From a05a7fbc6db2699ca4998c50e79268702d41a918 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 15 Apr 2025 06:31:50 +0000 Subject: [PATCH] Publish Advisories GHSA-23qm-j98q-xr7j GHSA-4j8f-fjpj-x22v GHSA-59gg-pj3q-72g8 GHSA-62xc-g7hf-p457 GHSA-6m47-c6q4-33vq GHSA-7c4m-cp34-4f9r GHSA-h2f3-jpg6-w3c6 GHSA-jcw4-9ccq-g3rh GHSA-m8ph-fr33-7cmg GHSA-wxrm-98h4-c857 GHSA-xf9q-jgmw-h653 GHSA-24vc-7q35-w5rv GHSA-6975-j4h6-fxff GHSA-j7px-pvwg-2r3m GHSA-jcc3-vmjf-jfhj GHSA-mwmr-r556-9837 GHSA-pcwj-m6p3-w8x3 GHSA-rfh5-gx7w-h7v7 GHSA-rrj2-ph5q-jxw2 GHSA-whpg-7794-8rqm --- .../GHSA-23qm-j98q-xr7j.json | 2 +- .../GHSA-4j8f-fjpj-x22v.json | 10 +++- .../GHSA-59gg-pj3q-72g8.json | 10 +++- .../GHSA-62xc-g7hf-p457.json | 2 +- .../GHSA-6m47-c6q4-33vq.json | 18 +++++- .../GHSA-7c4m-cp34-4f9r.json | 18 +++++- .../GHSA-h2f3-jpg6-w3c6.json | 10 +++- .../GHSA-jcw4-9ccq-g3rh.json | 2 +- .../GHSA-m8ph-fr33-7cmg.json | 18 +++++- .../GHSA-wxrm-98h4-c857.json | 10 +++- .../GHSA-xf9q-jgmw-h653.json | 10 +++- .../GHSA-24vc-7q35-w5rv.json | 29 ++++++++++ .../GHSA-6975-j4h6-fxff.json | 48 ++++++++++++++++ .../GHSA-j7px-pvwg-2r3m.json | 36 ++++++++++++ .../GHSA-jcc3-vmjf-jfhj.json | 29 ++++++++++ .../GHSA-mwmr-r556-9837.json | 36 ++++++++++++ .../GHSA-pcwj-m6p3-w8x3.json | 40 +++++++++++++ .../GHSA-rfh5-gx7w-h7v7.json | 40 +++++++++++++ .../GHSA-rrj2-ph5q-jxw2.json | 48 ++++++++++++++++ .../GHSA-whpg-7794-8rqm.json | 56 +++++++++++++++++++ 20 files changed, 461 insertions(+), 11 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-24vc-7q35-w5rv/GHSA-24vc-7q35-w5rv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6975-j4h6-fxff/GHSA-6975-j4h6-fxff.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j7px-pvwg-2r3m/GHSA-j7px-pvwg-2r3m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jcc3-vmjf-jfhj/GHSA-jcc3-vmjf-jfhj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mwmr-r556-9837/GHSA-mwmr-r556-9837.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pcwj-m6p3-w8x3/GHSA-pcwj-m6p3-w8x3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rfh5-gx7w-h7v7/GHSA-rfh5-gx7w-h7v7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rrj2-ph5q-jxw2/GHSA-rrj2-ph5q-jxw2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-whpg-7794-8rqm/GHSA-whpg-7794-8rqm.json diff --git a/advisories/unreviewed/2022/12/GHSA-23qm-j98q-xr7j/GHSA-23qm-j98q-xr7j.json b/advisories/unreviewed/2022/12/GHSA-23qm-j98q-xr7j/GHSA-23qm-j98q-xr7j.json index 33df9b7bcc7..502647cd482 100644 --- a/advisories/unreviewed/2022/12/GHSA-23qm-j98q-xr7j/GHSA-23qm-j98q-xr7j.json +++ b/advisories/unreviewed/2022/12/GHSA-23qm-j98q-xr7j/GHSA-23qm-j98q-xr7j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-23qm-j98q-xr7j", - "modified": "2022-12-31T00:30:23Z", + "modified": "2025-04-15T06:30:33Z", "published": "2022-12-23T15:30:24Z", "aliases": [ "CVE-2022-46641" diff --git a/advisories/unreviewed/2022/12/GHSA-4j8f-fjpj-x22v/GHSA-4j8f-fjpj-x22v.json b/advisories/unreviewed/2022/12/GHSA-4j8f-fjpj-x22v/GHSA-4j8f-fjpj-x22v.json index 167c0223dc4..24c43b1bcf0 100644 --- a/advisories/unreviewed/2022/12/GHSA-4j8f-fjpj-x22v/GHSA-4j8f-fjpj-x22v.json +++ b/advisories/unreviewed/2022/12/GHSA-4j8f-fjpj-x22v/GHSA-4j8f-fjpj-x22v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4j8f-fjpj-x22v", - "modified": "2023-01-04T18:30:59Z", + "modified": "2025-04-15T06:30:34Z", "published": "2022-12-23T21:30:19Z", "aliases": [ "CVE-2022-46568" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46568" }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/B1SZP0aIo" + }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/SetSysEmailSettings" + }, { "type": "WEB", "url": "https://hackmd.io/@0dayResearch/B1SZP0aIo" diff --git a/advisories/unreviewed/2022/12/GHSA-59gg-pj3q-72g8/GHSA-59gg-pj3q-72g8.json b/advisories/unreviewed/2022/12/GHSA-59gg-pj3q-72g8/GHSA-59gg-pj3q-72g8.json index b778363659d..04eebe225e8 100644 --- a/advisories/unreviewed/2022/12/GHSA-59gg-pj3q-72g8/GHSA-59gg-pj3q-72g8.json +++ b/advisories/unreviewed/2022/12/GHSA-59gg-pj3q-72g8/GHSA-59gg-pj3q-72g8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-59gg-pj3q-72g8", - "modified": "2023-01-04T21:30:19Z", + "modified": "2025-04-15T06:30:33Z", "published": "2022-12-23T21:30:19Z", "aliases": [ "CVE-2022-46563" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46563" }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/HkDzZLCUo" + }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/SetDynamicDNSSettings" + }, { "type": "WEB", "url": "https://hackmd.io/@0dayResearch/HkDzZLCUo" diff --git a/advisories/unreviewed/2022/12/GHSA-62xc-g7hf-p457/GHSA-62xc-g7hf-p457.json b/advisories/unreviewed/2022/12/GHSA-62xc-g7hf-p457/GHSA-62xc-g7hf-p457.json index 0821d1fd128..2defeb8ce59 100644 --- a/advisories/unreviewed/2022/12/GHSA-62xc-g7hf-p457/GHSA-62xc-g7hf-p457.json +++ b/advisories/unreviewed/2022/12/GHSA-62xc-g7hf-p457/GHSA-62xc-g7hf-p457.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-62xc-g7hf-p457", - "modified": "2022-12-31T00:30:23Z", + "modified": "2025-04-15T06:30:33Z", "published": "2022-12-23T15:30:24Z", "aliases": [ "CVE-2022-46642" diff --git a/advisories/unreviewed/2022/12/GHSA-6m47-c6q4-33vq/GHSA-6m47-c6q4-33vq.json b/advisories/unreviewed/2022/12/GHSA-6m47-c6q4-33vq/GHSA-6m47-c6q4-33vq.json index e586fcbc1bb..f7295b6529e 100644 --- a/advisories/unreviewed/2022/12/GHSA-6m47-c6q4-33vq/GHSA-6m47-c6q4-33vq.json +++ b/advisories/unreviewed/2022/12/GHSA-6m47-c6q4-33vq/GHSA-6m47-c6q4-33vq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6m47-c6q4-33vq", - "modified": "2023-01-04T21:30:19Z", + "modified": "2025-04-15T06:30:33Z", "published": "2022-12-23T21:30:19Z", "aliases": [ "CVE-2022-46561" @@ -19,6 +19,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46561" }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/SetWanSettings_L2TP" + }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/SetWanSettings_PPPoE" + }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/SetWanSettings_PPTP" + }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/ry55QVQvj" + }, { "type": "WEB", "url": "https://hackmd.io/@0dayResearch/SetWanSettings_L2TP" diff --git a/advisories/unreviewed/2022/12/GHSA-7c4m-cp34-4f9r/GHSA-7c4m-cp34-4f9r.json b/advisories/unreviewed/2022/12/GHSA-7c4m-cp34-4f9r/GHSA-7c4m-cp34-4f9r.json index a4aa1f57c01..dd31e5bd29c 100644 --- a/advisories/unreviewed/2022/12/GHSA-7c4m-cp34-4f9r/GHSA-7c4m-cp34-4f9r.json +++ b/advisories/unreviewed/2022/12/GHSA-7c4m-cp34-4f9r/GHSA-7c4m-cp34-4f9r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7c4m-cp34-4f9r", - "modified": "2023-01-04T18:30:58Z", + "modified": "2025-04-15T06:30:34Z", "published": "2022-12-23T21:30:19Z", "aliases": [ "CVE-2022-46570" @@ -19,6 +19,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46570" }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/SetWan3Settings_l2tp" + }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/SetWan3Settings_pppoe" + }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/SetWan3Settings_pptp" + }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/r1zsTSmDs" + }, { "type": "WEB", "url": "https://hackmd.io/@0dayResearch/SetWan3Settings_l2tp" diff --git a/advisories/unreviewed/2022/12/GHSA-h2f3-jpg6-w3c6/GHSA-h2f3-jpg6-w3c6.json b/advisories/unreviewed/2022/12/GHSA-h2f3-jpg6-w3c6/GHSA-h2f3-jpg6-w3c6.json index 413bf3b7d05..37c4ed7ef5d 100644 --- a/advisories/unreviewed/2022/12/GHSA-h2f3-jpg6-w3c6/GHSA-h2f3-jpg6-w3c6.json +++ b/advisories/unreviewed/2022/12/GHSA-h2f3-jpg6-w3c6/GHSA-h2f3-jpg6-w3c6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h2f3-jpg6-w3c6", - "modified": "2023-01-04T18:30:58Z", + "modified": "2025-04-15T06:30:34Z", "published": "2022-12-23T21:30:19Z", "aliases": [ "CVE-2022-46569" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46569" }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/SetWLanRadioSecurity" + }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/r1R6sWRUs" + }, { "type": "WEB", "url": "https://hackmd.io/@0dayResearch/SetWLanRadioSecurity" diff --git a/advisories/unreviewed/2022/12/GHSA-jcw4-9ccq-g3rh/GHSA-jcw4-9ccq-g3rh.json b/advisories/unreviewed/2022/12/GHSA-jcw4-9ccq-g3rh/GHSA-jcw4-9ccq-g3rh.json index 8b17dfce309..24594b28020 100644 --- a/advisories/unreviewed/2022/12/GHSA-jcw4-9ccq-g3rh/GHSA-jcw4-9ccq-g3rh.json +++ b/advisories/unreviewed/2022/12/GHSA-jcw4-9ccq-g3rh/GHSA-jcw4-9ccq-g3rh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jcw4-9ccq-g3rh", - "modified": "2022-12-30T18:30:44Z", + "modified": "2025-04-15T06:30:33Z", "published": "2022-12-23T18:30:41Z", "aliases": [ "CVE-2022-47938" diff --git a/advisories/unreviewed/2022/12/GHSA-m8ph-fr33-7cmg/GHSA-m8ph-fr33-7cmg.json b/advisories/unreviewed/2022/12/GHSA-m8ph-fr33-7cmg/GHSA-m8ph-fr33-7cmg.json index 23f7bdde70b..008fb30c608 100644 --- a/advisories/unreviewed/2022/12/GHSA-m8ph-fr33-7cmg/GHSA-m8ph-fr33-7cmg.json +++ b/advisories/unreviewed/2022/12/GHSA-m8ph-fr33-7cmg/GHSA-m8ph-fr33-7cmg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m8ph-fr33-7cmg", - "modified": "2023-03-03T21:30:17Z", + "modified": "2025-04-15T06:30:33Z", "published": "2022-12-23T21:30:19Z", "aliases": [ "CVE-2022-46560" @@ -19,6 +19,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46560" }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/SetWan2Settings_l2tp" + }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/SetWan2Settings_pppoe" + }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/SetWan2Settings_pptp" + }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/rkXr4BQPi" + }, { "type": "WEB", "url": "https://hackmd.io/@0dayResearch/SetWan2Settings_l2tp" diff --git a/advisories/unreviewed/2022/12/GHSA-wxrm-98h4-c857/GHSA-wxrm-98h4-c857.json b/advisories/unreviewed/2022/12/GHSA-wxrm-98h4-c857/GHSA-wxrm-98h4-c857.json index 85c772410e2..15eab3adb40 100644 --- a/advisories/unreviewed/2022/12/GHSA-wxrm-98h4-c857/GHSA-wxrm-98h4-c857.json +++ b/advisories/unreviewed/2022/12/GHSA-wxrm-98h4-c857/GHSA-wxrm-98h4-c857.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wxrm-98h4-c857", - "modified": "2023-01-04T21:30:19Z", + "modified": "2025-04-15T06:30:33Z", "published": "2022-12-23T21:30:19Z", "aliases": [ "CVE-2022-46562" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46562" }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/B1C9jeXDi" + }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/SetQuickVPNSettings_PSK" + }, { "type": "WEB", "url": "https://hackmd.io/@0dayResearch/B1C9jeXDi" diff --git a/advisories/unreviewed/2022/12/GHSA-xf9q-jgmw-h653/GHSA-xf9q-jgmw-h653.json b/advisories/unreviewed/2022/12/GHSA-xf9q-jgmw-h653/GHSA-xf9q-jgmw-h653.json index 0b0c57786a1..a4937dabaed 100644 --- a/advisories/unreviewed/2022/12/GHSA-xf9q-jgmw-h653/GHSA-xf9q-jgmw-h653.json +++ b/advisories/unreviewed/2022/12/GHSA-xf9q-jgmw-h653/GHSA-xf9q-jgmw-h653.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xf9q-jgmw-h653", - "modified": "2023-01-04T18:31:00Z", + "modified": "2025-04-15T06:30:33Z", "published": "2022-12-23T21:30:19Z", "aliases": [ "CVE-2022-46566" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46566" }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/SetQuickVPNSettings_Password" + }, + { + "type": "WEB", + "url": "https://hackmd.io/%400dayResearch/SyhDme7wo" + }, { "type": "WEB", "url": "https://hackmd.io/@0dayResearch/SetQuickVPNSettings_Password" diff --git a/advisories/unreviewed/2025/04/GHSA-24vc-7q35-w5rv/GHSA-24vc-7q35-w5rv.json b/advisories/unreviewed/2025/04/GHSA-24vc-7q35-w5rv/GHSA-24vc-7q35-w5rv.json new file mode 100644 index 00000000000..55dfe7ff86f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-24vc-7q35-w5rv/GHSA-24vc-7q35-w5rv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24vc-7q35-w5rv", + "modified": "2025-04-15T06:30:34Z", + "published": "2025-04-15T06:30:34Z", + "aliases": [ + "CVE-2024-13207" + ], + "details": "The Widget for Social Page Feeds WordPress plugin before 6.