "modified": "2025-03-27T06:32:04Z", + "published": "2025-03-27T06:32:04Z", + "aliases": [ + "CVE-2025-31112" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31112" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T04:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m55r-wvj5-r84g/GHSA-m55r-wvj5-r84g.json b/advisories/unreviewed/2025/03/GHSA-m55r-wvj5-r84g/GHSA-m55r-wvj5-r84g.json new file mode 100644 index 00000000000..3661930ba93 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m55r-wvj5-r84g/GHSA-m55r-wvj5-r84g.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m55r-wvj5-r84g", + "modified": "2025-03-27T06:32:03Z", + "published": "2025-03-27T06:32:03Z", + "aliases": [ + "CVE-2025-2832" + ], + "details": "A vulnerability was found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2832" + }, + { + "type": "WEB", + "url": "https://gitee.com/mingyuefusu/tushuguanlixitong/issues/IBTSPH" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.301469" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.301469" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.521460" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T04:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p27c-x3w3-m9pm/GHSA-p27c-x3w3-m9pm.json b/advisories/unreviewed/2025/03/GHSA-p27c-x3w3-m9pm/GHSA-p27c-x3w3-m9pm.json new file mode 100644 index 00000000000..1426e75545f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p27c-x3w3-m9pm/GHSA-p27c-x3w3-m9pm.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p27c-x3w3-m9pm", + "modified": "2025-03-27T06:32:04Z", + "published": "2025-03-27T06:32:04Z", + "aliases": [ + "CVE-2025-31105" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31105" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T04:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pxrg-c4w2-rfrm/GHSA-pxrg-c4w2-rfrm.json b/advisories/unreviewed/2025/03/GHSA-pxrg-c4w2-rfrm/GHSA-pxrg-c4w2-rfrm.json new file mode 100644 index 00000000000..4eda19f4651 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pxrg-c4w2-rfrm/GHSA-pxrg-c4w2-rfrm.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxrg-c4w2-rfrm", + "modified": "2025-03-27T06:32:04Z", + "published": "2025-03-27T06:32:04Z", + "aliases": [ + "CVE-2025-31108" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31108" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T04:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qcq7-2gff-cqjv/GHSA-qcq7-2gff-cqjv.json b/advisories/unreviewed/2025/03/GHSA-qcq7-2gff-cqjv/GHSA-qcq7-2gff-cqjv.json new file mode 100644 index 00000000000..273811fed21 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qcq7-2gff-cqjv/GHSA-qcq7-2gff-cqjv.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcq7-2gff-cqjv", + "modified": "2025-03-27T06:32:04Z", + "published": "2025-03-27T06:32:04Z", + "aliases": [ + "CVE-2025-31107" + ], + "details": "Rejected reason: Not used", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31107" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T04:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r9g3-6m6x-rjvm/GHSA-r9g3-6m6x-rjvm.json b/advisories/unreviewed/2025/03/GHSA-r9g3-6m6x-rjvm/GHSA-r9g3-6m6x-rjvm.json new file mode 100644 index 00000000000..327bc64691d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r9g3-6m6x-rjvm/GHSA-r9g3-6m6x-rjvm.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9g3-6m6x-rjvm", + "modified": "2025-03-27T06:32:04Z", + "published": "2025-03-27T06:32:04Z", + "aliases": [ + "CVE-2025-2332" + ], + "details": "The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.13 via deserialization of untrusted input in the 'returnMetaValueAsCustomerInput' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2332" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-ultimate-exporter/trunk/exportExtensions/ExportExtension.php#L3332" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3257504" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9546ab46-737c-4bd3-9542-8ab1b776b3ea?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T06:15:28Z" + } +} \ No newline at end of file