Publish Advisories

GHSA-8jm2-4r4f-748v
GHSA-q7m5-4xhc-7xfr
GHSA-qjrx-78jp-x72f
GHSA-32p9-v6w3-v6fj
GHSA-523h-xj4w-6jhm
GHSA-5752-jhh8-x4vc
GHSA-5vf7-798g-m8fj
GHSA-5xpq-j82h-xf63
GHSA-9x9g-g3c2-6rw9
GHSA-jcfc-jphx-4xvv
GHSA-m8rx-f843-vqgg
GHSA-prjg-m4m7-6g42
GHSA-qv6w-444m-m6w6
GHSA-v9j3-cm39-6hmg
This commit is contained in:
advisory-database[bot]
2025-03-28 09:32:07 +00:00
parent b81e3256f8
commit 88a76140bb
14 changed files with 509 additions and 3 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8jm2-4r4f-748v",
"modified": "2024-11-04T15:31:53Z",
"modified": "2025-03-28T09:30:30Z",
"published": "2024-03-25T06:30:23Z",
"aliases": [
"CVE-2024-29071"
@@ -23,6 +23,10 @@
"type": "WEB",
"url": "https://jvn.jp/en/vu/JVNVU93546510"
},
{
"type": "WEB",
"url": "https://kddi-tech.com/contents/appendix_L2_06.html#20304f4c-af1b-49fd-c3b5-8d1f55fd8b4f"
},
{
"type": "WEB",
"url": "https://www.au.com/support/service/internet/guide/modem/bl1500hm/firmware"
@@ -30,6 +34,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1391",
"CWE-522"
],
"severity": "HIGH",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q7m5-4xhc-7xfr",
"modified": "2024-10-27T06:30:46Z",
"modified": "2025-03-28T09:30:30Z",
"published": "2024-03-25T06:30:24Z",
"aliases": [
"CVE-2024-21865"
@@ -23,6 +23,10 @@
"type": "WEB",
"url": "https://jvn.jp/en/vu/JVNVU93546510"
},
{
"type": "WEB",
"url": "https://kddi-tech.com/contents/appendix_L2_06.html#20304f4c-af1b-49fd-c3b5-8d1f55fd8b4f"
},
{
"type": "WEB",
"url": "https://www.au.com/support/service/internet/guide/modem/bl1500hm/firmware"
@@ -30,6 +34,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-1391",
"CWE-521"
],
"severity": "MODERATE",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qjrx-78jp-x72f",
"modified": "2024-08-01T15:31:34Z",
"modified": "2025-03-28T09:30:29Z",
"published": "2024-03-25T06:30:23Z",
"aliases": [
"CVE-2024-28041"
@@ -23,6 +23,10 @@
"type": "WEB",
"url": "https://jvn.jp/en/vu/JVNVU93546510"
},
{
"type": "WEB",
"url": "https://kddi-tech.com/contents/appendix_L2_06.html#20304f4c-af1b-49fd-c3b5-8d1f55fd8b4f"
},
{
"type": "WEB",
"url": "https://www.au.com/support/service/internet/guide/modem/bl1500hm/firmware"
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-32p9-v6w3-v6fj",
"modified": "2025-03-28T09:30:30Z",
"published": "2025-03-28T09:30:30Z",
"aliases": [
"CVE-2025-27718"
],
"details": "Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file upload process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, the product's files may be obtained and/or altered or arbitrary code may be executed by a crafted HTTP request to specific functions of the product from a device connected to the LAN side.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27718"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN04278547"
},
{
"type": "WEB",
"url": "https://kddi-tech.com/contents/appendix_L2_06.html#64433e4a-8946-9c06-bddf-91cbfe56c8e5"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-28T09:15:14Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-523h-xj4w-6jhm",
"modified": "2025-03-28T09:30:30Z",
"published": "2025-03-28T09:30:30Z",
"aliases": [
"CVE-2025-27567"
],
"details": "Cross-site scripting vulnerability exists in the NickName registration screen of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the configuration page or functions accessible only from the LAN side of the product.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27567"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN04278547"
},
{
"type": "WEB",
"url": "https://kddi-tech.com/contents/appendix_L2_06.html#64433e4a-8946-9c06-bddf-91cbfe56c8e5"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-28T09:15:14Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5752-jhh8-x4vc",
"modified": "2025-03-28T09:30:30Z",
"published": "2025-03-28T09:30:30Z",
"aliases": [
"CVE-2025-27932"
],
"details": "Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file deletion process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, an attacker may delete a file on the device or cause a denial of service (DoS) condition.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27932"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN04278547"
},
{
"type": "WEB",
"url": "https://kddi-tech.com/contents/appendix_L2_06.html#64433e4a-8946-9c06-bddf-91cbfe56c8e5"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-28T09:15:14Z"
}
}
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5vf7-798g-m8fj",
"modified": "2025-03-28T09:30:30Z",
"published": "2025-03-28T09:30:30Z",
"aliases": [
"CVE-2025-1705"
],
"details": "The tagDiv Composer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3. This is due to missing or incorrect nonce validation within the td_ajax_get_views AJAX action. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1705"
},
{
"type": "WEB",
"url": "https://tagdiv.com/newspaper-changelog"
},
{
"type": "WEB",
"url": "https://tagdiv.com/tagdiv-composer-page-builder-basics"
},
{
"type": "WEB",
"url": "https://themeforest.net/item/newspaper/5489609"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2aaa8c34-cf7b-4630-adc8-cbb534deff89?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-28T09:15:13Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5xpq-j82h-xf63",
"modified": "2025-03-28T09:30:30Z",
"published": "2025-03-28T09:30:30Z",
"aliases": [
"CVE-2025-27726"
],
"details": "Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file download process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, the product's files may be obtained and/or altered by a crafted HTTP request to specific functions of the product from a device connected to the LAN side.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27726"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN04278547"
},
{
"type": "WEB",
"url": "https://kddi-tech.com/contents/appendix_L2_06.html#64433e4a-8946-9c06-bddf-91cbfe56c8e5"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-28T09:15:14Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9x9g-g3c2-6rw9",
