Publish Advisories

GHSA-5558-mmq3-572w
GHSA-9v8h-2rmp-52m8
GHSA-h9p3-57f6-xpmg
GHSA-wm69-gq95-wfj3
This commit is contained in:
advisory-database[bot]
2025-01-30 03:31:54 +00:00
parent e9bf4189b6
commit 6aca6e6b53
4 changed files with 224 additions and 0 deletions
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5558-mmq3-572w",
"modified": "2025-01-30T03:30:50Z",
"published": "2025-01-30T03:30:50Z",
"aliases": [
"CVE-2025-0847"
],
"details": "A vulnerability was found in 1000 Projects Employee Task Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /index.php of the component Login. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0847"
},
{
"type": "WEB",
"url": "https://github.com/onupset/CVE/issues/5"
},
{
"type": "WEB",
"url": "https://1000projects.org"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.294010"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.294010"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.485762"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-30T02:15:25Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9v8h-2rmp-52m8",
"modified": "2025-01-30T03:30:50Z",
"published": "2025-01-30T03:30:50Z",
"aliases": [
"CVE-2025-0846"
],
"details": "A vulnerability was found in 1000 Projects Employee Task Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/AdminLogin.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0846"
},
{
"type": "WEB",
"url": "https://github.com/onupset/CVE/issues/4"
},
{
"type": "WEB",
"url": "https://1000projects.org"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.294009"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.294009"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.485756"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-30T01:15:13Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h9p3-57f6-xpmg",
"modified": "2025-01-30T03:30:51Z",
"published": "2025-01-30T03:30:51Z",
"aliases": [
"CVE-2025-0849"
],
"details": "A vulnerability classified as critical has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /edit-staff/ of the component Staff Handler. The manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0849"
},
{
"type": "WEB",
"url": "https://github.com/KhukuriRimal/Vulnerabilities/blob/main/Sensitive%20Super%20Admin%20Data%20Exposure%20and%20Unauthorized%20Data%20Update%20via%20IDOR%20(Teacher%20Role%20to%20Super%20Admin%20Role).pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.294012"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.294012"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.487618"
},
{
"type": "WEB",
"url": "https://www.campcodes.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-266"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-30T02:15:25Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wm69-gq95-wfj3",
"modified": "2025-01-30T03:30:51Z",
"published": "2025-01-30T03:30:51Z",
"aliases": [
"CVE-2025-0848"
],
"details": "A vulnerability was found in Tenda A18 up to 15.13.07.09. It has been rated as critical. This issue affects the function SetCmdlineRun of the file /goform/SetCmdlineRun of the component HTTP POST Request Handler. The manipulation of the argument wpapsk_crypto5g leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0848"
},
{
"type": "WEB",
"url": "https://github.com/alc9700jmo/CVE/issues/9"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.294011"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.294011"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.485802"
},
{
"type": "WEB",
"url": "https://www.tenda.com.cn"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-30T02:15:25Z"
}
}