From bcd5084fb5562fc0465f808d171f8363560d20ff Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 20 Feb 2025 15:32:58 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-gvrx-mcwr-87pv.json | 4 +- .../GHSA-c2xh-vr49-pcp6.json | 4 +- .../GHSA-h63c-4f8g-75qg.json | 2 +- .../GHSA-298w-pg84-p7jw.json | 6 ++- .../GHSA-29x9-gccg-r992.json | 33 ++++++++++++++ .../GHSA-2v3m-p433-pwh8.json | 33 ++++++++++++++ .../GHSA-44hx-fmcp-x4qh.json | 33 ++++++++++++++ .../GHSA-4797-mjw6-28fm.json | 33 ++++++++++++++ .../GHSA-53fw-hrcf-m25v.json | 33 ++++++++++++++ .../GHSA-572j-cqp5-7xrw.json | 15 +++++-- .../GHSA-5f3r-pg69-63xp.json | 15 +++++-- .../GHSA-7qm6-crcf-w49m.json | 33 ++++++++++++++ .../GHSA-93jg-3qrg-49hq.json | 33 ++++++++++++++ .../GHSA-9qjq-983m-84r8.json | 44 +++++++++++++++++++ .../GHSA-cv3f-w5gj-ccpf.json | 15 +++++-- .../GHSA-fp97-fcph-wh29.json | 15 +++++-- .../GHSA-gcrj-wc48-gvjv.json | 33 ++++++++++++++ .../GHSA-hwqj-cjw9-27x8.json | 15 +++++-- .../GHSA-m4wh-553v-44vf.json | 33 ++++++++++++++ .../GHSA-p3mv-qf8j-947x.json | 36 +++++++++++++++ .../GHSA-p4xp-95h3-7gxv.json | 15 +++++-- .../GHSA-pf5r-3jm5-9v36.json | 15 +++++-- .../GHSA-pvq9-qx3f-f2w3.json | 15 +++++-- .../GHSA-qmvw-mmq3-8fjr.json | 15 +++++-- .../GHSA-qr42-xhm2-jg7w.json | 15 +++++-- .../GHSA-r34m-q473-j9rr.json | 15 +++++-- .../GHSA-vgc7-r882-frmh.json | 15 +++++-- .../GHSA-vq4v-4wp7-96x4.json | 36 +++++++++++++++ .../GHSA-wq23-w7cm-hgg8.json | 33 ++++++++++++++ .../GHSA-wr4v-2x2x-cprg.json | 15 +++++-- .../GHSA-xr3q-grc8-j3mx.json | 15 +++++-- .../GHSA-xxwx-qg6p-mx7w.json | 33 ++++++++++++++ 32 files changed, 644 insertions(+), 61 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-29x9-gccg-r992/GHSA-29x9-gccg-r992.json create mode 100644 advisories/unreviewed/2025/02/GHSA-2v3m-p433-pwh8/GHSA-2v3m-p433-pwh8.json create mode 100644 advisories/unreviewed/2025/02/GHSA-44hx-fmcp-x4qh/GHSA-44hx-fmcp-x4qh.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4797-mjw6-28fm/GHSA-4797-mjw6-28fm.json create mode 100644 advisories/unreviewed/2025/02/GHSA-53fw-hrcf-m25v/GHSA-53fw-hrcf-m25v.json create mode 100644 advisories/unreviewed/2025/02/GHSA-7qm6-crcf-w49m/GHSA-7qm6-crcf-w49m.json create mode 100644 advisories/unreviewed/2025/02/GHSA-93jg-3qrg-49hq/GHSA-93jg-3qrg-49hq.json create mode 100644 advisories/unreviewed/2025/02/GHSA-9qjq-983m-84r8/GHSA-9qjq-983m-84r8.json create mode 100644 advisories/unreviewed/2025/02/GHSA-gcrj-wc48-gvjv/GHSA-gcrj-wc48-gvjv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-m4wh-553v-44vf/GHSA-m4wh-553v-44vf.json create mode 100644 advisories/unreviewed/2025/02/GHSA-p3mv-qf8j-947x/GHSA-p3mv-qf8j-947x.json create mode 100644 advisories/unreviewed/2025/02/GHSA-vq4v-4wp7-96x4/GHSA-vq4v-4wp7-96x4.json create mode 100644 advisories/unreviewed/2025/02/GHSA-wq23-w7cm-hgg8/GHSA-wq23-w7cm-hgg8.json create mode 100644 advisories/unreviewed/2025/02/GHSA-xxwx-qg6p-mx7w/GHSA-xxwx-qg6p-mx7w.json diff --git a/advisories/unreviewed/2024/03/GHSA-gvrx-mcwr-87pv/GHSA-gvrx-mcwr-87pv.json b/advisories/unreviewed/2024/03/GHSA-gvrx-mcwr-87pv/GHSA-gvrx-mcwr-87pv.json index dda693e4881..ecec0a013a2 100644 --- a/advisories/unreviewed/2024/03/GHSA-gvrx-mcwr-87pv/GHSA-gvrx-mcwr-87pv.json +++ b/advisories/unreviewed/2024/03/GHSA-gvrx-mcwr-87pv/GHSA-gvrx-mcwr-87pv.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-gvrx-mcwr-87pv", - "modified": "2024-03-17T18:30:48Z", + "modified": "2025-02-20T15:31:06Z", "published": "2024-03-17T18:30:48Z", "aliases": [ "CVE-2024-24867" ], - "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Osamaesh WP Visitor Statistics (Real Time Traffic).This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 6.9.4.