diff --git a/advisories/unreviewed/2023/06/GHSA-4mrp-4c9h-48ww/GHSA-4mrp-4c9h-48ww.json b/advisories/unreviewed/2023/06/GHSA-4mrp-4c9h-48ww/GHSA-4mrp-4c9h-48ww.json index 22995e0f1d3..ba07aa2de1a 100644 --- a/advisories/unreviewed/2023/06/GHSA-4mrp-4c9h-48ww/GHSA-4mrp-4c9h-48ww.json +++ b/advisories/unreviewed/2023/06/GHSA-4mrp-4c9h-48ww/GHSA-4mrp-4c9h-48ww.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-287c-cc7v-7v95/GHSA-287c-cc7v-7v95.json b/advisories/unreviewed/2024/02/GHSA-287c-cc7v-7v95/GHSA-287c-cc7v-7v95.json index f62b8b4c21e..c2e5a0bdd72 100644 --- a/advisories/unreviewed/2024/02/GHSA-287c-cc7v-7v95/GHSA-287c-cc7v-7v95.json +++ b/advisories/unreviewed/2024/02/GHSA-287c-cc7v-7v95/GHSA-287c-cc7v-7v95.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-3f4g-fw75-mc93/GHSA-3f4g-fw75-mc93.json b/advisories/unreviewed/2024/02/GHSA-3f4g-fw75-mc93/GHSA-3f4g-fw75-mc93.json index 6931e02335e..8d8b7284a09 100644 --- a/advisories/unreviewed/2024/02/GHSA-3f4g-fw75-mc93/GHSA-3f4g-fw75-mc93.json +++ b/advisories/unreviewed/2024/02/GHSA-3f4g-fw75-mc93/GHSA-3f4g-fw75-mc93.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-4jc2-fxpv-j9j3/GHSA-4jc2-fxpv-j9j3.json b/advisories/unreviewed/2024/02/GHSA-4jc2-fxpv-j9j3/GHSA-4jc2-fxpv-j9j3.json index 185f9228680..529362952a5 100644 --- a/advisories/unreviewed/2024/02/GHSA-4jc2-fxpv-j9j3/GHSA-4jc2-fxpv-j9j3.json +++ b/advisories/unreviewed/2024/02/GHSA-4jc2-fxpv-j9j3/GHSA-4jc2-fxpv-j9j3.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-88wc-9wwc-jm28/GHSA-88wc-9wwc-jm28.json b/advisories/unreviewed/2024/02/GHSA-88wc-9wwc-jm28/GHSA-88wc-9wwc-jm28.json index 3163161cea0..19239db0525 100644 --- a/advisories/unreviewed/2024/02/GHSA-88wc-9wwc-jm28/GHSA-88wc-9wwc-jm28.json +++ b/advisories/unreviewed/2024/02/GHSA-88wc-9wwc-jm28/GHSA-88wc-9wwc-jm28.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-cg84-jfhr-gr28/GHSA-cg84-jfhr-gr28.json b/advisories/unreviewed/2024/02/GHSA-cg84-jfhr-gr28/GHSA-cg84-jfhr-gr28.json index 27b41da9c98..664496695b7 100644 --- a/advisories/unreviewed/2024/02/GHSA-cg84-jfhr-gr28/GHSA-cg84-jfhr-gr28.json +++ b/advisories/unreviewed/2024/02/GHSA-cg84-jfhr-gr28/GHSA-cg84-jfhr-gr28.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-h43f-4wgw-vfx3/GHSA-h43f-4wgw-vfx3.json b/advisories/unreviewed/2024/02/GHSA-h43f-4wgw-vfx3/GHSA-h43f-4wgw-vfx3.json index 8ccab7d00b2..cb489ca53a8 100644 --- a/advisories/unreviewed/2024/02/GHSA-h43f-4wgw-vfx3/GHSA-h43f-4wgw-vfx3.json +++ b/advisories/unreviewed/2024/02/GHSA-h43f-4wgw-vfx3/GHSA-h43f-4wgw-vfx3.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-mh5w-fqqj-wc98/GHSA-mh5w-fqqj-wc98.json b/advisories/unreviewed/2024/02/GHSA-mh5w-fqqj-wc98/GHSA-mh5w-fqqj-wc98.json index f5ee09919f4..2bfa7070c32 100644 --- a/advisories/unreviewed/2024/02/GHSA-mh5w-fqqj-wc98/GHSA-mh5w-fqqj-wc98.json +++ b/advisories/unreviewed/2024/02/GHSA-mh5w-fqqj-wc98/GHSA-mh5w-fqqj-wc98.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-q43v-29vw-5g49/GHSA-q43v-29vw-5g49.json b/advisories/unreviewed/2024/02/GHSA-q43v-29vw-5g49/GHSA-q43v-29vw-5g49.json index 94c2558d621..6a6dad2ba85 100644 --- a/advisories/unreviewed/2024/02/GHSA-q43v-29vw-5g49/GHSA-q43v-29vw-5g49.json +++ b/advisories/unreviewed/2024/02/GHSA-q43v-29vw-5g49/GHSA-q43v-29vw-5g49.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-qpqx-323c-39p3/GHSA-qpqx-323c-39p3.json b/advisories/unreviewed/2024/02/GHSA-qpqx-323c-39p3/GHSA-qpqx-323c-39p3.json index ee41e68cb20..094d11bf68b 100644 --- a/advisories/unreviewed/2024/02/GHSA-qpqx-323c-39p3/GHSA-qpqx-323c-39p3.json +++ b/advisories/unreviewed/2024/02/GHSA-qpqx-323c-39p3/GHSA-qpqx-323c-39p3.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-2wrg-7gpc-j9h6/GHSA-2wrg-7gpc-j9h6.json b/advisories/unreviewed/2025/01/GHSA-2wrg-7gpc-j9h6/GHSA-2wrg-7gpc-j9h6.json new file mode 100644 index 00000000000..b828be89034 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2wrg-7gpc-j9h6/GHSA-2wrg-7gpc-j9h6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wrg-7gpc-j9h6", + "modified": "2025-01-07T15:31:47Z", + "published": "2025-01-07T15:31:47Z", + "aliases": [ + "CVE-2024-45640" + ], + "details": "IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45640" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7180313" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-554j-jxx2-832r/GHSA-554j-jxx2-832r.json b/advisories/unreviewed/2025/01/GHSA-554j-jxx2-832r/GHSA-554j-jxx2-832r.json new file mode 100644 index 00000000000..6547bdc1a69 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-554j-jxx2-832r/GHSA-554j-jxx2-832r.