From 909c054bb4293ba6fc97644f20c1b3f99e621b4a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 25 Mar 2025 09:33:39 +0000 Subject: [PATCH] Publish Advisories GHSA-2935-2wfm-hhpv GHSA-2jqc-4vc4-2j4m GHSA-345v-qrhv-w227 GHSA-6gmq-j827-jv97 GHSA-6hxq-pcrc-rv2q GHSA-6r2v-grpr-6wv9 GHSA-6x45-4j6r-r8x8 GHSA-724h-5cwx-q5j4 GHSA-9r2v-hq4w-8pc6 GHSA-f7jq-jj4v-g9m5 GHSA-fc8r-2hc4-m2cc GHSA-g2h3-qrp9-2x4p GHSA-gvgr-wxrg-3hr3 GHSA-hppv-p84g-253f GHSA-p56m-pq92-4wxr GHSA-r6xg-mjqp-qqg4 GHSA-rxv9-287v-pp3r GHSA-v8f4-5r7f-6q9r GHSA-wvph-mf6h-fpww --- .../GHSA-2935-2wfm-hhpv.json | 40 +++++++++++ .../GHSA-2jqc-4vc4-2j4m.json | 56 +++++++++++++++ .../GHSA-345v-qrhv-w227.json | 56 +++++++++++++++ .../GHSA-6gmq-j827-jv97.json | 56 +++++++++++++++ .../GHSA-6hxq-pcrc-rv2q.json | 56 +++++++++++++++ .../GHSA-6r2v-grpr-6wv9.json | 40 +++++++++++ .../GHSA-6x45-4j6r-r8x8.json | 56 +++++++++++++++ .../GHSA-724h-5cwx-q5j4.json | 56 +++++++++++++++ .../GHSA-9r2v-hq4w-8pc6.json | 52 ++++++++++++++ .../GHSA-f7jq-jj4v-g9m5.json | 40 +++++++++++ .../GHSA-fc8r-2hc4-m2cc.json | 52 ++++++++++++++ .../GHSA-g2h3-qrp9-2x4p.json | 72 +++++++++++++++++++ .../GHSA-gvgr-wxrg-3hr3.json | 56 +++++++++++++++ .../GHSA-hppv-p84g-253f.json | 40 +++++++++++ .../GHSA-p56m-pq92-4wxr.json | 52 ++++++++++++++ .../GHSA-r6xg-mjqp-qqg4.json | 52 ++++++++++++++ .../GHSA-rxv9-287v-pp3r.json | 44 ++++++++++++ .../GHSA-v8f4-5r7f-6q9r.json | 40 +++++++++++ .../GHSA-wvph-mf6h-fpww.json | 48 +++++++++++++ 19 files changed, 964 insertions(+) create mode 100644 advisories/unreviewed/2025/03/GHSA-2935-2wfm-hhpv/GHSA-2935-2wfm-hhpv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2jqc-4vc4-2j4m/GHSA-2jqc-4vc4-2j4m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-345v-qrhv-w227/GHSA-345v-qrhv-w227.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6gmq-j827-jv97/GHSA-6gmq-j827-jv97.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6hxq-pcrc-rv2q/GHSA-6hxq-pcrc-rv2q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6r2v-grpr-6wv9/GHSA-6r2v-grpr-6wv9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6x45-4j6r-r8x8/GHSA-6x45-4j6r-r8x8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-724h-5cwx-q5j4/GHSA-724h-5cwx-q5j4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9r2v-hq4w-8pc6/GHSA-9r2v-hq4w-8pc6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f7jq-jj4v-g9m5/GHSA-f7jq-jj4v-g9m5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fc8r-2hc4-m2cc/GHSA-fc8r-2hc4-m2cc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g2h3-qrp9-2x4p/GHSA-g2h3-qrp9-2x4p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gvgr-wxrg-3hr3/GHSA-gvgr-wxrg-3hr3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hppv-p84g-253f/GHSA-hppv-p84g-253f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p56m-pq92-4wxr/GHSA-p56m-pq92-4wxr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r6xg-mjqp-qqg4/GHSA-r6xg-mjqp-qqg4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rxv9-287v-pp3r/GHSA-rxv9-287v-pp3r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v8f4-5r7f-6q9r/GHSA-v8f4-5r7f-6q9r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wvph-mf6h-fpww/GHSA-wvph-mf6h-fpww.json diff --git a/advisories/unreviewed/2025/03/GHSA-2935-2wfm-hhpv/GHSA-2935-2wfm-hhpv.json b/advisories/unreviewed/2025/03/GHSA-2935-2wfm-hhpv/GHSA-2935-2wfm-hhpv.json new file mode 100644 index 00000000000..0a8681a350b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2935-2wfm-hhpv/GHSA-2935-2wfm-hhpv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2935-2wfm-hhpv", + "modified": "2025-03-25T09:32:07Z", + "published": "2025-03-25T09:32:07Z", + "aliases": [ + "CVE-2025-2559" + ], + "details": "A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow indefinitely, leading to an OutOfMemoryError. This issue could result in a denial of service condition, preventing legitimate users from accessing the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2559" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-2559" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2353868" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T09:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2jqc-4vc4-2j4m/GHSA-2jqc-4vc4-2j4m.json b/advisories/unreviewed/2025/03/GHSA-2jqc-4vc4-2j4m/GHSA-2jqc-4vc4-2j4m.json new file mode 100644 index 00000000000..8078e7e8b73 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2jqc-4vc4-2j4m/GHSA-2jqc-4vc4-2j4m.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jqc-4vc4-2j4m", + "modified": "2025-03-25T09:32:06Z", + "published": "2025-03-25T09:32:06Z", + "aliases": [ + "CVE-2025-2752" + ], + "details": "A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/fast_atof.h of the component CSM File Handler. The manipulation leads to out-of-bounds read. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2752" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6013" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6013#issue-2877371176" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300857" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300857" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517786" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T08:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-345v-qrhv-w227/GHSA-345v-qrhv-w227.json b/advisories/unreviewed/2025/03/GHSA-345v-qrhv-w227/GHSA-345v-qrhv-w227.json new file mode 100644 index 00000000000..8a8af7bd3d0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-345v-qrhv-w227/GHSA-345v-qrhv-w227.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-345v-qrhv-w227", + "modified": "2025-03-25T09:32:06Z", + "published": "2025-03-25T09:32:06Z", + "aliases": [ + "CVE-2025-2751" + ], + "details": "A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation of the argument na leads to out-of-bounds read. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2751" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6012" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6012#issue-2877369817" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300856" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300856" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517785" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T08:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6gmq-j827-jv97/GHSA-6gmq-j827-jv97.json b/advisories/unreviewed/2025/03/GHSA-6gmq-j827-jv97/GHSA-6gmq-j827-jv97.json new file mode 100644 index 00000000000..8c5d3e41f2c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6gmq-j827-jv97/GHSA-6gmq-j827-jv97.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gmq-j827-jv97", + "modified": "2025-03-25T09:32:07Z", + "published": "2025-03-25T09:32:07Z", + "aliases": [ + "CVE-2025-2753" + ], + "details": "A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as critical. Affected is the function SceneCombiner::MergeScenes of the file code/AssetLib/LWS/LWSLoader.cpp of the component LWS File Handler. The manipulation leads to out-of-bounds read. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2753" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6014" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6014#issue-2877372462" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300858" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300858" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517787" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T09:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6hxq-pcrc-rv2q/GHSA-6hxq-pcrc-rv2q.json b/advisories/unreviewed/2025/03/GHSA-6hxq-pcrc-rv2q/GHSA-6hxq-pcrc-rv2q.json new file mode 100644 index 00000000000..8f676807ebd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6hxq-pcrc-rv2q/GHSA-6hxq-pcrc-rv2q.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hxq-pcrc-rv2q", + "modified": "2025-03-25T09:32:06Z", + "published": "2025-03-25T09:32:06Z", + "aliases": [ + "CVE-2025-2740" + ], + "details": "A vulnerability classified as critical has been found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/eligibility.php. The manipulation of the argument pagetitle leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2740" + }, + { + "type": "WEB", + "url": "https://github.com/guimo3/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300762" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300762" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.524733" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T07:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6r2v-grpr-6wv9/GHSA-6r2v-grpr-6wv9.json b/advisories/unreviewed/2025/03/GHSA-6r2v-grpr-6wv9/GHSA-6r2v-grpr-6wv9.json new file mode 100644 index 00000000000..b00f8504fd1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6r2v-grpr-6wv9/GHSA-6r2v-grpr-6wv9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r2v-grpr-6wv9", + "modified": "2025-03-25T09:32:07Z", + "published": "2025-03-25T09:32:06Z", + "aliases": [ + "CVE-2024-13710" + ], + "details": "The Estatebud – Properties & Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.5.0. This is due to missing or incorrect nonce validation on the 'estatebud_settings' page. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13710" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/estatebud-properties-listings" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c43f4c91-329d-46b9-b2c8-f35e5baa38d7?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T09:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6x45-4j6r-r8x8/GHSA-6x45-4j6r-r8x8.json b/advisories/unreviewed/2025/03/GHSA-6x45-4j6r-r8x8/GHSA-6x45-4j6r-r8x8.json new file mode 100644 index 00000000000..929b7993a95 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6x45-4j6r-r8x8/GHSA-6x45-4j6r-r8x8.