From 81dbde18389f27886cf9f4e0da99302b9b1a95d2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sun, 18 May 2025 21:31:27 +0000 Subject: [PATCH] Publish Advisories GHSA-2445-4c8x-52p7 GHSA-7jr4-6h99-wvp2 GHSA-cp28-vxmv-5fj9 GHSA-f333-vhwv-jvmx GHSA-fhgm-mxgh-gfpj GHSA-h27g-3gmj-f4j6 GHSA-j2rh-9hjf-9v46 GHSA-qpr4-2qj4-54m8 --- .../GHSA-2445-4c8x-52p7.json | 46 +++++++++++++++ .../GHSA-7jr4-6h99-wvp2.json | 52 +++++++++++++++++ .../GHSA-cp28-vxmv-5fj9.json | 56 +++++++++++++++++++ .../GHSA-f333-vhwv-jvmx.json | 10 +++- .../GHSA-fhgm-mxgh-gfpj.json | 10 +++- .../GHSA-h27g-3gmj-f4j6.json | 56 +++++++++++++++++++ .../GHSA-j2rh-9hjf-9v46.json | 56 +++++++++++++++++++ .../GHSA-qpr4-2qj4-54m8.json | 56 +++++++++++++++++++ 8 files changed, 340 insertions(+), 2 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-2445-4c8x-52p7/GHSA-2445-4c8x-52p7.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7jr4-6h99-wvp2/GHSA-7jr4-6h99-wvp2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-cp28-vxmv-5fj9/GHSA-cp28-vxmv-5fj9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-h27g-3gmj-f4j6/GHSA-h27g-3gmj-f4j6.json create mode 100644 advisories/unreviewed/2025/05/GHSA-j2rh-9hjf-9v46/GHSA-j2rh-9hjf-9v46.json create mode 100644 advisories/unreviewed/2025/05/GHSA-qpr4-2qj4-54m8/GHSA-qpr4-2qj4-54m8.json diff --git a/advisories/unreviewed/2025/05/GHSA-2445-4c8x-52p7/GHSA-2445-4c8x-52p7.json b/advisories/unreviewed/2025/05/GHSA-2445-4c8x-52p7/GHSA-2445-4c8x-52p7.json new file mode 100644 index 00000000000..5db22ad664e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2445-4c8x-52p7/GHSA-2445-4c8x-52p7.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2445-4c8x-52p7", + "modified": "2025-05-18T21:30:20Z", + "published": "2025-05-18T21:30:20Z", + "aliases": [ + "CVE-2025-4894" + ], + "details": "A vulnerability classified as problematic was found in calmkart Django-sso-server up to 057247929a94ffc358788a37ab99e391379a4d15. This vulnerability affects the function gen_rsa_keys of the file common/crypto.py. The manipulation leads to inadequate encryption strength. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4894" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309448" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309448" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.578019" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-18T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7jr4-6h99-wvp2/GHSA-7jr4-6h99-wvp2.json b/advisories/unreviewed/2025/05/GHSA-7jr4-6h99-wvp2/GHSA-7jr4-6h99-wvp2.json new file mode 100644 index 00000000000..8ac76a089f3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7jr4-6h99-wvp2/GHSA-7jr4-6h99-wvp2.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jr4-6h99-wvp2", + "modified": "2025-05-18T21:30:20Z", + "published": "2025-05-18T21:30:20Z", + "aliases": [ + "CVE-2025-4893" + ], + "details": "A vulnerability classified as critical has been found in jammy928 CoinExchange_CryptoExchange_Java up to 8adf508b996020d3efbeeb2473d7235bd01436fa. This affects the function uploadLocalImage of the file /CoinExchange_CryptoExchange_Java-master/00_framework/core/src/main/java/com/bizzan/bitrade/util/UploadFileUtil.java of the component File Upload Endpoint. The manipulation of the argument filename leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4893" + }, + { + "type": "WEB", + "url": "https://github.com/ShenxiuSec/cve-proofs/blob/main/POC-20250515-01.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309447" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309447" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.577907" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-18T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cp28-vxmv-5fj9/GHSA-cp28-vxmv-5fj9.json b/advisories/unreviewed/2025/05/GHSA-cp28-vxmv-5fj9/GHSA-cp28-vxmv-5fj9.json new file mode 100644 index 00000000000..1bfe6252e4c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cp28-vxmv-5fj9/GHSA-cp28-vxmv-5fj9.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp28-vxmv-5fj9", + "modified": "2025-05-18T21:30:20Z", + "published": "2025-05-18T21:30:20Z", + "aliases": [ + "CVE-2025-4895" + ], + "details": "A vulnerability, which was classified as critical, has been found in SourceCodester Doctors Appointment System 1.0. This issue affects some unknown processing of the file /admin/delete-session.