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-554j-jxx2-832r", + "modified": "2025-01-07T15:31:47Z", + "published": "2025-01-07T15:31:47Z", + "aliases": [ + "CVE-2025-0295" + ], + "details": "A vulnerability was found in code-projects Online Book Shop 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /booklist.php?subcatid=1. The manipulation of the argument subcatnm leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0295" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://gist.github.com/th4s1s/19d21e7fdbaf3512fccfd75df3080657" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290444" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290444" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.475134" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5wx3-r9cv-h65r/GHSA-5wx3-r9cv-h65r.json b/advisories/unreviewed/2025/01/GHSA-5wx3-r9cv-h65r/GHSA-5wx3-r9cv-h65r.json new file mode 100644 index 00000000000..c0bcab91d1e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5wx3-r9cv-h65r/GHSA-5wx3-r9cv-h65r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wx3-r9cv-h65r", + "modified": "2025-01-07T15:31:47Z", + "published": "2025-01-07T15:31:47Z", + "aliases": [ + "CVE-2024-45100" + ], + "details": "IBM Security ReaQta 3.12 could allow a privileged user to cause a denial of service by sending multiple administration requests due to improper allocation of resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45100" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7180313" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7q36-jprx-hc27/GHSA-7q36-jprx-hc27.json b/advisories/unreviewed/2025/01/GHSA-7q36-jprx-hc27/GHSA-7q36-jprx-hc27.json new file mode 100644 index 00000000000..0805ae51244 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7q36-jprx-hc27/GHSA-7q36-jprx-hc27.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q36-jprx-hc27", + "modified": "2025-01-07T15:31:47Z", + "published": "2025-01-07T15:31:47Z", + "aliases": [ + "CVE-2025-0296" + ], + "details": "A vulnerability was found in code-projects Online Book Shop 1.0. It has been classified as critical. This affects an unknown part of the file /booklist.php. The manipulation of the argument subcatid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0296" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://gist.github.com/th4s1s/4ebf1c60bbec213119f2eaac9cd29118" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290445" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290445" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.475135" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-92hg-q4w2-pmcv/GHSA-92hg-q4w2-pmcv.json b/advisories/unreviewed/2025/01/GHSA-92hg-q4w2-pmcv/GHSA-92hg-q4w2-pmcv.json index 16bae478409..93fd8c5bda2 100644 --- a/advisories/unreviewed/2025/01/GHSA-92hg-q4w2-pmcv/GHSA-92hg-q4w2-pmcv.json +++ b/advisories/unreviewed/2025/01/GHSA-92hg-q4w2-pmcv/GHSA-92hg-q4w2-pmcv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-92hg-q4w2-pmcv", - "modified": "2025-01-06T18:31:02Z", + "modified": "2025-01-07T15:31:46Z", "published": "2025-01-06T18:31:02Z", "aliases": [ "CVE-2024-51112" ], "details": "Open Redirect vulnerability in Pnetlab 5.3.11 allows an attacker to manipulate URLs to redirect users to arbitrary external websites via a crafted script", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-06T16:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9cw6-mv45-4hfh/GHSA-9cw6-mv45-4hfh.json b/advisories/unreviewed/2025/01/GHSA-9cw6-mv45-4hfh/GHSA-9cw6-mv45-4hfh.json new file mode 100644 index 00000000000..7995008829d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9cw6-mv45-4hfh/GHSA-9cw6-mv45-4hfh.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cw6-mv45-4hfh", + "modified": "2025-01-07T15:31:47Z", + "published": "2025-01-07T15:31:47Z", + "aliases": [ + "CVE-2024-12738" + ], + "details": "The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several user meta parameters in all versions up to, and including, 3.12.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page and clicks a link to show user meta.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12738" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/profile-builder/tags/3.12.8/features/email-confirmation/class-email-confirmation.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/profile-builder/tags/3.12.8/features/email-confirmation/class-email-confirmation.php#L95" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3217544" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/51b626e1-89c0-49b9-bfeb-32005e8e78d6?