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13207" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c3e27fa2-b6dd-48eb-83ec-99dc034eff38" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T06:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6975-j4h6-fxff/GHSA-6975-j4h6-fxff.json b/advisories/unreviewed/2025/04/GHSA-6975-j4h6-fxff/GHSA-6975-j4h6-fxff.json new file mode 100644 index 00000000000..0786fcead63 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6975-j4h6-fxff/GHSA-6975-j4h6-fxff.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6975-j4h6-fxff", + "modified": "2025-04-15T06:30:34Z", + "published": "2025-04-15T06:30:34Z", + "aliases": [ + "CVE-2025-2225" + ], + "details": "The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rael_title_tag' parameter in all versions up to, and including, 1.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 1.6.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2225" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/responsive-addons-for-elementor/trunk/includes/widgets-manager/widgets/class-responsive-addons-for-elementor-icon-box.php#L2499" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3261241" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3263280" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f5ace7fb-530e-4a69-bbf7-e2c66491dd75?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T06:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j7px-pvwg-2r3m/GHSA-j7px-pvwg-2r3m.json b/advisories/unreviewed/2025/04/GHSA-j7px-pvwg-2r3m/GHSA-j7px-pvwg-2r3m.json new file mode 100644 index 00000000000..1214f67100b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j7px-pvwg-2r3m/GHSA-j7px-pvwg-2r3m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7px-pvwg-2r3m", + "modified": "2025-04-15T06:30:34Z", + "published": "2025-04-15T06:30:34Z", + "aliases": [ + "CVE-2025-29984" + ], + "details": "Dell Trusted Device, versions prior to 7.0.3.0, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29984" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000299528/dsa-2025-151" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T04:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jcc3-vmjf-jfhj/GHSA-jcc3-vmjf-jfhj.json b/advisories/unreviewed/2025/04/GHSA-jcc3-vmjf-jfhj/GHSA-jcc3-vmjf-jfhj.json new file mode 100644 index 00000000000..dad6abb9bba --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jcc3-vmjf-jfhj/GHSA-jcc3-vmjf-jfhj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcc3-vmjf-jfhj", + "modified": "2025-04-15T06:30:34Z", + "published": "2025-04-15T06:30:34Z", + "aliases": [ + "CVE-2024-13610" + ], + "details": "The Simple Social Media Share Buttons WordPress plugin before 6.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13610" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/85229528-1110-4d45-b972-8bbcba003a1f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T06:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mwmr-r556-9837/GHSA-mwmr-r556-9837.json b/advisories/unreviewed/2025/04/GHSA-mwmr-r556-9837/GHSA-mwmr-r556-9837.json new file mode 100644 index 00000000000..17f2322c41e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mwmr-r556-9837/GHSA-mwmr-r556-9837.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwmr-r556-9837", + "modified": "2025-04-15T06:30:34Z", + "published": "2025-04-15T06:30:34Z", + "aliases": [ + "CVE-2025-29983" + ], + "details": "Dell Trusted Device, versions prior to 7.0.3.