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6x45-4j6r-r8x8", + "modified": "2025-03-25T09:32:06Z", + "published": "2025-03-25T09:32:06Z", + "aliases": [ + "CVE-2025-2750" + ], + "details": "A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation leads to out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2750" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6011" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6011#issue-2877369004" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300855" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300855" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517783" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T08:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-724h-5cwx-q5j4/GHSA-724h-5cwx-q5j4.json b/advisories/unreviewed/2025/03/GHSA-724h-5cwx-q5j4/GHSA-724h-5cwx-q5j4.json new file mode 100644 index 00000000000..b0cc738eb9e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-724h-5cwx-q5j4/GHSA-724h-5cwx-q5j4.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-724h-5cwx-q5j4", + "modified": "2025-03-25T09:32:07Z", + "published": "2025-03-25T09:32:07Z", + "aliases": [ + "CVE-2025-2755" + ], + "details": "A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as critical. Affected by this issue is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument src.entries leads to out-of-bounds read. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2755" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6017" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6017#issue-2877374161" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300860" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300860" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517789" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T09:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9r2v-hq4w-8pc6/GHSA-9r2v-hq4w-8pc6.json b/advisories/unreviewed/2025/03/GHSA-9r2v-hq4w-8pc6/GHSA-9r2v-hq4w-8pc6.json new file mode 100644 index 00000000000..e7d34d7bac8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9r2v-hq4w-8pc6/GHSA-9r2v-hq4w-8pc6.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r2v-hq4w-8pc6", + "modified": "2025-03-25T09:32:06Z", + "published": "2025-03-25T09:32:06Z", + "aliases": [ + "CVE-2025-2744" + ], + "details": "A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected is an unknown function of the file /admin-api/mp/material/upload-news-image of the component Material Upload Interface. The manipulation of the argument File leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2744" + }, + { + "type": "WEB", + "url": "https://github.com/uglory-gll/javasec/blob/main/ruoyi-vue-pro.md#7arbitrary-file-deletion-vulnerability---uploadnewsimage" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300846" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300846" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.519694" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T07:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f7jq-jj4v-g9m5/GHSA-f7jq-jj4v-g9m5.json b/advisories/unreviewed/2025/03/GHSA-f7jq-jj4v-g9m5/GHSA-f7jq-jj4v-g9m5.json new file mode 100644 index 00000000000..f2b60d0bc09 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f7jq-jj4v-g9m5/GHSA-f7jq-jj4v-g9m5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7jq-jj4v-g9m5", + "modified": "2025-03-25T09:32:05Z", + "published": "2025-03-25T09:32:05Z", + "aliases": [ + "CVE-2025-1320" + ], + "details": "The teachPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.0.9. This is due to missing or incorrect nonce validation on the import.php page. This makes it possible for unauthenticated attackers to delete imports via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1320" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/teachpress" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b677ad8b-4f01-4147-bcf6-ae769046be48?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T07:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fc8r-2hc4-m2cc/GHSA-fc8r-2hc4-m2cc.json b/advisories/unreviewed/2025/03/GHSA-fc8r-2hc4-m2cc/GHSA-fc8r-2hc4-m2cc.json new file mode 100644 index 00000000000..8de593c55b7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fc8r-2hc4-m2cc/GHSA-fc8r-2hc4-m2cc.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc8r-2hc4-m2cc", + "modified": "2025-03-25T09:32:05Z", + "published": "2025-03-25T09:32:05Z", + "aliases": [ + "CVE-2025-2252" + ], + "details": "The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.6.1 via the edd_ajax_get_download_title() function. This makes it possible for unauthenticated attackers to extract private post titles of downloads. The impact here is minimal.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2252" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/easy-digital-downloads/tags/3.3.6.1/includes/ajax-functions.php#L459" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/easy-digital-downloads/tags/3.3.6.1/includes/ajax-functions.php#L466" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3257409/easy-digital-downloads/trunk/includes/ajax-functions.php?contextall=1" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3257409/easy-digital-downloads/trunk/includes/ajax-functions.php?old=3226442&old_path=easy-digital-downloads%2Ftrunk%2Fincludes%2Fajax-functions.