From 6aca6e6b53b94045594a51c4d9570a4c46fe4e5f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 30 Jan 2025 03:31:54 +0000 Subject: [PATCH] Publish Advisories GHSA-5558-mmq3-572w GHSA-9v8h-2rmp-52m8 GHSA-h9p3-57f6-xpmg GHSA-wm69-gq95-wfj3 --- .../GHSA-5558-mmq3-572w.json | 56 +++++++++++++++++++ .../GHSA-9v8h-2rmp-52m8.json | 56 +++++++++++++++++++ .../GHSA-h9p3-57f6-xpmg.json | 56 +++++++++++++++++++ .../GHSA-wm69-gq95-wfj3.json | 56 +++++++++++++++++++ 4 files changed, 224 insertions(+) create mode 100644 advisories/unreviewed/2025/01/GHSA-5558-mmq3-572w/GHSA-5558-mmq3-572w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9v8h-2rmp-52m8/GHSA-9v8h-2rmp-52m8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-h9p3-57f6-xpmg/GHSA-h9p3-57f6-xpmg.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wm69-gq95-wfj3/GHSA-wm69-gq95-wfj3.json diff --git a/advisories/unreviewed/2025/01/GHSA-5558-mmq3-572w/GHSA-5558-mmq3-572w.json b/advisories/unreviewed/2025/01/GHSA-5558-mmq3-572w/GHSA-5558-mmq3-572w.json new file mode 100644 index 00000000000..ae3138fb3cb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5558-mmq3-572w/GHSA-5558-mmq3-572w.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5558-mmq3-572w", + "modified": "2025-01-30T03:30:50Z", + "published": "2025-01-30T03:30:50Z", + "aliases": [ + "CVE-2025-0847" + ], + "details": "A vulnerability was found in 1000 Projects Employee Task Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /index.php of the component Login. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0847" + }, + { + "type": "WEB", + "url": "https://github.com/onupset/CVE/issues/5" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.294010" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.294010" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.485762" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T02:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9v8h-2rmp-52m8/GHSA-9v8h-2rmp-52m8.json b/advisories/unreviewed/2025/01/GHSA-9v8h-2rmp-52m8/GHSA-9v8h-2rmp-52m8.json new file mode 100644 index 00000000000..c798fa3828a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9v8h-2rmp-52m8/GHSA-9v8h-2rmp-52m8.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v8h-2rmp-52m8", + "modified": "2025-01-30T03:30:50Z", + "published": "2025-01-30T03:30:50Z", + "aliases": [ + "CVE-2025-0846" + ], + "details": "A vulnerability was found in 1000 Projects Employee Task Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/AdminLogin.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0846" + }, + { + "type": "WEB", + "url": "https://github.com/onupset/CVE/issues/4" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.294009" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.294009" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.485756" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T01:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h9p3-57f6-xpmg/GHSA-h9p3-57f6-xpmg.json b/advisories/unreviewed/2025/01/GHSA-h9p3-57f6-xpmg/GHSA-h9p3-57f6-xpmg.json new file mode 100644 index 00000000000..eaf33fe32c6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h9p3-57f6-xpmg/GHSA-h9p3-57f6-xpmg.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9p3-57f6-xpmg", + "modified": "2025-01-30T03:30:51Z", + "published": "2025-01-30T03:30:51Z", + "aliases": [ + "CVE-2025-0849" + ], + "details": "A vulnerability classified as critical has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /edit-staff/ of the component Staff Handler. The manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0849" + }, + { + "type": "WEB", + "url": "https://github.com/KhukuriRimal/Vulnerabilities/blob/main/Sensitive%20Super%20Admin%20Data%20Exposure%20and%20Unauthorized%20Data%20Update%20via%20IDOR%20(Teacher%20Role%20to%20Super%20Admin%20Role).pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.294012" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.294012" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.487618" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T02:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wm69-gq95-wfj3/GHSA-wm69-gq95-wfj3.json b/advisories/unreviewed/2025/01/GHSA-wm69-gq95-wfj3/GHSA-wm69-gq95-wfj3.json new file mode 100644 index 00000000000..9806d2150f6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wm69-gq95-wfj3/GHSA-wm69-gq95-wfj3.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wm69-gq95-wfj3", + "modified": "2025-01-30T03:30:51Z", + "published": "2025-01-30T03:30:51Z", + "aliases": [ + "CVE-2025-0848" + ], + "details": "A vulnerability was found in Tenda A18 up to 15.13.07.09. It has been rated as critical. This issue affects the function SetCmdlineRun of the file /goform/SetCmdlineRun of the component HTTP POST Request Handler. The manipulation of the argument wpapsk_crypto5g leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0848" + }, + { + "type": "WEB", + "url": "https://github.com/alc9700jmo/CVE/issues/9" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.294011" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.294011" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.485802" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-30T02:15:25Z" + } +} \ No newline at end of file