From 9915e253f860ff5785d6d0580f7386ba20daada7 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 6 May 2025 00:33:11 +0000 Subject: [PATCH] Publish Advisories GHSA-45f6-6g3x-67c2 GHSA-4f46-w5m2-fwxq GHSA-7cg4-g3qc-hjr8 GHSA-cjvw-2hqr-v93r GHSA-cw88-2jmf-99gh GHSA-f4x7-vp5w-9x56 GHSA-hfqg-w7pg-59vf GHSA-jwmh-m92h-24jx GHSA-p635-c8mp-2g9m GHSA-rg86-p2xf-8jv6 GHSA-x8fp-23r2-qrrm --- .../GHSA-45f6-6g3x-67c2.json | 52 +++++++++++++++++ .../GHSA-4f46-w5m2-fwxq.json | 52 +++++++++++++++++ .../GHSA-7cg4-g3qc-hjr8.json | 29 ++++++++++ .../GHSA-cjvw-2hqr-v93r.json | 52 +++++++++++++++++ .../GHSA-cw88-2jmf-99gh.json | 29 ++++++++++ .../GHSA-f4x7-vp5w-9x56.json | 56 +++++++++++++++++++ .../GHSA-hfqg-w7pg-59vf.json | 56 +++++++++++++++++++ .../GHSA-jwmh-m92h-24jx.json | 52 +++++++++++++++++ .../GHSA-p635-c8mp-2g9m.json | 56 +++++++++++++++++++ .../GHSA-rg86-p2xf-8jv6.json | 29 ++++++++++ .../GHSA-x8fp-23r2-qrrm.json | 56 +++++++++++++++++++ 11 files changed, 519 insertions(+) create mode 100644 advisories/unreviewed/2025/05/GHSA-45f6-6g3x-67c2/GHSA-45f6-6g3x-67c2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-4f46-w5m2-fwxq/GHSA-4f46-w5m2-fwxq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7cg4-g3qc-hjr8/GHSA-7cg4-g3qc-hjr8.json create mode 100644 advisories/unreviewed/2025/05/GHSA-cjvw-2hqr-v93r/GHSA-cjvw-2hqr-v93r.json create mode 100644 advisories/unreviewed/2025/05/GHSA-cw88-2jmf-99gh/GHSA-cw88-2jmf-99gh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-f4x7-vp5w-9x56/GHSA-f4x7-vp5w-9x56.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hfqg-w7pg-59vf/GHSA-hfqg-w7pg-59vf.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jwmh-m92h-24jx/GHSA-jwmh-m92h-24jx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-p635-c8mp-2g9m/GHSA-p635-c8mp-2g9m.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rg86-p2xf-8jv6/GHSA-rg86-p2xf-8jv6.json create mode 100644 advisories/unreviewed/2025/05/GHSA-x8fp-23r2-qrrm/GHSA-x8fp-23r2-qrrm.json diff --git a/advisories/unreviewed/2025/05/GHSA-45f6-6g3x-67c2/GHSA-45f6-6g3x-67c2.json b/advisories/unreviewed/2025/05/GHSA-45f6-6g3x-67c2/GHSA-45f6-6g3x-67c2.json new file mode 100644 index 00000000000..07d37578bf5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-45f6-6g3x-67c2/GHSA-45f6-6g3x-67c2.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45f6-6g3x-67c2", + "modified": "2025-05-06T00:31:05Z", + "published": "2025-05-06T00:31:05Z", + "aliases": [ + "CVE-2025-4293" + ], + "details": "A vulnerability was found in MRCMS 3.1.3 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/group/edit.do of the component Group Edit Page. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4293" + }, + { + "type": "WEB", + "url": "https://github.com/bdkuzma/vuln/issues/2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.307400" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.307400" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.563534" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T23:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4f46-w5m2-fwxq/GHSA-4f46-w5m2-fwxq.json b/advisories/unreviewed/2025/05/GHSA-4f46-w5m2-fwxq/GHSA-4f46-w5m2-fwxq.json new file mode 100644 index 00000000000..474a697df7a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4f46-w5m2-fwxq/GHSA-4f46-w5m2-fwxq.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f46-w5m2-fwxq", + "modified": "2025-05-06T00:31:05Z", + "published": "2025-05-06T00:31:05Z", + "aliases": [ + "CVE-2025-4292" + ], + "details": "A vulnerability has been found in MRCMS 3.1.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/user/edit.do of the component Edit User Page. The manipulation of the argument Username leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4292" + }, + { + "type": "WEB", + "url": "https://github.com/bdkuzma/vuln/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.307399" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.307399" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.563533" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T23:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7cg4-g3qc-hjr8/GHSA-7cg4-g3qc-hjr8.json