"modified": "2025-03-28T09:30:30Z",
"published": "2025-03-28T09:30:30Z",
"aliases": [
"CVE-2025-27716"
],
"details": "Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file/folder listing process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, the product's files may be obtained and/or altered by a crafted HTTP request to specific functions of the product from a device connected to the LAN side.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27716"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN04278547"
},
{
"type": "WEB",
"url": "https://kddi-tech.com/contents/appendix_L2_06.html#64433e4a-8946-9c06-bddf-91cbfe56c8e5"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-28T09:15:14Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jcfc-jphx-4xvv",
"modified": "2025-03-28T09:30:30Z",
"published": "2025-03-28T09:30:30Z",
"aliases": [
"CVE-2025-2328"
],
"details": "The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'dnd_remove_uploaded_files' function in all versions up to, and including, 1.3.8.7. This makes it possible for unauthenticated attackers to add arbitrary file paths (such as ../../../../wp-config.php) to uploaded files on the server, which can easily lead to remote code execution when an Administrator deletes the message. Exploiting this vulnerability requires the Flamingo plugin to be installed and activated.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2328"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/drag-and-drop-multiple-file-upload-contact-form-7/trunk/inc/dnd-upload-cf7.php#L153"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3261964"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0f6cca7a-b8ff-4ca5-b813-e611eac07695?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-28T07:15:39Z"
}
}
@@ -0,0 +1,64 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m8rx-f843-vqgg",
"modified": "2025-03-28T09:30:30Z",
"published": "2025-03-28T09:30:30Z",
"aliases": [
"CVE-2025-2074"
],
"details": "The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to generic SQL Injection via the sSearch parameter in all versions up to, and including, 1.29 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries, particularly when the plugins settings page hasnt been visited and its welcome message has not been dismissed. This issue can be used to extract sensitive information from the database.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2074"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/advanced-google-recaptcha/trunk/libs/admin.php?rev=3248228#L106"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/advanced-google-recaptcha/trunk/libs/ajax.php?rev=3248228#L20"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/advanced-google-recaptcha/trunk/libs/ajax.php?rev=3248228#L277"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/advanced-google-recaptcha/trunk/libs/ajax.php?rev=3248228#L401"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/advanced-google-recaptcha/trunk/libs/setup.php?rev=3248228#L636"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3262396"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/advanced-google-recaptcha/#developers"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/963a9b30-9194-4abc-aa69-eb333cbddef3?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-28T08:15:15Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-prjg-m4m7-6g42",
"modified": "2025-03-28T09:30:30Z",
"published": "2025-03-28T09:30:30Z",
"aliases": [
"CVE-2025-27574"
],
"details": "Cross-site scripting vulnerability exists in the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the configuration page or functions accessible only from the LAN side of the product.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:P/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27574"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN04278547"
},
{
"type": "WEB",
"url": "https://kddi-tech.com/contents/appendix_L2_06.html#64433e4a-8946-9c06-bddf-91cbfe56c8e5"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-28T09:15:14Z"
}
}
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qv6w-444m-m6w6",
"modified": "2025-03-28T09:30:30Z",
"published": "2025-03-28T09:30:30Z",
"aliases": [
"CVE-2025-2485"
],
"details": "The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8.7 via deserialization of untrusted input from the 'dnd_upload_cf7_upload'\n function. This makes it possible for attackers to inject a PHP Object through a PHAR file. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. This vulnerability may be exploited by unauthenticated attackers when a form is present on the site with the file upload action. The Flamingo plugin must be installed and activated in order to exploit the vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2485"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/drag-and-drop-multiple-file-upload-contact-form-7/trunk/inc/dnd-upload-cf7.php#L25"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/drag-and-drop-multiple-file-upload-contact-form-7/trunk/inc/dnd-upload-cf7.php#L844"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3261964"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/79ffe548-0005-4f5e-873f-a1afec64a251?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-28T07:15:39Z"
}
}
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v9j3-cm39-6hmg",
"modified": "2025-03-28T09:30:30Z",
"published": "2025-03-28T09:30:30Z",
"aliases": [
"CVE-2025-2578"
],
"details": "The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.19 via the 'wpAmeliaApiCall' function. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2578"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/ameliabooking/trunk/ameliabooking.php#L172"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/ameliabooking/trunk/src/Application/Commands/Entities/GetEntitiesCommandHandler.php#L127"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3261318"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6806e07b-96bf-43ad-a3ac-2105e7449e3c?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-28T08:15:15Z"
}
}