mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-23qm-j98q-xr7j GHSA-4j8f-fjpj-x22v GHSA-59gg-pj3q-72g8 GHSA-62xc-g7hf-p457 GHSA-6m47-c6q4-33vq GHSA-7c4m-cp34-4f9r GHSA-h2f3-jpg6-w3c6 GHSA-jcw4-9ccq-g3rh GHSA-m8ph-fr33-7cmg GHSA-wxrm-98h4-c857 GHSA-xf9q-jgmw-h653 GHSA-24vc-7q35-w5rv GHSA-6975-j4h6-fxff GHSA-j7px-pvwg-2r3m GHSA-jcc3-vmjf-jfhj GHSA-mwmr-r556-9837 GHSA-pcwj-m6p3-w8x3 GHSA-rfh5-gx7w-h7v7 GHSA-rrj2-ph5q-jxw2 GHSA-whpg-7794-8rqm
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-23qm-j98q-xr7j",
|
||||
"modified": "2022-12-31T00:30:23Z",
|
||||
"modified": "2025-04-15T06:30:33Z",
|
||||
"published": "2022-12-23T15:30:24Z",
|
||||
"aliases": [
|
||||
"CVE-2022-46641"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4j8f-fjpj-x22v",
|
||||
"modified": "2023-01-04T18:30:59Z",
|
||||
"modified": "2025-04-15T06:30:34Z",
|
||||
"published": "2022-12-23T21:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2022-46568"
|
||||
@@ -19,6 +19,14 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46568"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/B1SZP0aIo"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/SetSysEmailSettings"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/@0dayResearch/B1SZP0aIo"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-59gg-pj3q-72g8",
|
||||
"modified": "2023-01-04T21:30:19Z",
|
||||
"modified": "2025-04-15T06:30:33Z",
|
||||
"published": "2022-12-23T21:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2022-46563"
|
||||
@@ -19,6 +19,14 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46563"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/HkDzZLCUo"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/SetDynamicDNSSettings"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/@0dayResearch/HkDzZLCUo"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-62xc-g7hf-p457",
|
||||
"modified": "2022-12-31T00:30:23Z",
|
||||
"modified": "2025-04-15T06:30:33Z",
|
||||
"published": "2022-12-23T15:30:24Z",
|
||||
"aliases": [
|
||||
"CVE-2022-46642"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6m47-c6q4-33vq",
|
||||
"modified": "2023-01-04T21:30:19Z",
|
||||
"modified": "2025-04-15T06:30:33Z",
|
||||
"published": "2022-12-23T21:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2022-46561"
|
||||
@@ -19,6 +19,22 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46561"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/SetWanSettings_L2TP"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/SetWanSettings_PPPoE"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/SetWanSettings_PPTP"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/ry55QVQvj"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/@0dayResearch/SetWanSettings_L2TP"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7c4m-cp34-4f9r",
|
||||
"modified": "2023-01-04T18:30:58Z",
|
||||
"modified": "2025-04-15T06:30:34Z",
|
||||
"published": "2022-12-23T21:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2022-46570"
|
||||
@@ -19,6 +19,22 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46570"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/SetWan3Settings_l2tp"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/SetWan3Settings_pppoe"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/SetWan3Settings_pptp"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/r1zsTSmDs"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/@0dayResearch/SetWan3Settings_l2tp"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-h2f3-jpg6-w3c6",
|
||||
"modified": "2023-01-04T18:30:58Z",
|
||||
"modified": "2025-04-15T06:30:34Z",
|
||||
"published": "2022-12-23T21:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2022-46569"
|
||||
@@ -19,6 +19,14 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46569"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/SetWLanRadioSecurity"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/r1R6sWRUs"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/@0dayResearch/SetWLanRadioSecurity"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jcw4-9ccq-g3rh",
|
||||
"modified": "2022-12-30T18:30:44Z",
|
||||
"modified": "2025-04-15T06:30:33Z",
|
||||
"published": "2022-12-23T18:30:41Z",
|
||||
"aliases": [
|
||||
"CVE-2022-47938"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m8ph-fr33-7cmg",
|
||||
"modified": "2023-03-03T21:30:17Z",
|
||||
"modified": "2025-04-15T06:30:33Z",
|
||||
"published": "2022-12-23T21:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2022-46560"
|
||||
@@ -19,6 +19,22 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46560"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/SetWan2Settings_l2tp"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/SetWan2Settings_pppoe"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/SetWan2Settings_pptp"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/rkXr4BQPi"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/@0dayResearch/SetWan2Settings_l2tp"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-wxrm-98h4-c857",
|
||||
"modified": "2023-01-04T21:30:19Z",
|
||||
"modified": "2025-04-15T06:30:33Z",
|
||||
"published": "2022-12-23T21:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2022-46562"
|
||||
@@ -19,6 +19,14 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46562"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/B1C9jeXDi"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/SetQuickVPNSettings_PSK"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/@0dayResearch/B1C9jeXDi"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-xf9q-jgmw-h653",
|
||||
"modified": "2023-01-04T18:31:00Z",
|
||||
"modified": "2025-04-15T06:30:33Z",
|
||||
"published": "2022-12-23T21:30:19Z",
|
||||
"aliases": [
|
||||
"CVE-2022-46566"
|
||||
@@ -19,6 +19,14 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46566"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/SetQuickVPNSettings_Password"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/%400dayResearch/SyhDme7wo"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://hackmd.io/@0dayResearch/SetQuickVPNSettings_Password"
|
||||
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-24vc-7q35-w5rv",
|
||||
"modified": "2025-04-15T06:30:34Z",
|
||||
"published": "2025-04-15T06:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2024-13207"
|
||||
],
|
||||
"details": "The Widget for Social Page Feeds WordPress plugin before 6.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13207"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://wpscan.com/vulnerability/c3e27fa2-b6dd-48eb-83ec-99dc034eff38"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-15T06:15:42Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,48 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6975-j4h6-fxff",
