Publish Advisories

GHSA-phqx-gjxc-wrp9
GHSA-w4w8-q6pw-hgxq
GHSA-2mf6-q75m-3xr8
GHSA-63xr-9hmx-v966
GHSA-6mf2-fq9m-xrff
GHSA-82j5-p9gh-m4p2
GHSA-8mgr-c64f-w923
GHSA-h735-q6rm-hjcj
GHSA-xjpv-4c4j-wwp8
GHSA-xqm8-c3rv-5vpf
This commit is contained in:
advisory-database[bot]
2025-01-03 21:31:37 +00:00
parent abb8506cb9
commit aa8bea5253
10 changed files with 225 additions and 21 deletions
@@ -30,6 +30,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120",
"CWE-787"
],
"severity": "CRITICAL",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w4w8-q6pw-hgxq",
"modified": "2024-04-04T04:47:34Z",
"modified": "2025-01-03T21:30:38Z",
"published": "2023-06-13T18:30:39Z",
"aliases": [
"CVE-2023-31541"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2mf6-q75m-3xr8",
"modified": "2025-01-03T15:30:38Z",
"modified": "2025-01-03T21:30:40Z",
"published": "2025-01-03T15:30:38Z",
"aliases": [
"CVE-2024-48814"
],
"details": "SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-03T15:15:10Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-63xr-9hmx-v966",
"modified": "2025-01-03T18:30:34Z",
"modified": "2025-01-03T21:30:40Z",
"published": "2025-01-03T18:30:34Z",
"aliases": [
"CVE-2024-35365"
],
"details": "FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-415"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-03T18:15:15Z"
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6mf2-fq9m-xrff",
"modified": "2025-01-03T21:30:40Z",
"published": "2025-01-03T21:30:40Z",
"aliases": [
"CVE-2025-0196"
],
"details": "A vulnerability classified as critical has been found in code-projects Point of Sales and Inventory Management System 1.0. This affects an unknown part of the file /user/plist.php. The manipulation of the argument cat leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0196"
},
{
"type": "WEB",
"url": "https://code-projects.org"
},
{
"type": "WEB",
"url": "https://gist.github.com/Masamuneee/13b0a6384f0c07e8db462df9cb18fd47"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.290133"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.290133"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.473350"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-03T19:15:12Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-82j5-p9gh-m4p2",
"modified": "2025-01-03T21:30:40Z",
"published": "2025-01-03T21:30:40Z",
"aliases": [
"CVE-2025-0197"
],
"details": "A vulnerability classified as critical was found in code-projects Point of Sales and Inventory Management System 1.0. This vulnerability affects unknown code of the file /user/search.php. The manipulation of the argument name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0197"
},
{
"type": "WEB",
"url": "https://code-projects.org"
},
{
"type": "WEB",
"url": "https://gist.github.com/Masamuneee/07a787e5a4599954c178baf90eeb553c"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.290134"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.290134"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.473362"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-03T20:15:28Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8mgr-c64f-w923",
"modified": "2025-01-03T21:30:40Z",
"published": "2025-01-03T21:30:40Z",
"aliases": [
"CVE-2025-0198"
],
"details": "A vulnerability, which was classified as critical, has been found in code-projects Point of Sales and Inventory Management System 1.0. This issue affects some unknown processing of the file /user/search_result.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0198"
},
{
"type": "WEB",
"url": "https://code-projects.org"
},
{
"type": "WEB",
"url": "https://gist.github.com/Masamuneee/86580188bf42580c0ae70ae4d247e6df"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.290135"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.290135"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.473383"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-03T21:15:14Z"
}
}
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h735-q6rm-hjcj",
"modified": "2025-01-03T18:30:34Z",
"modified": "2025-01-03T21:30:40Z",
"published": "2025-01-03T18:30:34Z",
"aliases": [
"CVE-2024-55507"
],
"details": "An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-281"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-03T16:15:26Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xjpv-4c4j-wwp8",
"modified": "2025-01-03T15:30:38Z",
"modified": "2025-01-03T21:30:40Z",
"published": "2025-01-03T15:30:38Z",
"aliases": [
"CVE-2024-55078"
],
"details": "An arbitrary file upload vulnerability in the component /adminUser/updateImg of WukongCRM-11.0-JAVA v11.3.3 allows attackers to execute arbitrary code via uploading a crafted file.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-434"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-03T15:15:10Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xqm8-c3rv-5vpf",
"modified": "2025-01-03T18:30:34Z",
"modified": "2025-01-03T21:30:40Z",
"published": "2025-01-03T18:30:34Z",
"aliases": [
"CVE-2024-36613"
],
"details": "FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-190"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-03T18:15:15Z"