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9e0e3b81-55fe-46b2-bae1-d7321d74c485?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T07:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g2h3-qrp9-2x4p/GHSA-g2h3-qrp9-2x4p.json b/advisories/unreviewed/2025/03/GHSA-g2h3-qrp9-2x4p/GHSA-g2h3-qrp9-2x4p.json new file mode 100644 index 00000000000..21a76d2137b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g2h3-qrp9-2x4p/GHSA-g2h3-qrp9-2x4p.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2h3-qrp9-2x4p", + "modified": "2025-03-25T09:32:07Z", + "published": "2025-03-25T09:32:07Z", + "aliases": [ + "CVE-2025-2319" + ], + "details": "The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.11.13 to 5.25.08. This is due to missing or incorrect nonce validation on the 'ELISQLREPORTS_menu' function. This makes it possible for unauthenticated attackers to execute code on the server via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Version 5.25.10 adds a nonce check, which makes this vulnerability exploitable by admins only.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2319" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elisqlreports/tags/4..11.13/index.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elisqlreports/tags/4..11.15/index.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elisqlreports/tags/4..11.33/index.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elisqlreports/tags/4.11.37/index.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elisqlreports/tags/4.16.38/index.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elisqlreports/tags/4.17.38/index.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elisqlreports/tags/4.17.42/index.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elisqlreports/tags/5.21.35/index.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elisqlreports/tags/5.25.08/index.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/eade6ab0-ff79-4107-83ce-e85b37d97442?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T09:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gvgr-wxrg-3hr3/GHSA-gvgr-wxrg-3hr3.json b/advisories/unreviewed/2025/03/GHSA-gvgr-wxrg-3hr3/GHSA-gvgr-wxrg-3hr3.json new file mode 100644 index 00000000000..173a204a222 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gvgr-wxrg-3hr3/GHSA-gvgr-wxrg-3hr3.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvgr-wxrg-3hr3", + "modified": "2025-03-25T09:32:07Z", + "published": "2025-03-25T09:32:07Z", + "aliases": [ + "CVE-2025-2754" + ], + "details": "A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as critical. Affected by this vulnerability is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument it leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2754" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6015" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6015#issue-2877373501" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300859" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300859" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517788" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T09:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hppv-p84g-253f/GHSA-hppv-p84g-253f.json b/advisories/unreviewed/2025/03/GHSA-hppv-p84g-253f/GHSA-hppv-p84g-253f.json new file mode 100644 index 00000000000..5be317beedf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hppv-p84g-253f/GHSA-hppv-p84g-253f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hppv-p84g-253f", + "modified": "2025-03-25T09:32:07Z", + "published": "2025-03-25T09:32:07Z", + "aliases": [ + "CVE-2024-13731" + ], + "details": "The Alert Box Block – Display notice/alerts in the front end. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Alert Box block in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13731" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/alert-box-block" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d63cd13e-4a16-483f-8165-6c8090ceebab?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T09:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p56m-pq92-4wxr/GHSA-p56m-pq92-4wxr.json b/advisories/unreviewed/2025/03/GHSA-p56m-pq92-4wxr/GHSA-p56m-pq92-4wxr.json new file mode 100644 index 00000000000..acb989c9a7e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p56m-pq92-4wxr/GHSA-p56m-pq92-4wxr.