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4895" + }, + { + "type": "WEB", + "url": "https://github.com/Xiaoyi-ing/CVE/issues/11" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309449" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309449" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.578022" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-18T21:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f333-vhwv-jvmx/GHSA-f333-vhwv-jvmx.json b/advisories/unreviewed/2025/05/GHSA-f333-vhwv-jvmx/GHSA-f333-vhwv-jvmx.json index 46583ea17f2..6f43e45e7bb 100644 --- a/advisories/unreviewed/2025/05/GHSA-f333-vhwv-jvmx/GHSA-f333-vhwv-jvmx.json +++ b/advisories/unreviewed/2025/05/GHSA-f333-vhwv-jvmx/GHSA-f333-vhwv-jvmx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f333-vhwv-jvmx", - "modified": "2025-05-18T00:30:27Z", + "modified": "2025-05-18T21:30:20Z", "published": "2025-05-18T00:30:27Z", "aliases": [ "CVE-2025-4919" @@ -18,6 +18,14 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1966614" }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-36" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-37" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2025-38" diff --git a/advisories/unreviewed/2025/05/GHSA-fhgm-mxgh-gfpj/GHSA-fhgm-mxgh-gfpj.json b/advisories/unreviewed/2025/05/GHSA-fhgm-mxgh-gfpj/GHSA-fhgm-mxgh-gfpj.json index 975f1a00162..dff32291c60 100644 --- a/advisories/unreviewed/2025/05/GHSA-fhgm-mxgh-gfpj/GHSA-fhgm-mxgh-gfpj.json +++ b/advisories/unreviewed/2025/05/GHSA-fhgm-mxgh-gfpj/GHSA-fhgm-mxgh-gfpj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fhgm-mxgh-gfpj", - "modified": "2025-05-18T00:30:27Z", + "modified": "2025-05-18T21:30:20Z", "published": "2025-05-18T00:30:27Z", "aliases": [ "CVE-2025-4918" @@ -18,6 +18,14 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1966612" }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-36" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2025-37" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2025-38" diff --git a/advisories/unreviewed/2025/05/GHSA-h27g-3gmj-f4j6/GHSA-h27g-3gmj-f4j6.json b/advisories/unreviewed/2025/05/GHSA-h27g-3gmj-f4j6/GHSA-h27g-3gmj-f4j6.json new file mode 100644 index 00000000000..13dd1156f4b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h27g-3gmj-f4j6/GHSA-h27g-3gmj-f4j6.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h27g-3gmj-f4j6", + "modified": "2025-05-18T21:30:20Z", + "published": "2025-05-18T21:30:20Z", + "aliases": [ + "CVE-2025-4896" + ], + "details": "A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/UserCongratulationsExec. The manipulation of the argument getuid leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4896" + }, + { + "type": "WEB", + "url": "https://github.com/byxs0x0/cve2/blob/main/Tenda%20AC10.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309452" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309452" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.578034" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-18T21:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j2rh-9hjf-9v46/GHSA-j2rh-9hjf-9v46.json b/advisories/unreviewed/2025/05/GHSA-j2rh-9hjf-9v46/GHSA-j2rh-9hjf-9v46.json new file mode 100644 index 00000000000..f08b4c08972 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j2rh-9hjf-9v46/GHSA-j2rh-9hjf-9v46.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2rh-9hjf-9v46", + "modified": "2025-05-18T21:30:20Z", + "published": "2025-05-18T21:30:20Z", + "aliases": [ + "CVE-2025-4892" + ], + "details": "A vulnerability was found in code-projects Police Station Management System 1.0. It has been declared as critical. Affected by this vulnerability is the function criminal::remove of the file source.cpp of the component Delete Record. The manipulation of the argument No leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4892" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/zzzxc643/cve/blob/main/Police-StationManagementSystem2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309445" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309445" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.577501" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-18T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qpr4-2qj4-54m8/GHSA-qpr4-2qj4-54m8.json b/advisories/unreviewed/2025/05/GHSA-qpr4-2qj4-54m8/GHSA-qpr4-2qj4-54m8.json new file mode 100644 index 00000000000..90b39d5b2a2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qpr4-2qj4-54m8/GHSA-qpr4-2qj4-54m8.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpr4-2qj4-54m8", + "modified": "2025-05-18T21:30:20Z", + "published": "2025-05-18T21:30:20Z", + "aliases": [ + "CVE-2025-4891" + ], + "details": "A vulnerability was found in code-projects Police Station Management System 1.0. It has been classified as critical. Affected is the function criminal::display of the file source.cpp of the component Display Record. The manipulation of the argument N leads to buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4891" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/zzzxc643/cve/blob/main/Police-StationManagementSystem.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309444" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309444" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.577500" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-18T19:15:19Z" + } +} \ No newline at end of file