Publish Advisories

GHSA-mfx3-9vhp-h958
GHSA-v7jj-p23v-hq9f
This commit is contained in:
advisory-database[bot]
2025-05-04 06:31:38 +00:00
parent 5c663584b5
commit a99537e1df
2 changed files with 112 additions and 0 deletions
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mfx3-9vhp-h958",
"modified": "2025-05-04T06:30:28Z",
"published": "2025-05-04T06:30:28Z",
"aliases": [
"CVE-2025-4248"
],
"details": "A vulnerability has been found in SourceCodester Simple To-Do List System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /complete_task.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4248"
},
{
"type": "WEB",
"url": "https://github.com/zonesec0/findcve/issues/9"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.307345"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.307345"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.562700"
},
{
"type": "WEB",
"url": "https://www.sourcecodester.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-04T06:15:14Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v7jj-p23v-hq9f",
"modified": "2025-05-04T06:30:28Z",
"published": "2025-05-04T06:30:28Z",
"aliases": [
"CVE-2025-4247"
],
"details": "A vulnerability, which was classified as critical, was found in SourceCodester Simple To-Do List System 1.0. Affected is an unknown function of the file /delete_task.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4247"
},
{
"type": "WEB",
"url": "https://github.com/zonesec0/findcve/issues/8"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.307344"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.307344"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.562699"
},
{
"type": "WEB",
"url": "https://www.sourcecodester.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-04T05:15:30Z"
}
}