From 8e34e59ac2ff99e2269a9a4d67ff80e50a37402e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 2 Jan 2025 06:32:35 +0000 Subject: [PATCH] Publish Advisories GHSA-33c4-c7ch-qm8j GHSA-66fj-74pq-7rwx GHSA-6gg3-5p97-3cp8 GHSA-99f2-vhmm-9fw8 GHSA-j77f-79w9-rghc GHSA-pm3j-mqcc-rjqr GHSA-wpxf-7pwx-p92p --- .../GHSA-33c4-c7ch-qm8j.json | 36 +++++++++++++++ .../GHSA-66fj-74pq-7rwx.json | 36 +++++++++++++++ .../GHSA-6gg3-5p97-3cp8.json | 29 ++++++++++++ .../GHSA-99f2-vhmm-9fw8.json | 40 +++++++++++++++++ .../GHSA-j77f-79w9-rghc.json | 29 ++++++++++++ .../GHSA-pm3j-mqcc-rjqr.json | 44 +++++++++++++++++++ .../GHSA-wpxf-7pwx-p92p.json | 29 ++++++++++++ 7 files changed, 243 insertions(+) create mode 100644 advisories/unreviewed/2025/01/GHSA-33c4-c7ch-qm8j/GHSA-33c4-c7ch-qm8j.json create mode 100644 advisories/unreviewed/2025/01/GHSA-66fj-74pq-7rwx/GHSA-66fj-74pq-7rwx.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6gg3-5p97-3cp8/GHSA-6gg3-5p97-3cp8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-99f2-vhmm-9fw8/GHSA-99f2-vhmm-9fw8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-j77f-79w9-rghc/GHSA-j77f-79w9-rghc.json create mode 100644 advisories/unreviewed/2025/01/GHSA-pm3j-mqcc-rjqr/GHSA-pm3j-mqcc-rjqr.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wpxf-7pwx-p92p/GHSA-wpxf-7pwx-p92p.json diff --git a/advisories/unreviewed/2025/01/GHSA-33c4-c7ch-qm8j/GHSA-33c4-c7ch-qm8j.json b/advisories/unreviewed/2025/01/GHSA-33c4-c7ch-qm8j/GHSA-33c4-c7ch-qm8j.json new file mode 100644 index 00000000000..14c4a820fbb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-33c4-c7ch-qm8j/GHSA-33c4-c7ch-qm8j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33c4-c7ch-qm8j", + "modified": "2025-01-02T06:30:47Z", + "published": "2025-01-02T06:30:47Z", + "aliases": [ + "CVE-2025-22214" + ], + "details": "Landray EIS 2001 through 2006 allows Message/fi_message_receiver.aspx?replyid= SQL injection.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22214" + }, + { + "type": "WEB", + "url": "https://github.com/Zerone0x00/CVE/blob/main/%E8%93%9D%E5%87%8CEISsql%E6%B3%A8%E5%85%A5/1.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T04:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-66fj-74pq-7rwx/GHSA-66fj-74pq-7rwx.json b/advisories/unreviewed/2025/01/GHSA-66fj-74pq-7rwx/GHSA-66fj-74pq-7rwx.json new file mode 100644 index 00000000000..91c35df9f85 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-66fj-74pq-7rwx/GHSA-66fj-74pq-7rwx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66fj-74pq-7rwx", + "modified": "2025-01-02T06:30:47Z", + "published": "2025-01-02T06:30:47Z", + "aliases": [ + "CVE-2024-56829" + ], + "details": "Huang Yaoshi Pharmaceutical Management Software through 16.0 allows arbitrary file upload via a .asp filename in the fileName element of the UploadFile element in a SOAP request to /XSDService.asmx.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56829" + }, + { + "type": "WEB", + "url": "https://github.com/Zerone0x00/CVE/blob/main/%E9%BB%84%E8%8D%AF%E5%B8%88%E8%8D%AF%E4%B8%9A%E7%AE%A1%E7%90%86%E8%BD%AF%E4%BB%B6/UploadFile%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T04:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6gg3-5p97-3cp8/GHSA-6gg3-5p97-3cp8.json b/advisories/unreviewed/2025/01/GHSA-6gg3-5p97-3cp8/GHSA-6gg3-5p97-3cp8.json new file mode 100644 index 00000000000..50725930741 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6gg3-5p97-3cp8/GHSA-6gg3-5p97-3cp8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gg3-5p97-3cp8", + "modified": "2025-01-02T06:30:47Z", + "published": "2025-01-02T06:30:47Z", + "aliases": [ + "CVE-2024-12595" + ], + "details": "The AHAthat Plugin WordPress plugin through 1.6 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12595" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/7a506438-3106-477f-816d-b9b116ec8555" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-99f2-vhmm-9fw8/GHSA-99f2-vhmm-9fw8.json