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p56m-pq92-4wxr", + "modified": "2025-03-25T09:32:06Z", + "published": "2025-03-25T09:32:06Z", + "aliases": [ + "CVE-2025-2743" + ], + "details": "A vulnerability, which was classified as problematic, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. This issue affects some unknown processing of the file /admin-api/mp/material/upload-temporary of the component Material Upload Interface. The manipulation of the argument File leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2743" + }, + { + "type": "WEB", + "url": "https://github.com/uglory-gll/javasec/blob/main/ruoyi-vue-pro.md#6arbitrary-file-deletion-vulnerability---uploadtemporarymaterial" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300845" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300845" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.519692" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T07:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r6xg-mjqp-qqg4/GHSA-r6xg-mjqp-qqg4.json b/advisories/unreviewed/2025/03/GHSA-r6xg-mjqp-qqg4/GHSA-r6xg-mjqp-qqg4.json new file mode 100644 index 00000000000..470a2357c67 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r6xg-mjqp-qqg4/GHSA-r6xg-mjqp-qqg4.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6xg-mjqp-qqg4", + "modified": "2025-03-25T09:32:06Z", + "published": "2025-03-25T09:32:06Z", + "aliases": [ + "CVE-2025-2742" + ], + "details": "A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. This vulnerability affects unknown code of the file /admin-api/mp/material/upload-permanent of the component Material Upload Interface. The manipulation of the argument File leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2742" + }, + { + "type": "WEB", + "url": "https://github.com/uglory-gll/javasec/blob/main/ruoyi-vue-pro.md#5arbitrary-file-deletion-vulnerability---uploadpermanentmaterial" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300844" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300844" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.519691" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T07:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rxv9-287v-pp3r/GHSA-rxv9-287v-pp3r.json b/advisories/unreviewed/2025/03/GHSA-rxv9-287v-pp3r/GHSA-rxv9-287v-pp3r.json new file mode 100644 index 00000000000..38986175f48 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rxv9-287v-pp3r/GHSA-rxv9-287v-pp3r.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxv9-287v-pp3r", + "modified": "2025-03-25T09:32:05Z", + "published": "2025-03-25T09:32:05Z", + "aliases": [ + "CVE-2024-12623" + ], + "details": "The DICOM Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dcm' shortcode in all versions up to, and including, 0.10.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12623" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/dicom-support/trunk/DicomSupport.php#L120" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3257320%40dicom-support&new=3257320%40dicom-support&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d76052f8-34b3-4930-a5bf-182420b07968?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T07:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v8f4-5r7f-6q9r/GHSA-v8f4-5r7f-6q9r.json b/advisories/unreviewed/2025/03/GHSA-v8f4-5r7f-6q9r/GHSA-v8f4-5r7f-6q9r.json new file mode 100644 index 00000000000..87574e3c39a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v8f4-5r7f-6q9r/GHSA-v8f4-5r7f-6q9r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8f4-5r7f-6q9r", + "modified": "2025-03-25T09:32:07Z", + "published": "2025-03-25T09:32:07Z", + "aliases": [ + "CVE-2025-2510" + ], + "details": "The Frndzk Expandable Bottom Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text' parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2510" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/frndzk-expandable-bottom-bar/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4261c81e-13a2-4022-8048-aeb0ea4e9ee4?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T09:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wvph-mf6h-fpww/GHSA-wvph-mf6h-fpww.json b/advisories/unreviewed/2025/03/GHSA-wvph-mf6h-fpww/GHSA-wvph-mf6h-fpww.json new file mode 100644 index 00000000000..6c5d18b2be3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wvph-mf6h-fpww/GHSA-wvph-mf6h-fpww.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvph-mf6h-fpww", + "modified": "2025-03-25T09:32:06Z", + "published": "2025-03-25T09:32:06Z", + "aliases": [ + "CVE-2024-13690" + ], + "details": "The WP Church Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several donation form submission parameters in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13690" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wp-church-donation" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/de8ac20f-d6ae-4e55-9337-4fb5ebd4f24a?source=cve" + }, + { + "type": "WEB", + "url": "http://plugins.svn.wordpress.org/wp-church-donation/tags/1.7/includes/church-donation-form-display.php" + }, + { + "type": "WEB", + "url": "http://plugins.svn.wordpress.org/wp-church-donation/tags/1.7/includes/church-donation-listings.php" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-25T09:15:13Z" + } +} \ No newline at end of file