b/advisories/unreviewed/2025/05/GHSA-7cg4-g3qc-hjr8/GHSA-7cg4-g3qc-hjr8.json new file mode 100644 index 00000000000..dd2270f039e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7cg4-g3qc-hjr8/GHSA-7cg4-g3qc-hjr8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cg4-g3qc-hjr8", + "modified": "2025-05-06T00:31:04Z", + "published": "2025-05-06T00:31:04Z", + "aliases": [ + "CVE-2025-44071" + ], + "details": "SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allows attackers to execute arbitrary code via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44071" + }, + { + "type": "WEB", + "url": "https://github.com/202110420106/CVE/blob/master/seacms/seacms_rce.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cjvw-2hqr-v93r/GHSA-cjvw-2hqr-v93r.json b/advisories/unreviewed/2025/05/GHSA-cjvw-2hqr-v93r/GHSA-cjvw-2hqr-v93r.json new file mode 100644 index 00000000000..d19f4045d7c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cjvw-2hqr-v93r/GHSA-cjvw-2hqr-v93r.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjvw-2hqr-v93r", + "modified": "2025-05-06T00:31:05Z", + "published": "2025-05-06T00:31:05Z", + "aliases": [ + "CVE-2025-4290" + ], + "details": "A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component SMNT Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4290" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-1d02cb01af712a1176c64e21664ade52d09ec09ab368d4501d7d09296bcd395b.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.307397" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.307397" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.561628" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cw88-2jmf-99gh/GHSA-cw88-2jmf-99gh.json b/advisories/unreviewed/2025/05/GHSA-cw88-2jmf-99gh/GHSA-cw88-2jmf-99gh.json new file mode 100644 index 00000000000..6f9d9ef9922 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cw88-2jmf-99gh/GHSA-cw88-2jmf-99gh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cw88-2jmf-99gh", + "modified": "2025-05-06T00:31:05Z", + "published": "2025-05-06T00:31:05Z", + "aliases": [ + "CVE-2025-44074" + ], + "details": "SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_topic.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44074" + }, + { + "type": "WEB", + "url": "https://github.com/202110420106/CVE/blob/master/seacms/seacms_topic_sql.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f4x7-vp5w-9x56/GHSA-f4x7-vp5w-9x56.json b/advisories/unreviewed/2025/05/GHSA-f4x7-vp5w-9x56/GHSA-f4x7-vp5w-9x56.json new file mode 100644 index 00000000000..e27884b05c6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f4x7-vp5w-9x56/GHSA-f4x7-vp5w-9x56.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4x7-vp5w-9x56", + "modified": "2025-05-06T00:31:05Z", + "published": "2025-05-06T00:31:05Z", + "aliases": [ + "CVE-2025-4298" + ], + "details": "A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been declared as critical. This vulnerability affects the function formSetCfm of the file /goform/setcfm. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4298" + }, + { + "type": "WEB", + "url": "https://github.com/CH13hh/tmp_store_cc/blob/main/AC1206/AC1206formSetCfm/formSetCfm.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.307402" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.307402" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.563557" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-06T00:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hfqg-w7pg-59vf/GHSA-hfqg-w7pg-59vf.json b/advisories/unreviewed/2025/05/GHSA-hfqg-w7pg-59vf/GHSA-hfqg-w7pg-59vf.json new file mode 100644 index 00000000000..d11c959be94 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hfqg-w7pg-59vf/GHSA-hfqg-w7pg-59vf.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfqg-w7pg-59vf", + "modified": "2025-05-06T00:31:05Z", + "published": "2025-05-06T00:31:05Z", + "aliases": [ + "CVE-2025-4297" + ], + "details": "A vulnerability was found in PHPGurukul Men Salon Management System 2.0. It has been classified as critical. This affects an unknown part of the file /admin/change-password.