\n\n", + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Osamaesh WP Visitor Statistics (Real Time Traffic).This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 6.9.4.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/06/GHSA-c2xh-vr49-pcp6/GHSA-c2xh-vr49-pcp6.json b/advisories/unreviewed/2024/06/GHSA-c2xh-vr49-pcp6/GHSA-c2xh-vr49-pcp6.json index b8276d9598c..ce714a81308 100644 --- a/advisories/unreviewed/2024/06/GHSA-c2xh-vr49-pcp6/GHSA-c2xh-vr49-pcp6.json +++ b/advisories/unreviewed/2024/06/GHSA-c2xh-vr49-pcp6/GHSA-c2xh-vr49-pcp6.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-639" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-h63c-4f8g-75qg/GHSA-h63c-4f8g-75qg.json b/advisories/unreviewed/2024/08/GHSA-h63c-4f8g-75qg/GHSA-h63c-4f8g-75qg.json index 4955768548b..125207aab97 100644 --- a/advisories/unreviewed/2024/08/GHSA-h63c-4f8g-75qg/GHSA-h63c-4f8g-75qg.json +++ b/advisories/unreviewed/2024/08/GHSA-h63c-4f8g-75qg/GHSA-h63c-4f8g-75qg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h63c-4f8g-75qg", - "modified": "2024-08-20T12:30:27Z", + "modified": "2025-02-20T15:31:06Z", "published": "2024-08-20T12:30:27Z", "aliases": [ "CVE-2024-21689" diff --git a/advisories/unreviewed/2025/02/GHSA-298w-pg84-p7jw/GHSA-298w-pg84-p7jw.json b/advisories/unreviewed/2025/02/GHSA-298w-pg84-p7jw/GHSA-298w-pg84-p7jw.json index a2a6e693116..1991807817e 100644 --- a/advisories/unreviewed/2025/02/GHSA-298w-pg84-p7jw/GHSA-298w-pg84-p7jw.json +++ b/advisories/unreviewed/2025/02/GHSA-298w-pg84-p7jw/GHSA-298w-pg84-p7jw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-298w-pg84-p7jw", - "modified": "2025-02-20T00:32:05Z", + "modified": "2025-02-20T15:31:09Z", "published": "2025-02-20T00:32:05Z", "aliases": [ "CVE-2024-37361" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://support.pentaho.com/hc/en-us/articles/34298351866893--Resolved-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Improper-Neutralization-of-Input-During-Web-Page-Generation-Cross-site-Scripting-Versions-before-10-2-0-0-and-9-3-0-9-including-8-3-x-Impacted-CVE-2024-37360" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/34299135441805--Resolved-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Deserialization-of-Untrusted-Data-Versions-before-10-2-0-0-and-9-3-0-9-including-8-3-x-Impacted-CVE-2024-37361" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-29x9-gccg-r992/GHSA-29x9-gccg-r992.json b/advisories/unreviewed/2025/02/GHSA-29x9-gccg-r992/GHSA-29x9-gccg-r992.json new file mode 100644 index 00000000000..291bd7dbc2c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-29x9-gccg-r992/GHSA-29x9-gccg-r992.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29x9-gccg-r992", + "modified": "2025-02-20T15:31:10Z", + "published": "2025-02-20T15:31:10Z", + "aliases": [ + "CVE-2024-57401" + ], + "details": "SQL Injection vulnerability in Uniclare Student portal v.2 and before allows a remote attacker to execute arbitrary code via the Forgot Password function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57401" + }, + { + "type": "WEB", + "url": "https://github.com/aksingh82/CVE-2024-57401" + }, + { + "type": "WEB", + "url": "https://studentportal.universitysolutions.in" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2v3m-p433-pwh8/GHSA-2v3m-p433-pwh8.json b/advisories/unreviewed/2025/02/GHSA-2v3m-p433-pwh8/GHSA-2v3m-p433-pwh8.json new file mode 100644 index 00000000000..2cd779339db --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2v3m-p433-pwh8/GHSA-2v3m-p433-pwh8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v3m-p433-pwh8", + "modified": "2025-02-20T15:31:09Z", + "published": "2025-02-20T15:31:09Z", + "aliases": [ + "CVE-2023-51309" + ], + "details": "A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51309" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176492" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/car-park-booking/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-44hx-fmcp-x4qh/GHSA-44hx-fmcp-x4qh.json b/advisories/unreviewed/2025/02/GHSA-44hx-fmcp-x4qh/GHSA-44hx-fmcp-x4qh.json new file mode 100644 index 00000000000..b0bf98e60a8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-44hx-fmcp-x4qh/GHSA-44hx-fmcp-x4qh.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44hx-fmcp-x4qh", + "modified": "2025-02-20T15:31:09Z", + "published": "2025-02-20T15:31:09Z", + "aliases": [ + "CVE-2023-51306" + ], + "details": "PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the \"name, title\" parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51306" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176516" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/event-ticketing-system/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4797-mjw6-28fm/GHSA-4797-mjw6-28fm.json b/advisories/unreviewed/2025/02/GHSA-4797-mjw6-28fm/GHSA-4797-mjw6-28fm.json new file mode 100644 index 00000000000..a1444374e60 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4797-mjw6-28fm/GHSA-4797-mjw6-28fm.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4797-mjw6-28fm", + "modified": "2025-02-20T15:31:10Z", + "published": "2025-02-20T15:31:09Z", + "aliases": [ + "CVE-2023-51312" + ], + "details": "PHPJabbers Restaurant Booking System v3.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in Reservations menu, Schedule section date parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51312" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176493" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/restaurant-booking-system/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-53fw-hrcf-m25v/GHSA-53fw-hrcf-m25v.json b/advisories/unreviewed/2025/02/GHSA-53fw-hrcf-m25v/GHSA-53fw-hrcf-m25v.json new file mode 100644 index 00000000000..3b087a14601 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-53fw-hrcf-m25v/GHSA-53fw-hrcf-m25v.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53fw-hrcf-m25v", + "modified": "2025-02-20T15:31:09Z", + "published": "2025-02-20T15:31:09Z", + "aliases": [ + "CVE-2023-51311" + ], + "details": "PHPJabbers Car Park Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51311" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176494" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/car-park-booking/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-572j-cqp5-7xrw/GHSA-572j-cqp5-7xrw.json b/advisories/unreviewed/2025/02/GHSA-572j-cqp5-7xrw/GHSA-572j-cqp5-7xrw.json index 6fe23e0e44b..09eff475677 100644 --- a/advisories/unreviewed/2025/02/GHSA-572j-cqp5-7xrw/GHSA-572j-cqp5-7xrw.json +++ b/advisories/unreviewed/2025/02/GHSA-572j-cqp5-7xrw/GHSA-572j-cqp5-7xrw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-572j-cqp5-7xrw", - "modified": "2025-02-20T00:32:03Z", + "modified": "2025-02-20T15:31:08Z", "published": "2025-02-20T00:32:03Z", "aliases": [ "CVE-2023-51305" ], "details": "PHPJabbers Car Park Booking System v3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the \"name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key\" parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T23:15:09Z" diff --git a/advisories/unreviewed/2025/02/GHSA-5f3r-pg69-63xp/GHSA-5f3r-pg69-63xp.json b/advisories/unreviewed/2025/02/GHSA-5f3r-pg69-63xp/GHSA-5f3r-pg69-63xp.json index ecbaa6c49e6..6c5626c20ae 100644 --- a/advisories/unreviewed/2025/02/GHSA-5f3r-pg69-63xp/GHSA-5f3r-pg69-63xp.json +++ b/advisories/unreviewed/2025/02/GHSA-5f3r-pg69-63xp/GHSA-5f3r-pg69-63xp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5f3r-pg69-63xp", - "modified": "2025-02-20T00:32:04Z", + "modified": "2025-02-20T15:31:09Z", "published": "2025-02-20T00:32:04Z", "aliases": [ "CVE-2025-25945" ], "details": "An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4_DescriptorFactory::CreateDescriptorFromStream at Ap4DescriptorFactory.cpp.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T23:15:15Z" diff --git a/advisories/unreviewed/2025/02/GHSA-7qm6-crcf-w49m/GHSA-7qm6-crcf-w49m.json b/advisories/unreviewed/2025/02/GHSA-7qm6-crcf-w49m/GHSA-7qm6-crcf-w49m.json new file mode 100644 index 00000000000..249d6e59a80 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7qm6-crcf-w49m/GHSA-7qm6-crcf-w49m.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qm6-crcf-w49m", + "modified": "2025-02-20T15:31:09Z", + "published": "2025-02-20T15:31:09Z", + "aliases": [ + "CVE-2023-51308" + ], + "details": "PHPJabbers Car Park Booking System v3.0 is vulnerable to Multiple HTML Injection in the \"name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title\" parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51308" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176491" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/car-park-booking/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-93jg-3qrg-49hq/GHSA-93jg-3qrg-49hq.json b/advisories/unreviewed/2025/02/GHSA-93jg-3qrg-49hq/GHSA-93jg-3qrg-49hq.json new file mode 100644 index 00000000000..6a3a667bbb1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-93jg-3qrg-49hq/GHSA-93jg-3qrg-49hq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93jg-3qrg-49hq", + "modified": "2025-02-20T15:31:10Z", + "published": "2025-02-20T15:31:10Z", + "aliases": [ + "CVE-2023-51315" + ], + "details": "PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the \"seat_name, plugin_sms_api_key, plugin_sms_country_code, title, name\" parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51315" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176493" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/restaurant-booking-system/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9qjq-983m-84r8/GHSA-9qjq-983m-84r8.json b/advisories/unreviewed/2025/02/GHSA-9qjq-983m-84r8/GHSA-9qjq-983m-84r8.json new file mode 100644 index 00000000000..f9dcea06beb --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9qjq-983m-84r8/GHSA-9qjq-983m-84r8.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qjq-983m-84r8", + "modified": "2025-02-20T15:31:09Z", + "published": "2025-02-20T15:31:09Z", + "aliases": [ + "CVE-2025-1039" + ], + "details": "The Lenix Elementor Leads addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a URL form field in all versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1039" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3237538/lenix-elementor-leads-addon" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/0d1abaf9-4044-4dcc-95df-73f23a8a5a9f" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/29f835c8-769a-47c0-832f-622860b1c59c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cv3f-w5gj-ccpf/GHSA-cv3f-w5gj-ccpf.json b/advisories/unreviewed/2025/02/GHSA-cv3f-w5gj-ccpf/GHSA-cv3f-w5gj-ccpf.json