Publish Advisories

GHSA-5p56-56jf-wfv2
GHSA-2wh4-gmm6-gqj2
GHSA-4785-6qpq-mxrv
GHSA-98c3-q46g-62qh
GHSA-h7c4-42v9-h338
GHSA-j37q-3xjr-5589
GHSA-jrw2-pv6m-v2w5
GHSA-m727-97qg-jrmp
GHSA-mh84-747x-6j6c
GHSA-mm94-j6p9-32xj
GHSA-phf9-ch44-7c3w
GHSA-wm7c-hvrf-c5wg
GHSA-xp9q-qcjq-74gr
This commit is contained in:
advisory-database[bot]
2025-03-27 03:35:28 +00:00
parent 054adc07f0
commit 9c4ef1f432
13 changed files with 166 additions and 10 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5p56-56jf-wfv2",
"modified": "2025-03-19T21:30:35Z",
"modified": "2025-03-27T03:33:33Z",
"published": "2022-05-13T01:10:43Z",
"aliases": [
"CVE-2017-12637"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-12637"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20170807202056/http://www.sh0w.top/index.php/archives/7"
},
{
"type": "WEB",
"url": "http://www.sh0w.top/index.php/archives/7"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2wh4-gmm6-gqj2",
"modified": "2025-03-22T06:33:03Z",
"modified": "2025-03-27T03:33:35Z",
"published": "2025-03-22T06:33:03Z",
"aliases": [
"CVE-2025-0724"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4785-6qpq-mxrv",
"modified": "2025-03-22T03:30:33Z",
"modified": "2025-03-27T03:33:34Z",
"published": "2025-03-22T03:30:33Z",
"aliases": [
"CVE-2024-13737"
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-288"
"CWE-288",
"CWE-306"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h7c4-42v9-h338",
"modified": "2025-03-22T06:33:02Z",
"modified": "2025-03-27T03:33:35Z",
"published": "2025-03-22T06:33:02Z",
"aliases": [
"CVE-2025-0723"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j37q-3xjr-5589",
"modified": "2025-03-26T21:31:07Z",
"modified": "2025-03-27T03:33:35Z",
"published": "2025-03-26T21:31:07Z",
"aliases": [
"CVE-2025-31160"
@@ -34,6 +34,22 @@
{
"type": "WEB",
"url": "https://rachelbythebay.com/w/2025/03/26/atop"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/03/26/3"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/03/27/1"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/03/27/2"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/03/27/3"
}
],
"database_specific": {
@@ -34,7 +34,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-288"
"CWE-288",
"CWE-306"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-321"
"CWE-321",
"CWE-798"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mh84-747x-6j6c",
"modified": "2025-03-22T06:33:03Z",
"modified": "2025-03-27T03:33:35Z",
"published": "2025-03-22T06:33:03Z",
"aliases": [
"CVE-2025-1408"
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mm94-j6p9-32xj",
"modified": "2025-03-27T03:33:35Z",
"published": "2025-03-27T03:33:35Z",
"aliases": [
"CVE-2024-45352"
],
"details": "An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45352"
},
{
"type": "WEB",
"url": "https://trust.mi.com/zh-CN/misrc/bulletins/advisory?cveId=550"
}
],
"database_specific": {
"cwe_ids": [
"CWE-346"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-27T02:15:15Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-phf9-ch44-7c3w",
"modified": "2025-03-27T03:33:36Z",
"published": "2025-03-27T03:33:36Z",
"aliases": [
"CVE-2025-2831"
],
"details": "A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. This vulnerability affects the function getBookList of the file /admin/bookList?page=1&limit=10. The manipulation of the argument condition leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2831"
},
{
"type": "WEB",
"url": "https://gitee.com/mingyuefusu/tushuguanlixitong/issues/IBTSJL"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.301468"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.301468"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.521458"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-27T03:15:14Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wm7c-hvrf-c5wg",
"modified": "2025-03-27T03:33:35Z",
"published": "2025-03-27T03:33:35Z",
"aliases": [
"CVE-2025-2481"
],
"details": "The MediaView plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the id' parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2481"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/mediaview/tags/1.1.2/inc/forms/addMedia.inc.php#L48"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/mediaview/#developers"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ca2d687f-0358-4642-849b-100bf40cbbf1?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-27T02:15:16Z"
}
}
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,