From 73826d1f71f06b948f9c8115b10258f071cd5477 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 7 Apr 2025 09:32:02 +0000 Subject: [PATCH] Publish Advisories GHSA-7576-jc69-87m3 GHSA-7hr2-9rf8-gx6q GHSA-x464-67pg-rxcc GHSA-v85x-rrgc-699v GHSA-m39v-c9r9-vmwh GHSA-4cw8-8gfg-9xm5 GHSA-5r62-mjf5-xwhj GHSA-cfp6-9cf4-xhvc GHSA-j2gf-g3mw-7r5v GHSA-j322-6qx5-mxw2 GHSA-j8hv-qq9w-2x29 GHSA-j8rw-3x8v-v327 GHSA-vfg7-232g-q3r5 GHSA-w85p-m37q-fvfw --- .../GHSA-7576-jc69-87m3.json | 6 ++- .../GHSA-7hr2-9rf8-gx6q.json | 10 +++- .../GHSA-x464-67pg-rxcc.json | 10 +++- .../GHSA-v85x-rrgc-699v.json | 6 ++- .../GHSA-m39v-c9r9-vmwh.json | 6 ++- .../GHSA-4cw8-8gfg-9xm5.json | 52 +++++++++++++++++++ .../GHSA-5r62-mjf5-xwhj.json | 51 ++++++++++++++++++ .../GHSA-cfp6-9cf4-xhvc.json | 52 +++++++++++++++++++ .../GHSA-j2gf-g3mw-7r5v.json | 52 +++++++++++++++++++ .../GHSA-j322-6qx5-mxw2.json | 52 +++++++++++++++++++ .../GHSA-j8hv-qq9w-2x29.json | 52 +++++++++++++++++++ .../GHSA-j8rw-3x8v-v327.json | 6 ++- .../GHSA-vfg7-232g-q3r5.json | 52 +++++++++++++++++++ .../GHSA-w85p-m37q-fvfw.json | 36 +++++++++++++ 14 files changed, 437 insertions(+), 6 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-4cw8-8gfg-9xm5/GHSA-4cw8-8gfg-9xm5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5r62-mjf5-xwhj/GHSA-5r62-mjf5-xwhj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cfp6-9cf4-xhvc/GHSA-cfp6-9cf4-xhvc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j2gf-g3mw-7r5v/GHSA-j2gf-g3mw-7r5v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j322-6qx5-mxw2/GHSA-j322-6qx5-mxw2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j8hv-qq9w-2x29/GHSA-j8hv-qq9w-2x29.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vfg7-232g-q3r5/GHSA-vfg7-232g-q3r5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-w85p-m37q-fvfw/GHSA-w85p-m37q-fvfw.json diff --git a/advisories/unreviewed/2024/06/GHSA-7576-jc69-87m3/GHSA-7576-jc69-87m3.json b/advisories/unreviewed/2024/06/GHSA-7576-jc69-87m3/GHSA-7576-jc69-87m3.json index c0335444a61..74cab97f5a7 100644 --- a/advisories/unreviewed/2024/06/GHSA-7576-jc69-87m3/GHSA-7576-jc69-87m3.json +++ b/advisories/unreviewed/2024/06/GHSA-7576-jc69-87m3/GHSA-7576-jc69-87m3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7576-jc69-87m3", - "modified": "2024-06-19T15:30:54Z", + "modified": "2025-04-07T09:30:22Z", "published": "2024-06-19T15:30:54Z", "aliases": [ "CVE-2024-38611" @@ -14,6 +14,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38611" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/04d1086a62ac492ebb6bb0c94c1c8cb55f5d1f36" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/43fff07e4b1956d0e5cf23717507e438278ea3d9" diff --git a/advisories/unreviewed/2024/09/GHSA-7hr2-9rf8-gx6q/GHSA-7hr2-9rf8-gx6q.json b/advisories/unreviewed/2024/09/GHSA-7hr2-9rf8-gx6q/GHSA-7hr2-9rf8-gx6q.json index 5b1e4f15fae..f18074fe259 100644 --- a/advisories/unreviewed/2024/09/GHSA-7hr2-9rf8-gx6q/GHSA-7hr2-9rf8-gx6q.json +++ b/advisories/unreviewed/2024/09/GHSA-7hr2-9rf8-gx6q/GHSA-7hr2-9rf8-gx6q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7hr2-9rf8-gx6q", - "modified": "2024-09-23T18:30:34Z", + "modified": "2025-04-07T09:30:22Z", "published": "2024-09-18T09:30:37Z", "aliases": [ "CVE-2024-46772" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46772" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/04805efe8623f8721f3c01182ea73d68e88c62d8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b9264aa24f628eba5779d1c916441e0cedde9b3d" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/ea79068d4073bf303f8203f2625af7d9185a1bc6" diff --git a/advisories/unreviewed/2024/10/GHSA-x464-67pg-rxcc/GHSA-x464-67pg-rxcc.json b/advisories/unreviewed/2024/10/GHSA-x464-67pg-rxcc/GHSA-x464-67pg-rxcc.json index 6876440fa89..5463a1b5362 100644 --- a/advisories/unreviewed/2024/10/GHSA-x464-67pg-rxcc/GHSA-x464-67pg-rxcc.json +++ b/advisories/unreviewed/2024/10/GHSA-x464-67pg-rxcc/GHSA-x464-67pg-rxcc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x464-67pg-rxcc", - "modified": "2024-11-20T21:30:48Z", + "modified": "2025-04-07T09:30:22Z", "published": "2024-10-21T21:30:54Z", "aliases": [ "CVE-2024-50056" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50056" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/03fa71e97e9bb116993ec1d51b8a6fe776db0984" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/72a68d2bede3284b95ee93a5ab3a81758bba95b0" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/a7bb96b18864225a694e3887ac2733159489e4b0" diff --git a/advisories/unreviewed/2024/11/GHSA-v85x-rrgc-699v/GHSA-v85x-rrgc-699v.json b/advisories/unreviewed/2024/11/GHSA-v85x-rrgc-699v/GHSA-v85x-rrgc-699v.json index 80a3df1c34f..4281a4770c4 100644 --- a/advisories/unreviewed/2024/11/GHSA-v85x-rrgc-699v/GHSA-v85x-rrgc-699v.json +++ b/advisories/unreviewed/2024/11/GHSA-v85x-rrgc-699v/GHSA-v85x-rrgc-699v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v85x-rrgc-699v", - "modified": "2024-11-08T15:31:12Z", + "modified": "2025-04-07T09:30:22Z", "published": "2024-11-05T18:32:13Z", "aliases": [ "CVE-2024-50137" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/2cf59663660799ce16f4dfbed97cdceac7a7fa11" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3918b2016d28c9b2bddd5ab194ab366a4e2310f5" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/c923f1fb8ae8627322d167b73bb4f978404a05de" diff --git a/advisories/unreviewed/2024/12/GHSA-m39v-c9r9-vmwh/GHSA-m39v-c9r9-vmwh.json b/advisories/unreviewed/2024/12/GHSA-m39v-c9r9-vmwh/GHSA-m39v-c9r9-vmwh.json index 4df43f3f281..573e13f5b26 100644 --- a/advisories/unreviewed/2024/12/GHSA-m39v-c9r9-vmwh/GHSA-m39v-c9r9-vmwh.json +++ b/advisories/unreviewed/2024/12/GHSA-m39v-c9r9-vmwh/GHSA-m39v-c9r9-vmwh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m39v-c9r9-vmwh", - "modified": "2025-01-08T18:30:47Z", + "modified": "2025-04-07T09:30:23Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56620" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/64506b3d23a337e98a74b18dcb10c8619365f2bd" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f16a097047e38dcdd169a15e3eed1b2f2147a2e7" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/f99cb5f6344ef93777fd3add7979ebf291a852df" diff --git a/advisories/unreviewed/2025/04/GHSA-4cw8-8gfg-9xm5/GHSA-4cw8-8gfg-9xm5.json b/advisories/unreviewed/2025/04/GHSA-4cw8-8gfg-9xm5/GHSA-4cw8-8gfg-9xm5.json new file mode 100644 index 00000000000..78bcbfd9c76 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4cw8-8gfg-9xm5/GHSA-4cw8-8gfg-9xm5.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cw8-8gfg-9xm5", + "modified": "2025-04-07T09:30:23Z", + "published": "2025-04-07T09:30:23Z", + "aliases": [ + "CVE-2025-3342" + ], + "details": "A vulnerability has been found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/payment_save.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3342" + }, + { + "type": "WEB", + "url": "https://github.com/p1026/CVE/issues/57" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303556" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303556" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.551916" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T08:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5r62-mjf5-xwhj/GHSA-5r62-mjf5-xwhj.json b/advisories/unreviewed/2025/04/GHSA-5r62-mjf5-xwhj/GHSA-5r62-mjf5-xwhj.json new file mode 100644 index 00000000000..3081d6f43ab --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5r62-mjf5-xwhj/GHSA-5r62-mjf5-xwhj.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r62-mjf5-xwhj", + "modified": "2025-04-07T09:30:23Z", + "published": "2025-04-07T09:30:23Z", + "aliases": [ + "CVE-2025-30473" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Common SQL Provider.