index be3043aebf4..64d8058396b 100644 --- a/advisories/unreviewed/2025/02/GHSA-cv3f-w5gj-ccpf/GHSA-cv3f-w5gj-ccpf.json +++ b/advisories/unreviewed/2025/02/GHSA-cv3f-w5gj-ccpf/GHSA-cv3f-w5gj-ccpf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cv3f-w5gj-ccpf", - "modified": "2025-02-20T00:32:04Z", + "modified": "2025-02-20T15:31:08Z", "published": "2025-02-20T00:32:04Z", "aliases": [ "CVE-2025-25943" ], "details": "Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2Atom::AP4_Stz2Atom component located in Ap4Stz2Atom.cpp.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T23:15:15Z" diff --git a/advisories/unreviewed/2025/02/GHSA-fp97-fcph-wh29/GHSA-fp97-fcph-wh29.json b/advisories/unreviewed/2025/02/GHSA-fp97-fcph-wh29/GHSA-fp97-fcph-wh29.json index 7b6f2739999..0a059a8e929 100644 --- a/advisories/unreviewed/2025/02/GHSA-fp97-fcph-wh29/GHSA-fp97-fcph-wh29.json +++ b/advisories/unreviewed/2025/02/GHSA-fp97-fcph-wh29/GHSA-fp97-fcph-wh29.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fp97-fcph-wh29", - "modified": "2025-02-19T21:31:38Z", + "modified": "2025-02-20T15:31:08Z", "published": "2025-02-19T21:31:38Z", "aliases": [ "CVE-2023-51303" ], "details": "PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple HTML Injection in the \"lid, name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title\" parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T21:15:15Z" diff --git a/advisories/unreviewed/2025/02/GHSA-gcrj-wc48-gvjv/GHSA-gcrj-wc48-gvjv.json b/advisories/unreviewed/2025/02/GHSA-gcrj-wc48-gvjv/GHSA-gcrj-wc48-gvjv.json new file mode 100644 index 00000000000..b8378efac2b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gcrj-wc48-gvjv/GHSA-gcrj-wc48-gvjv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcrj-wc48-gvjv", + "modified": "2025-02-20T15:31:10Z", + "published": "2025-02-20T15:31:10Z", + "aliases": [ + "CVE-2023-51314" + ], + "details": "A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Restaurant Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51314" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176496" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/restaurant-booking-system/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hwqj-cjw9-27x8/GHSA-hwqj-cjw9-27x8.json b/advisories/unreviewed/2025/02/GHSA-hwqj-cjw9-27x8/GHSA-hwqj-cjw9-27x8.json index a84a65d766b..3a3ec8d1a0f 100644 --- a/advisories/unreviewed/2025/02/GHSA-hwqj-cjw9-27x8/GHSA-hwqj-cjw9-27x8.json +++ b/advisories/unreviewed/2025/02/GHSA-hwqj-cjw9-27x8/GHSA-hwqj-cjw9-27x8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hwqj-cjw9-27x8", - "modified": "2025-02-20T00:32:05Z", + "modified": "2025-02-20T15:31:09Z", "published": "2025-02-20T00:32:05Z", "aliases": [ "CVE-2025-25947" ], "details": "An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_AtomParent::RemoveChild, during the execution of mp4encrypt with a specially crafted MP4 input file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-665" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T23:15:15Z" diff --git a/advisories/unreviewed/2025/02/GHSA-m4wh-553v-44vf/GHSA-m4wh-553v-44vf.json b/advisories/unreviewed/2025/02/GHSA-m4wh-553v-44vf/GHSA-m4wh-553v-44vf.json new file mode 100644 index 00000000000..66b7d1bcd00 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m4wh-553v-44vf/GHSA-m4wh-553v-44vf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4wh-553v-44vf", + "modified": "2025-02-20T15:31:10Z", + "published": "2025-02-20T15:31:10Z", + "aliases": [ + "CVE-2023-51316" + ], + "details": "A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Bus