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c6wh-r22m-2hjm/GHSA-c6wh-r22m-2hjm.json b/advisories/unreviewed/2025/01/GHSA-c6wh-r22m-2hjm/GHSA-c6wh-r22m-2hjm.json new file mode 100644 index 00000000000..777ed7a13e3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c6wh-r22m-2hjm/GHSA-c6wh-r22m-2hjm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6wh-r22m-2hjm", + "modified": "2025-01-07T15:31:46Z", + "published": "2025-01-07T15:31:46Z", + "aliases": [ + "CVE-2023-28739" + ], + "details": "Incorrect default permissions in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28739" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00928.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h53h-w5f8-j3p6/GHSA-h53h-w5f8-j3p6.json b/advisories/unreviewed/2025/01/GHSA-h53h-w5f8-j3p6/GHSA-h53h-w5f8-j3p6.json new file mode 100644 index 00000000000..08e3b4715c3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h53h-w5f8-j3p6/GHSA-h53h-w5f8-j3p6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h53h-w5f8-j3p6", + "modified": "2025-01-07T15:31:46Z", + "published": "2025-01-07T15:31:46Z", + "aliases": [ + "CVE-2023-25174" + ], + "details": "Improper access control in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25174" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00928.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mmjm-8qjp-f6jv/GHSA-mmjm-8qjp-f6jv.json b/advisories/unreviewed/2025/01/GHSA-mmjm-8qjp-f6jv/GHSA-mmjm-8qjp-f6jv.json new file mode 100644 index 00000000000..8deae968569 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mmjm-8qjp-f6jv/GHSA-mmjm-8qjp-f6jv.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmjm-8qjp-f6jv", + "modified": "2025-01-07T15:31:47Z", + "published": "2025-01-07T15:31:47Z", + "aliases": [ + "CVE-2025-0294" + ], + "details": "A vulnerability has been found in SourceCodester Home Clean Services Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /public_html/admin/process.php. The manipulation of the argument type/length/business leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0294" + }, + { + "type": "WEB", + "url": "https://github.com/xiaosguang/cve/blob/main/Home%20Clean%20Services%20Management/Home%20Clean%20Services%20Management%20System%20process.php%20id%20SQL%20injection.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290443" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290443" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.475076" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r8qg-p9r3-cc3j/GHSA-r8qg-p9r3-cc3j.json b/advisories/unreviewed/2025/01/GHSA-r8qg-p9r3-cc3j/GHSA-r8qg-p9r3-cc3j.json new file mode 100644 index 00000000000..fef12e61877 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r8qg-p9r3-cc3j/GHSA-r8qg-p9r3-cc3j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8qg-p9r3-cc3j", + "modified": "2025-01-07T15:31:47Z", + "published": "2025-01-07T15:31:47Z", + "aliases": [ + "CVE-2024-12131" + ], + "details": "The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.5 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to submit resumes for other applicants when applying for jobs.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12131" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-job-portal/tags/2.2.6/modules/jobapply/model.php?rev=3216415" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b4772ab0-41cd-4b35-bda9-d72e0fd7b7a5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x7m8-vrfv-272v/GHSA-x7m8-vrfv-272v.json b/advisories/unreviewed/2025/01/GHSA-x7m8-vrfv-272v/GHSA-x7m8-vrfv-272v.json new file mode 100644 index 00000000000..fe36540d7e2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x7m8-vrfv-272v/GHSA-x7m8-vrfv-272v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7m8-vrfv-272v", + "modified": "2025-01-07T15:31:47Z", + "published": "2025-01-07T15:31:46Z", + "aliases": [ + "CVE-2024-12426" + ], + "details": "Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice.\n\n\n\n\nURLs could be constructed which expanded environmental variables or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links.\n\n\nThis issue affects LibreOffice: from 24.8 before < 24.8.4.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12426" + }, + { + "type": "WEB", + "url": "https://www.libreoffice.org/about-us/security/advisories/cve-2024-12426" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T13:15:07Z" + } +} \ No newline at end of file