\n\nWhen using the partition clause in SQLTableCheckOperator as parameter (which was a recommended pattern), Authenticated UI User could inject arbitrary SQL command when triggering DAG exposing partition_clause to the user.\nThis allowed the DAG Triggering user to escalate privileges to execute those arbitrary commands which they normally would not have.\n\n\nThis issue affects Apache Airflow Common SQL Provider: before 1.24.1.\n\nUsers are recommended to upgrade to version 1.24.1, which fixes the issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30473" + }, + { + "type": "WEB", + "url": "https://github.com/apache/airflow/pull/48098" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/53klkv790cylqcop0350w7nfq1y6h0t2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/04/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/06/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/06/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/06/3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T09:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cfp6-9cf4-xhvc/GHSA-cfp6-9cf4-xhvc.json b/advisories/unreviewed/2025/04/GHSA-cfp6-9cf4-xhvc/GHSA-cfp6-9cf4-xhvc.json new file mode 100644 index 00000000000..c621a230b12 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cfp6-9cf4-xhvc/GHSA-cfp6-9cf4-xhvc.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfp6-9cf4-xhvc", + "modified": "2025-04-07T09:30:23Z", + "published": "2025-04-07T09:30:23Z", + "aliases": [ + "CVE-2025-3344" + ], + "details": "A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/assign_save.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3344" + }, + { + "type": "WEB", + "url": "https://github.com/p1026/CVE/issues/59" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303558" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303558" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.551918" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T09:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j2gf-g3mw-7r5v/GHSA-j2gf-g3mw-7r5v.json b/advisories/unreviewed/2025/04/GHSA-j2gf-g3mw-7r5v/GHSA-j2gf-g3mw-7r5v.json new file mode 100644 index 00000000000..2a2a85c39a0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j2gf-g3mw-7r5v/GHSA-j2gf-g3mw-7r5v.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2gf-g3mw-7r5v", + "modified": "2025-04-07T09:30:23Z", + "published": "2025-04-07T09:30:23Z", + "aliases": [ + "CVE-2025-3340" + ], + "details": "A vulnerability, which was classified as critical, has been found in codeprojects Online Restaurant Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/combo_update.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3340" + }, + { + "type": "WEB", + "url": "https://github.com/p1026/CVE/issues/55" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303554" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303554" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.551914" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T07:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j322-6qx5-mxw2/GHSA-j322-6qx5-mxw2.json b/advisories/unreviewed/2025/04/GHSA-j322-6qx5-mxw2/GHSA-j322-6qx5-mxw2.json new file mode 100644 index 00000000000..2a0a56b2d85 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j322-6qx5-mxw2/GHSA-j322-6qx5-mxw2.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j322-6qx5-mxw2", + "modified": "2025-04-07T09:30:23Z", + "published": "2025-04-07T09:30:23Z", + "aliases": [ + "CVE-2025-3343" + ], + "details": "A vulnerability was found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/reservation_update.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3343" + }, + { + "type": "WEB", + "url": "https://github.com/p1026/CVE/issues/58" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303557" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303557" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.551917" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T08:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j8hv-qq9w-2x29/GHSA-j8hv-qq9w-2x29.json b/advisories/unreviewed/2025/04/GHSA-j8hv-qq9w-2x29/GHSA-j8hv-qq9w-2x29.json new file mode 100644 index 00000000000..cfa73c3fdc4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j8hv-qq9w-2x29/GHSA-j8hv-qq9w-2x29.