Reservation System v1.1 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51316" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176497" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/bus-reservation-system/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p3mv-qf8j-947x/GHSA-p3mv-qf8j-947x.json b/advisories/unreviewed/2025/02/GHSA-p3mv-qf8j-947x/GHSA-p3mv-qf8j-947x.json new file mode 100644 index 00000000000..f35138d01f2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p3mv-qf8j-947x/GHSA-p3mv-qf8j-947x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3mv-qf8j-947x", + "modified": "2025-02-20T15:31:05Z", + "published": "2025-02-20T15:31:05Z", + "aliases": [ + "CVE-2023-22311" + ], + "details": "Improper access control in some Intel(R) Optane(TM) PMem 100 Series Management Software before version 01.00.00.3547 may allow an authenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22311" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00948.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p4xp-95h3-7gxv/GHSA-p4xp-95h3-7gxv.json b/advisories/unreviewed/2025/02/GHSA-p4xp-95h3-7gxv/GHSA-p4xp-95h3-7gxv.json index c8703a8bfa6..3b5632f3ccf 100644 --- a/advisories/unreviewed/2025/02/GHSA-p4xp-95h3-7gxv/GHSA-p4xp-95h3-7gxv.json +++ b/advisories/unreviewed/2025/02/GHSA-p4xp-95h3-7gxv/GHSA-p4xp-95h3-7gxv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p4xp-95h3-7gxv", - "modified": "2025-02-20T00:32:05Z", + "modified": "2025-02-20T15:31:09Z", "published": "2025-02-20T00:32:05Z", "aliases": [ "CVE-2025-25946" ], "details": "An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in AP4_MarlinIpmpEncryptingProcessor::Initialize and AP4_Processor::Process, during the execution of mp4encrypt with a specially crafted MP4 input file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T23:15:15Z" diff --git a/advisories/unreviewed/2025/02/GHSA-pf5r-3jm5-9v36/GHSA-pf5r-3jm5-9v36.json b/advisories/unreviewed/2025/02/GHSA-pf5r-3jm5-9v36/GHSA-pf5r-3jm5-9v36.json index d5ec75c961d..260ec3482a0 100644 --- a/advisories/unreviewed/2025/02/GHSA-pf5r-3jm5-9v36/GHSA-pf5r-3jm5-9v36.json +++ b/advisories/unreviewed/2025/02/GHSA-pf5r-3jm5-9v36/GHSA-pf5r-3jm5-9v36.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pf5r-3jm5-9v36", - "modified": "2025-02-20T00:32:04Z", + "modified": "2025-02-20T15:31:08Z", "published": "2025-02-20T00:32:04Z", "aliases": [ "CVE-2025-25944" ], "details": "Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the Ap4RtpAtom.cpp, specifically in AP4_RtpAtom::AP4_RtpAtom, during the execution of mp4fragment with a crafted MP4 input file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T23:15:15Z" diff --git a/advisories/unreviewed/2025/02/GHSA-pvq9-qx3f-f2w3/GHSA-pvq9-qx3f-f2w3.json b/advisories/unreviewed/2025/02/GHSA-pvq9-qx3f-f2w3/GHSA-pvq9-qx3f-f2w3.json index 0282cfa378b..91de86a0b75 100644 --- a/advisories/unreviewed/2025/02/GHSA-pvq9-qx3f-f2w3/GHSA-pvq9-qx3f-f2w3.json +++ b/advisories/unreviewed/2025/02/GHSA-pvq9-qx3f-f2w3/GHSA-pvq9-qx3f-f2w3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pvq9-qx3f-f2w3", - "modified": "2025-02-19T21:31:38Z", + "modified": "2025-02-20T15:31:06Z", "published": "2025-02-19T21:31:38Z", "aliases": [ "CVE-2023-51299" ], "details": "PHPJabbers Hotel Booking System v4.0 is vulnerable to HTML Injection in the \"name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title\" parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T20:15:35Z" diff --git a/advisories/unreviewed/2025/02/GHSA-qmvw-mmq3-8fjr/GHSA-qmvw-mmq3-8fjr.json