|
||||
"modified": "2025-04-15T06:30:34Z",
|
||||
"published": "2025-04-15T06:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2025-2225"
|
||||
],
|
||||
"details": "The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rael_title_tag' parameter in all versions up to, and including, 1.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 1.6.9.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2225"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://plugins.trac.wordpress.org/browser/responsive-addons-for-elementor/trunk/includes/widgets-manager/widgets/class-responsive-addons-for-elementor-icon-box.php#L2499"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://plugins.trac.wordpress.org/changeset/3261241"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://plugins.trac.wordpress.org/changeset/3263280"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f5ace7fb-530e-4a69-bbf7-e2c66491dd75?source=cve"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-15T06:15:43Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,36 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-j7px-pvwg-2r3m",
|
||||
"modified": "2025-04-15T06:30:34Z",
|
||||
"published": "2025-04-15T06:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2025-29984"
|
||||
],
|
||||
"details": "Dell Trusted Device, versions prior to 7.0.3.0, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29984"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.dell.com/support/kbdoc/en-us/000299528/dsa-2025-151"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-284"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-15T04:15:36Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jcc3-vmjf-jfhj",
|
||||
"modified": "2025-04-15T06:30:34Z",
|
||||
"published": "2025-04-15T06:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2024-13610"
|
||||
],
|
||||
"details": "The Simple Social Media Share Buttons WordPress plugin before 6.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).",
|
||||
"severity": [],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13610"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://wpscan.com/vulnerability/85229528-1110-4d45-b972-8bbcba003a1f"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [],
|
||||
"severity": null,
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-15T06:15:43Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,36 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mwmr-r556-9837",
|
||||
"modified": "2025-04-15T06:30:34Z",
|
||||
"published": "2025-04-15T06:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2025-29983"
|
||||
],
|
||||
"details": "Dell Trusted Device, versions prior to 7.0.3.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29983"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.dell.com/support/kbdoc/en-us/000299528/dsa-2025-151"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-59"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-15T04:15:36Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-pcwj-m6p3-w8x3",
|
||||
"modified": "2025-04-15T06:30:34Z",
|
||||
"published": "2025-04-15T06:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2025-32993"
|
||||
],
|
||||
"details": "Vision Helpdesk through 5.7.0 allows Time-Based Blind SQL injection via the Forgot Password (aka index.php?/home/forgot-password) vis_username parameter. Authentication is not needed.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32993"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://nav1n.medium.com/sql-injection-in-vision-helpdesk-tools-a83dfc27f3ab"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.visionhelpdesk.com/vision-helpdesk-v5-7-0-stable-version-released.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-89"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-15T06:15:43Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-rfh5-gx7w-h7v7",
|
||||
"modified": "2025-04-15T06:30:34Z",
|
||||
"published": "2025-04-15T06:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2025-3576"
|
||||
],
|
||||
"details": "A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3576"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://access.redhat.com/security/cve/CVE-2025-3576"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359465"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-328"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-15T06:15:44Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,48 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-rrj2-ph5q-jxw2",
|
||||
"modified": "2025-04-15T06:30:34Z",
|
||||
"published": "2025-04-15T06:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2025-3573"
|
||||
],
|
||||
"details": "Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This value will populate a message via $.validator.messages in a user localizable dictionary.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
|
||||
},
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3573"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/jquery-validation/jquery-validation/pull/2462"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/jquery-validation/jquery-validation/commit/7a490d8f39bd988027568ddcf51755e1f4688902"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.snyk.io/vuln/SNYK-JS-JQUERYVALIDATION-5952285"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-15T05:15:31Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,56 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-whpg-7794-8rqm",
|
||||
"modified": "2025-04-15T06:30:34Z",
|
||||
"published": "2025-04-15T06:30:34Z",
|
||||
"aliases": [
|
||||
"CVE-2025-3622"
|
||||
],
|
||||
"details": "A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects the function load of the file xinference/thirdparty/cosyvoice/cli/model.py. The manipulation leads to deserialization.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
|
||||
},
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3622"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/xorbitsai/inference/issues/3190"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/xorbitsai/inference/issues/3190#issuecomment-2783462266"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://vuldb.com/?ctiid.304679"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://vuldb.com/?id.304679"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://vuldb.com/?submit.552245"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-20"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-04-15T06:15:44Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user