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Multiple parameters might be affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4297" + }, + { + "type": "WEB", + "url": "https://github.com/lierran1/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.307401" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.307401" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.563548" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T23:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jwmh-m92h-24jx/GHSA-jwmh-m92h-24jx.json b/advisories/unreviewed/2025/05/GHSA-jwmh-m92h-24jx/GHSA-jwmh-m92h-24jx.json new file mode 100644 index 00000000000..e6c8e814ebd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jwmh-m92h-24jx/GHSA-jwmh-m92h-24jx.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwmh-m92h-24jx", + "modified": "2025-05-06T00:31:05Z", + "published": "2025-05-06T00:31:05Z", + "aliases": [ + "CVE-2025-4291" + ], + "details": "A vulnerability, which was classified as critical, was found in IdeaCMS up to 1.6. Affected is the function saveUpload. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4291" + }, + { + "type": "WEB", + "url": "https://gitee.com/ideacms/ideacms/issues/IC32SB" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.307398" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.307398" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.563522" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p635-c8mp-2g9m/GHSA-p635-c8mp-2g9m.json b/advisories/unreviewed/2025/05/GHSA-p635-c8mp-2g9m/GHSA-p635-c8mp-2g9m.json new file mode 100644 index 00000000000..89f8f4941bd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p635-c8mp-2g9m/GHSA-p635-c8mp-2g9m.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p635-c8mp-2g9m", + "modified": "2025-05-06T00:31:05Z", + "published": "2025-05-06T00:31:05Z", + "aliases": [ + "CVE-2025-4299" + ], + "details": "A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been rated as critical. This issue affects the function setSchedWifi of the file /goform/openSchedWifi. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4299" + }, + { + "type": "WEB", + "url": "https://github.com/CH13hh/tmp_store_cc/blob/main/AC1206/AC1206setSchedWifi/setSchedWifi.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.307403" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.307403" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.563558" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-06T00:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rg86-p2xf-8jv6/GHSA-rg86-p2xf-8jv6.json b/advisories/unreviewed/2025/05/GHSA-rg86-p2xf-8jv6/GHSA-rg86-p2xf-8jv6.json new file mode 100644 index 00000000000..196bb0cf9d6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rg86-p2xf-8jv6/GHSA-rg86-p2xf-8jv6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg86-p2xf-8jv6", + "modified": "2025-05-06T00:31:04Z", + "published": "2025-05-06T00:31:04Z", + "aliases": [ + "CVE-2025-44072" + ], + "details": "SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_manager.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44072" + }, + { + "type": "WEB", + "url": "https://github.com/202110420106/CVE/blob/master/seacms/seacms_manage_sql.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x8fp-23r2-qrrm/GHSA-x8fp-23r2-qrrm.json b/advisories/unreviewed/2025/05/GHSA-x8fp-23r2-qrrm/GHSA-x8fp-23r2-qrrm.json new file mode 100644 index 00000000000..af5110b3667 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x8fp-23r2-qrrm/GHSA-x8fp-23r2-qrrm.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8fp-23r2-qrrm", + "modified": "2025-05-06T00:31:05Z", + "published": "2025-05-06T00:31:05Z", + "aliases": [ + "CVE-2025-4300" + ], + "details": "A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. Affected is an unknown function of the file /search_list.php. The manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4300" + }, + { + "type": "WEB", + "url": "https://github.com/6BXK6/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.307404" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.307404" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.563623" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-06T00:15:16Z" + } +} \ No newline at end of file