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29983" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000299528/dsa-2025-151" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T04:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pcwj-m6p3-w8x3/GHSA-pcwj-m6p3-w8x3.json b/advisories/unreviewed/2025/04/GHSA-pcwj-m6p3-w8x3/GHSA-pcwj-m6p3-w8x3.json new file mode 100644 index 00000000000..f81fd4295e1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pcwj-m6p3-w8x3/GHSA-pcwj-m6p3-w8x3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcwj-m6p3-w8x3", + "modified": "2025-04-15T06:30:34Z", + "published": "2025-04-15T06:30:34Z", + "aliases": [ + "CVE-2025-32993" + ], + "details": "Vision Helpdesk through 5.7.0 allows Time-Based Blind SQL injection via the Forgot Password (aka index.php?/home/forgot-password) vis_username parameter. Authentication is not needed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32993" + }, + { + "type": "WEB", + "url": "https://nav1n.medium.com/sql-injection-in-vision-helpdesk-tools-a83dfc27f3ab" + }, + { + "type": "WEB", + "url": "https://www.visionhelpdesk.com/vision-helpdesk-v5-7-0-stable-version-released.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T06:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rfh5-gx7w-h7v7/GHSA-rfh5-gx7w-h7v7.json b/advisories/unreviewed/2025/04/GHSA-rfh5-gx7w-h7v7/GHSA-rfh5-gx7w-h7v7.json new file mode 100644 index 00000000000..81ccf4a1abb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rfh5-gx7w-h7v7/GHSA-rfh5-gx7w-h7v7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfh5-gx7w-h7v7", + "modified": "2025-04-15T06:30:34Z", + "published": "2025-04-15T06:30:34Z", + "aliases": [ + "CVE-2025-3576" + ], + "details": "A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3576" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-3576" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2359465" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-328" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T06:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rrj2-ph5q-jxw2/GHSA-rrj2-ph5q-jxw2.json b/advisories/unreviewed/2025/04/GHSA-rrj2-ph5q-jxw2/GHSA-rrj2-ph5q-jxw2.json new file mode 100644 index 00000000000..1a02de061f3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rrj2-ph5q-jxw2/GHSA-rrj2-ph5q-jxw2.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrj2-ph5q-jxw2", + "modified": "2025-04-15T06:30:34Z", + "published": "2025-04-15T06:30:34Z", + "aliases": [ + "CVE-2025-3573" + ], + "details": "Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This value will populate a message via $.validator.messages in a user localizable dictionary.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3573" + }, + { + "type": "WEB", + "url": "https://github.com/jquery-validation/jquery-validation/pull/2462" + }, + { + "type": "WEB", + "url": "https://github.com/jquery-validation/jquery-validation/commit/7a490d8f39bd988027568ddcf51755e1f4688902" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-JS-JQUERYVALIDATION-5952285" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T05:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-whpg-7794-8rqm/GHSA-whpg-7794-8rqm.json b/advisories/unreviewed/2025/04/GHSA-whpg-7794-8rqm/GHSA-whpg-7794-8rqm.json new file mode 100644 index 00000000000..1091ad32f16 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-whpg-7794-8rqm/GHSA-whpg-7794-8rqm.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whpg-7794-8rqm", + "modified": "2025-04-15T06:30:34Z", + "published": "2025-04-15T06:30:34Z", + "aliases": [ + "CVE-2025-3622" + ], + "details": "A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects the function load of the file xinference/thirdparty/cosyvoice/cli/model.py. The manipulation leads to deserialization.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3622" + }, + { + "type": "WEB", + "url": "https://github.com/xorbitsai/inference/issues/3190" + }, + { + "type": "WEB", + "url": "https://github.com/xorbitsai/inference/issues/3190#issuecomment-2783462266" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.304679" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.304679" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.552245" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-15T06:15:44Z" + } +} \ No newline at end of file