b/advisories/unreviewed/2025/02/GHSA-qmvw-mmq3-8fjr/GHSA-qmvw-mmq3-8fjr.json index 9ac2bcd39d9..75b228019e1 100644 --- a/advisories/unreviewed/2025/02/GHSA-qmvw-mmq3-8fjr/GHSA-qmvw-mmq3-8fjr.json +++ b/advisories/unreviewed/2025/02/GHSA-qmvw-mmq3-8fjr/GHSA-qmvw-mmq3-8fjr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qmvw-mmq3-8fjr", - "modified": "2025-02-19T21:31:38Z", + "modified": "2025-02-20T15:31:06Z", "published": "2025-02-19T21:31:38Z", "aliases": [ "CVE-2023-51296" ], "details": "PHPJabbers Event Booking Calendar v4.0 is vulnerable to Cross-Site Scripting (XSS) in the \"name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key\" parameters which allows attackers to execute arbitrary code", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T19:15:14Z" diff --git a/advisories/unreviewed/2025/02/GHSA-qr42-xhm2-jg7w/GHSA-qr42-xhm2-jg7w.json b/advisories/unreviewed/2025/02/GHSA-qr42-xhm2-jg7w/GHSA-qr42-xhm2-jg7w.json index 0fc06608359..f124144f332 100644 --- a/advisories/unreviewed/2025/02/GHSA-qr42-xhm2-jg7w/GHSA-qr42-xhm2-jg7w.json +++ b/advisories/unreviewed/2025/02/GHSA-qr42-xhm2-jg7w/GHSA-qr42-xhm2-jg7w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qr42-xhm2-jg7w", - "modified": "2025-02-19T21:31:38Z", + "modified": "2025-02-20T15:31:06Z", "published": "2025-02-19T21:31:38Z", "aliases": [ "CVE-2023-51298" ], "details": "PHPJabbers Event Booking Calendar v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1236" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T20:15:34Z" diff --git a/advisories/unreviewed/2025/02/GHSA-r34m-q473-j9rr/GHSA-r34m-q473-j9rr.json b/advisories/unreviewed/2025/02/GHSA-r34m-q473-j9rr/GHSA-r34m-q473-j9rr.json index 3daf710a92c..5c17bdacb3e 100644 --- a/advisories/unreviewed/2025/02/GHSA-r34m-q473-j9rr/GHSA-r34m-q473-j9rr.json +++ b/advisories/unreviewed/2025/02/GHSA-r34m-q473-j9rr/GHSA-r34m-q473-j9rr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r34m-q473-j9rr", - "modified": "2025-02-19T21:31:38Z", + "modified": "2025-02-20T15:31:08Z", "published": "2025-02-19T21:31:38Z", "aliases": [ "CVE-2023-51302" ], "details": "PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1236" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T21:15:14Z" diff --git a/advisories/unreviewed/2025/02/GHSA-vgc7-r882-frmh/GHSA-vgc7-r882-frmh.json b/advisories/unreviewed/2025/02/GHSA-vgc7-r882-frmh/GHSA-vgc7-r882-frmh.json index a8f0b309d39..170fd8217a9 100644 --- a/advisories/unreviewed/2025/02/GHSA-vgc7-r882-frmh/GHSA-vgc7-r882-frmh.json +++ b/advisories/unreviewed/2025/02/GHSA-vgc7-r882-frmh/GHSA-vgc7-r882-frmh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vgc7-r882-frmh", - "modified": "2025-02-19T21:31:38Z", + "modified": "2025-02-20T15:31:08Z", "published": "2025-02-19T21:31:38Z", "aliases": [ "CVE-2023-51301" ], "details": "A lack of rate limiting in the \"Login Section, Forgot Email\" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T21:15:14Z" diff --git a/advisories/unreviewed/2025/02/GHSA-vq4v-4wp7-96x4/GHSA-vq4v-4wp7-96x4.json b/advisories/unreviewed/2025/02/GHSA-vq4v-4wp7-96x4/GHSA-vq4v-4wp7-96x4.json new file mode 100644 index 00000000000..130dfdef13a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vq4v-4wp7-96x4/GHSA-vq4v-4wp7-96x4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq4v-4wp7-96x4", + "modified": "2025-02-20T15:31:06Z", + "published": "2025-02-20T15:31:06Z", + "aliases": [ + "CVE-2023-27517" + ], + "details": "Improper access control in some Intel(R) Optane(TM) PMem software before versions 01.00.00.3547, 02.00.00.3915, 03.00.00.0483 may allow an athenticated user to potentially enable escalation of privilege via local access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27517" + }, + { + "type": "WEB", + "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00948.