diff --git a/advisories/unreviewed/2025/01/GHSA-c5v2-8pm5-g9wp/GHSA-c5v2-8pm5-g9wp.json b/advisories/unreviewed/2025/01/GHSA-c5v2-8pm5-g9wp/GHSA-c5v2-8pm5-g9wp.json new file mode 100644 index 00000000000..c4c25e967b2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c5v2-8pm5-g9wp/GHSA-c5v2-8pm5-g9wp.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5v2-8pm5-g9wp", + "modified": "2025-01-05T21:30:30Z", + "published": "2025-01-05T21:30:30Z", + "aliases": [ + "CVE-2025-0229" + ], + "details": "A vulnerability, which was classified as critical, has been found in code-projects Travel Management System 1.0. This issue affects some unknown processing of the file /enquiry.php. The manipulation of the argument pid/t1/t2/t3/t4/t5/t6/t7 leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0229" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/Huandtx/cve/blob/main/cve/sql1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290225" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290225" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.474572" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-05T20:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hvj6-6hh6-hg48/GHSA-hvj6-6hh6-hg48.json b/advisories/unreviewed/2025/01/GHSA-hvj6-6hh6-hg48/GHSA-hvj6-6hh6-hg48.json new file mode 100644 index 00000000000..776093b68e5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hvj6-6hh6-hg48/GHSA-hvj6-6hh6-hg48.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvj6-6hh6-hg48", + "modified": "2025-01-05T21:30:30Z", + "published": "2025-01-05T21:30:30Z", + "aliases": [ + "CVE-2025-0230" + ], + "details": "A vulnerability, which was classified as critical, was found in code-projects Responsive Hotel Site 1.0. Affected is an unknown function of the file /admin/print.php. The manipulation of the argument pid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0230" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/Huandtx/cve/blob/main/cve/Responsive%20Hotel%20Site/sql1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290226" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290226" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.474581" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-05T21:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jh5q-pr4q-x6j4/GHSA-jh5q-pr4q-x6j4.json b/advisories/unreviewed/2025/01/GHSA-jh5q-pr4q-x6j4/GHSA-jh5q-pr4q-x6j4.json new file mode 100644 index 00000000000..581df47606e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jh5q-pr4q-x6j4/GHSA-jh5q-pr4q-x6j4.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jh5q-pr4q-x6j4", + "modified": "2025-01-05T21:30:30Z", + "published": "2025-01-05T21:30:30Z", + "aliases": [ + "CVE-2025-0228" + ], + "details": "A vulnerability has been found in code-projects Local Storage Todo App 1.0 and classified as problematic. This vulnerability affects unknown code of the file /js-todo-app/index.html. The manipulation of the argument Add leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0228" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290218" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290218" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.474049" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-05T19:15:06Z" + } +} \ No newline at end of file