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8hv-qq9w-2x29", + "modified": "2025-04-07T09:30:23Z", + "published": "2025-04-07T09:30:23Z", + "aliases": [ + "CVE-2025-3345" + ], + "details": "A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/combo.php. The manipulation of the argument del leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3345" + }, + { + "type": "WEB", + "url": "https://github.com/p1026/CVE/issues/60" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303559" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303559" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.551919" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T09:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j8rw-3x8v-v327/GHSA-j8rw-3x8v-v327.json b/advisories/unreviewed/2025/04/GHSA-j8rw-3x8v-v327/GHSA-j8rw-3x8v-v327.json index 6c235d6c03e..88085e80681 100644 --- a/advisories/unreviewed/2025/04/GHSA-j8rw-3x8v-v327/GHSA-j8rw-3x8v-v327.json +++ b/advisories/unreviewed/2025/04/GHSA-j8rw-3x8v-v327/GHSA-j8rw-3x8v-v327.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j8rw-3x8v-v327", - "modified": "2025-04-01T18:30:51Z", + "modified": "2025-04-07T09:30:22Z", "published": "2025-04-01T18:30:51Z", "aliases": [ "CVE-2025-21918" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/592a0327d026a122e97e8e8bb7c60cbbe7697344" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7a735a8a46f6ebf898bbefd96659ca5da798bce0" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/b13abcb7ddd8d38de769486db5bd917537b32ab1" diff --git a/advisories/unreviewed/2025/04/GHSA-vfg7-232g-q3r5/GHSA-vfg7-232g-q3r5.json b/advisories/unreviewed/2025/04/GHSA-vfg7-232g-q3r5/GHSA-vfg7-232g-q3r5.json new file mode 100644 index 00000000000..5b703c2d4c1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vfg7-232g-q3r5/GHSA-vfg7-232g-q3r5.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfg7-232g-q3r5", + "modified": "2025-04-07T09:30:23Z", + "published": "2025-04-07T09:30:23Z", + "aliases": [ + "CVE-2025-3341" + ], + "details": "A vulnerability, which was classified as critical, was found in codeprojects Online Restaurant Management System 1.0. This affects an unknown part of the file /admin/reservation_view.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3341" + }, + { + "type": "WEB", + "url": "https://github.com/p1026/CVE/issues/56" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303555" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303555" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.551915" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T07:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w85p-m37q-fvfw/GHSA-w85p-m37q-fvfw.json b/advisories/unreviewed/2025/04/GHSA-w85p-m37q-fvfw/GHSA-w85p-m37q-fvfw.json new file mode 100644 index 00000000000..dcbf6fdffb8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w85p-m37q-fvfw/GHSA-w85p-m37q-fvfw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w85p-m37q-fvfw", + "modified": "2025-04-07T09:30:23Z", + "published": "2025-04-07T09:30:23Z", + "aliases": [ + "CVE-2024-11859" + ], + "details": "DLL Search Order Hijacking vulnerability potentially allowed an attacker with administrator privileges to load a malicious dynamic-link library and execute its code.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11859" + }, + { + "type": "WEB", + "url": "https://support.eset.com/en/ca8810-dll-search-order-hijacking-vulnerability-in-eset-products-for-windows-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T09:15:15Z" + } +} \ No newline at end of file