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-14T14:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wq23-w7cm-hgg8/GHSA-wq23-w7cm-hgg8.json b/advisories/unreviewed/2025/02/GHSA-wq23-w7cm-hgg8/GHSA-wq23-w7cm-hgg8.json new file mode 100644 index 00000000000..9e7f37ead4b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wq23-w7cm-hgg8/GHSA-wq23-w7cm-hgg8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq23-w7cm-hgg8", + "modified": "2025-02-20T15:31:09Z", + "published": "2025-02-20T15:31:09Z", + "aliases": [ + "CVE-2023-51310" + ], + "details": "A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Car Park Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51310" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176492" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/car-park-booking/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wr4v-2x2x-cprg/GHSA-wr4v-2x2x-cprg.json b/advisories/unreviewed/2025/02/GHSA-wr4v-2x2x-cprg/GHSA-wr4v-2x2x-cprg.json index 5a862a6e4ed..c018491ebba 100644 --- a/advisories/unreviewed/2025/02/GHSA-wr4v-2x2x-cprg/GHSA-wr4v-2x2x-cprg.json +++ b/advisories/unreviewed/2025/02/GHSA-wr4v-2x2x-cprg/GHSA-wr4v-2x2x-cprg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wr4v-2x2x-cprg", - "modified": "2025-02-20T00:32:04Z", + "modified": "2025-02-20T15:31:08Z", "published": "2025-02-20T00:32:04Z", "aliases": [ "CVE-2025-25942" ], "details": "An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specifically, memory allocated in SampleArray::SampleArray in Mp4Fragment.cpp is not properly released.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T23:15:15Z" diff --git a/advisories/unreviewed/2025/02/GHSA-xr3q-grc8-j3mx/GHSA-xr3q-grc8-j3mx.json b/advisories/unreviewed/2025/02/GHSA-xr3q-grc8-j3mx/GHSA-xr3q-grc8-j3mx.json index ecfc6e6327d..8b6c1fe8aff 100644 --- a/advisories/unreviewed/2025/02/GHSA-xr3q-grc8-j3mx/GHSA-xr3q-grc8-j3mx.json +++ b/advisories/unreviewed/2025/02/GHSA-xr3q-grc8-j3mx/GHSA-xr3q-grc8-j3mx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xr3q-grc8-j3mx", - "modified": "2025-02-19T21:31:38Z", + "modified": "2025-02-20T15:31:07Z", "published": "2025-02-19T21:31:38Z", "aliases": [ "CVE-2023-51300" ], "details": "PHPJabbers Hotel Booking System v4.0 is vulnerable to Cross-Site Scripting (XSS) vulnerabilities in the \"name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key\" parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-19T21:15:14Z" diff --git a/advisories/unreviewed/2025/02/GHSA-xxwx-qg6p-mx7w/GHSA-xxwx-qg6p-mx7w.json b/advisories/unreviewed/2025/02/GHSA-xxwx-qg6p-mx7w/GHSA-xxwx-qg6p-mx7w.json new file mode 100644 index 00000000000..7278d206034 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xxwx-qg6p-mx7w/GHSA-xxwx-qg6p-mx7w.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxwx-qg6p-mx7w", + "modified": "2025-02-20T15:31:10Z", + "published": "2025-02-20T15:31:10Z", + "aliases": [ + "CVE-2023-51313" + ], + "details": "PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51313" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/restaurant-booking-system/#sectionDemo" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176498/PHPJabbers-Restaurant-Booking-System-3.0-CSV-Injection.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T15:15:12Z" + } +} \ No newline at end of file