b/advisories/unreviewed/2025/01/GHSA-99f2-vhmm-9fw8/GHSA-99f2-vhmm-9fw8.json new file mode 100644 index 00000000000..90c96d4a786 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-99f2-vhmm-9fw8/GHSA-99f2-vhmm-9fw8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99f2-vhmm-9fw8", + "modified": "2025-01-02T06:30:47Z", + "published": "2025-01-02T06:30:47Z", + "aliases": [ + "CVE-2024-56830" + ], + "details": "The Net::EasyTCP package 0.15 through 0.26 for Perl uses Perl's builtin rand() if no strong randomization module is present.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56830" + }, + { + "type": "WEB", + "url": "https://github.com/briandfoy/cpan-security-advisory/issues/184" + }, + { + "type": "WEB", + "url": "https://metacpan.org/release/MNAGUIB/EasyTCP-0.26/changes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-338" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j77f-79w9-rghc/GHSA-j77f-79w9-rghc.json b/advisories/unreviewed/2025/01/GHSA-j77f-79w9-rghc/GHSA-j77f-79w9-rghc.json new file mode 100644 index 00000000000..2498befc311 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j77f-79w9-rghc/GHSA-j77f-79w9-rghc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j77f-79w9-rghc", + "modified": "2025-01-02T06:30:47Z", + "published": "2025-01-02T06:30:47Z", + "aliases": [ + "CVE-2024-11184" + ], + "details": "The wp-enable-svg WordPress plugin through 0.7 does not sanitize SVG files when uploaded, allowing for authors and above to upload SVGs containing malicious scripts", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11184" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/fc982bcb-9974-481f-aef4-580ae9edc3c8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T06:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pm3j-mqcc-rjqr/GHSA-pm3j-mqcc-rjqr.json b/advisories/unreviewed/2025/01/GHSA-pm3j-mqcc-rjqr/GHSA-pm3j-mqcc-rjqr.json new file mode 100644 index 00000000000..b1a3b18c14c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pm3j-mqcc-rjqr/GHSA-pm3j-mqcc-rjqr.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pm3j-mqcc-rjqr", + "modified": "2025-01-02T06:30:47Z", + "published": "2025-01-02T06:30:47Z", + "aliases": [ + "CVE-2002-20002" + ], + "details": "The Net::EasyTCP package before 0.15 for Perl always uses Perl's builtin rand(), which is not a strong random number generator, for cryptographic keys.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2002-20002" + }, + { + "type": "WEB", + "url": "https://github.com/briandfoy/cpan-security-advisory/issues/184" + }, + { + "type": "WEB", + "url": "https://metacpan.org/release/MNAGUIB/EasyTCP-0.15/view/EasyTCP.pm" + }, + { + "type": "WEB", + "url": "https://metacpan.org/release/MNAGUIB/EasyTCP-0.26/changes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-338" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T05:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wpxf-7pwx-p92p/GHSA-wpxf-7pwx-p92p.json b/advisories/unreviewed/2025/01/GHSA-wpxf-7pwx-p92p/GHSA-wpxf-7pwx-p92p.json new file mode 100644 index 00000000000..6a4bb001a70 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wpxf-7pwx-p92p/GHSA-wpxf-7pwx-p92p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpxf-7pwx-p92p", + "modified": "2025-01-02T06:30:47Z", + "published": "2025-01-02T06:30:47Z", + "aliases": [ + "CVE-2024-11357" + ], + "details": "The goodlayers-core WordPress plugin before 2.0.10 does not sanitise and escape some of its settings, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11357" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/7e8c6816-9b7a-43e8-9508-789c8051dd9b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T06:15:07Z" + } +} \ No newline at end of file