diff --git a/advisories/unreviewed/2025/04/GHSA-36rp-732m-6hcp/GHSA-36rp-732m-6hcp.json b/advisories/unreviewed/2025/04/GHSA-36rp-732m-6hcp/GHSA-36rp-732m-6hcp.json new file mode 100644 index 00000000000..48268bf0c96 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-36rp-732m-6hcp/GHSA-36rp-732m-6hcp.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36rp-732m-6hcp", + "modified": "2025-04-08T00:30:26Z", + "published": "2025-04-08T00:30:26Z", + "aliases": [ + "CVE-2025-3385" + ], + "details": "A vulnerability was found in LinZhaoguan pb-cms 2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Classification Management Page. The manipulation of the argument Classification name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3385" + }, + { + "type": "WEB", + "url": "https://gitee.com/LinZhaoguan/pb-cms/issues/IBN3S0" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303631" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303631" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-64xv-53wr-f7jr/GHSA-64xv-53wr-f7jr.json b/advisories/unreviewed/2025/04/GHSA-64xv-53wr-f7jr/GHSA-64xv-53wr-f7jr.json new file mode 100644 index 00000000000..255bac56ccb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-64xv-53wr-f7jr/GHSA-64xv-53wr-f7jr.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64xv-53wr-f7jr", + "modified": "2025-04-08T00:30:27Z", + "published": "2025-04-08T00:30:27Z", + "aliases": [ + "CVE-2025-3386" + ], + "details": "A vulnerability was found in LinZhaoguan pb-cms 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin#links of the component Friendship Link Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3386" + }, + { + "type": "WEB", + "url": "https://gitee.com/LinZhaoguan/pb-cms/issues/IBN3MW" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303632" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303632" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7xhv-8pwp-m3fc/GHSA-7xhv-8pwp-m3fc.json b/advisories/unreviewed/2025/04/GHSA-7xhv-8pwp-m3fc/GHSA-7xhv-8pwp-m3fc.json new file mode 100644 index 00000000000..63e668d209d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7xhv-8pwp-m3fc/GHSA-7xhv-8pwp-m3fc.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xhv-8pwp-m3fc", + "modified": "2025-04-08T00:30:27Z", + "published": "2025-04-08T00:30:27Z", + "aliases": [ + "CVE-2025-3389" + ], + "details": "A vulnerability, which was classified as problematic, has been found in hailey888 oa_system up to 2025.01.01. This issue affects the function testMess of the file cn/gson/oasys/controller/inform/InformManageController.java of the component Backend. The manipulation of the argument menu leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3389" + }, + { + "type": "WEB", + "url": "https://gitee.com/hailey888/oa_system/issues/IBRQXH" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303635" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303635" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T00:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fw86-xhhv-rpg5/GHSA-fw86-xhhv-rpg5.json b/advisories/unreviewed/2025/04/GHSA-fw86-xhhv-rpg5/GHSA-fw86-xhhv-rpg5.json new file mode 100644 index 00000000000..6e22a9001d1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fw86-xhhv-rpg5/GHSA-fw86-xhhv-rpg5.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw86-xhhv-rpg5", + "modified": "2025-04-08T00:30:27Z", + "published": "2025-04-08T00:30:27Z", + "aliases": [ + "CVE-2025-3388" + ], + "details": "A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects the function loginCheck of the file cn/gson/oasys/controller/login/LoginsController.java of the component Frontend. The manipulation of the argument Username leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3388" + }, + { + "type": "WEB", + "url": "https://gitee.com/hailey888/oa_system/issues/IBRQYI" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303634" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303634" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T23:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gc6q-4496-9jf2/GHSA-gc6q-4496-9jf2.json b/advisories/unreviewed/2025/04/GHSA-gc6q-4496-9jf2/GHSA-gc6q-4496-9jf2.json new file mode 100644 index 00000000000..4731e2c9212 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gc6q-4496-9jf2/GHSA-gc6q-4496-9jf2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc6q-4496-9jf2", + "modified": "2025-04-08T00:30:26Z", + "published": "2025-04-08T00:30:26Z", + "aliases": [ + "CVE-2025-32409" + ], + "details": "Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to TCP port 60002, and placed into the correct image-update location as a consequence of both directory traversal and unintended handling of concurrency.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32409" + }, + { + "type": "WEB", + "url": "https://www.prizmlabs.io/post/remote-rootkits-uncovering-a-0-click-rce-in-the-supernote-nomad-e-ink-tablet" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qmp8-f8gr-pg77/GHSA-qmp8-f8gr-pg77.json b/advisories/unreviewed/2025/04/GHSA-qmp8-f8gr-pg77/GHSA-qmp8-f8gr-pg77.json new file mode 100644 index 00000000000..d55d455a13a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qmp8-f8gr-pg77/GHSA-qmp8-f8gr-pg77.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmp8-f8gr-pg77", + "modified": "2025-04-08T00:30:27Z", + "published": "2025-04-08T00:30:27Z", + "aliases": [ + "CVE-2025-3387" + ], + "details": "A vulnerability classified as problematic has been found in renrenio renren-security up to 5.4.0. This affects an unknown part of the component JSON Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3387" + }, + { + "type": "WEB", + "url": "https://gitee.com/renrenio/renren-security/issues/IBOU02" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303633" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303633" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T23:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qv5r-5qvq-7xgp/GHSA-qv5r-5qvq-7xgp.json b/advisories/unreviewed/2025/04/GHSA-qv5r-5qvq-7xgp/GHSA-qv5r-5qvq-7xgp.json new file mode 100644 index 00000000000..9c055bfada4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qv5r-5qvq-7xgp/GHSA-qv5r-5qvq-7xgp.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv5r-5qvq-7xgp", + "modified": "2025-04-08T00:30:27Z", + "published": "2025-04-08T00:30:27Z", + "aliases": [ + "CVE-2025-3390" + ], + "details": "A vulnerability, which was classified as problematic, was found in hailey888 oa_system up to 2025.01.01. Affected is the function addandchangeday of the file cn/gson/oass/controller/daymanager/DaymanageController.java of the component Backend. The manipulation of the argument scheduleList leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3390" + }, + { + "type": "WEB", + "url": "https://gitee.com/hailey888/oa_system/issues/IBRRZX" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303636" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303636" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T00:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vv22-vwq7-hqwj/GHSA-vv22-vwq7-hqwj.json b/advisories/unreviewed/2025/04/GHSA-vv22-vwq7-hqwj/GHSA-vv22-vwq7-hqwj.json new file mode 100644 index 00000000000..8e51a184134 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vv22-vwq7-hqwj/GHSA-vv22-vwq7-hqwj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv22-vwq7-hqwj", + "modified": "2025-04-08T00:30:26Z", + "published": "2025-04-08T00:30:26Z", + "aliases": [ + "CVE-2025-0942" + ], + "details": "The DB chooser functionality in Jalios JPlatform 10 SP6 before 10.0.6 improperly neutralizes special elements used in an SQL command allows for authenticated administrative users to trigger SQL Injection.\n\nThis issue affects JPlatform before 10.0.6 and a PatchPlugin release 10.0.6 was issued 2023-02-06.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0942" + }, + { + "type": "WEB", + "url": "https://community.jalios.com/jcms/jc2_734797/fr/avertissement-de-securite-2023-02-06" + }, + { + "type": "WEB", + "url": "https://community.jalios.com/patchplugin-10.0.6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-07T22:15:16Z" + } +} \ No newline at end of file