From bf29ef2fe336f7763e36e0e3791592acbc89f165 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 4 Apr 2025 06:35:57 +0000 Subject: [PATCH] Publish Advisories GHSA-23cx-98wc-24qg GHSA-3gc7-fjrx-p6mg GHSA-436m-r88g-vhmq GHSA-4j95-6ppr-m85x GHSA-4vjr-hfpp-2m7w GHSA-7q45-mvf9-r93q GHSA-842m-396f-hgpg GHSA-8c9q-c5r4-q67m GHSA-8mmw-qfv3-2mgw GHSA-9376-rv54-429x GHSA-9gmr-vw8q-4xjq GHSA-fq5x-7292-2p5r GHSA-g9jw-53r4-8v8g GHSA-gffv-vp66-96qc GHSA-gmjv-5x6x-6hfr GHSA-jghh-64fm-ph6v GHSA-p357-62x7-hf5p GHSA-pc6c-whfr-9343 GHSA-pg7p-xxvc-73xx GHSA-qw64-6vcc-8ghx GHSA-v292-qccp-5g6f GHSA-wm96-jrv9-gggq GHSA-xmq2-8hhc-7629 --- .../GHSA-23cx-98wc-24qg.json | 56 +++++++++++++++++++ .../GHSA-3gc7-fjrx-p6mg.json | 48 ++++++++++++++++ .../GHSA-436m-r88g-vhmq.json | 36 ++++++++++++ .../GHSA-4j95-6ppr-m85x.json | 44 +++++++++++++++ .../GHSA-4vjr-hfpp-2m7w.json | 48 ++++++++++++++++ .../GHSA-7q45-mvf9-r93q.json | 52 +++++++++++++++++ .../GHSA-842m-396f-hgpg.json | 40 +++++++++++++ .../GHSA-8c9q-c5r4-q67m.json | 56 +++++++++++++++++++ .../GHSA-8mmw-qfv3-2mgw.json | 40 +++++++++++++ .../GHSA-9376-rv54-429x.json | 40 +++++++++++++ .../GHSA-9gmr-vw8q-4xjq.json | 56 +++++++++++++++++++ .../GHSA-fq5x-7292-2p5r.json | 44 +++++++++++++++ .../GHSA-g9jw-53r4-8v8g.json | 52 +++++++++++++++++ .../GHSA-gffv-vp66-96qc.json | 40 +++++++++++++ .../GHSA-gmjv-5x6x-6hfr.json | 44 +++++++++++++++ .../GHSA-jghh-64fm-ph6v.json | 56 +++++++++++++++++++ .../GHSA-p357-62x7-hf5p.json | 56 +++++++++++++++++++ .../GHSA-pc6c-whfr-9343.json | 36 ++++++++++++ .../GHSA-pg7p-xxvc-73xx.json | 29 ++++++++++ .../GHSA-qw64-6vcc-8ghx.json | 44 +++++++++++++++ .../GHSA-v292-qccp-5g6f.json | 40 +++++++++++++ .../GHSA-wm96-jrv9-gggq.json | 56 +++++++++++++++++++ .../GHSA-xmq2-8hhc-7629.json | 56 +++++++++++++++++++ 23 files changed, 1069 insertions(+) create mode 100644 advisories/unreviewed/2025/04/GHSA-23cx-98wc-24qg/GHSA-23cx-98wc-24qg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3gc7-fjrx-p6mg/GHSA-3gc7-fjrx-p6mg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-436m-r88g-vhmq/GHSA-436m-r88g-vhmq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4j95-6ppr-m85x/GHSA-4j95-6ppr-m85x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4vjr-hfpp-2m7w/GHSA-4vjr-hfpp-2m7w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7q45-mvf9-r93q/GHSA-7q45-mvf9-r93q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-842m-396f-hgpg/GHSA-842m-396f-hgpg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8c9q-c5r4-q67m/GHSA-8c9q-c5r4-q67m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8mmw-qfv3-2mgw/GHSA-8mmw-qfv3-2mgw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9376-rv54-429x/GHSA-9376-rv54-429x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9gmr-vw8q-4xjq/GHSA-9gmr-vw8q-4xjq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fq5x-7292-2p5r/GHSA-fq5x-7292-2p5r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g9jw-53r4-8v8g/GHSA-g9jw-53r4-8v8g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gffv-vp66-96qc/GHSA-gffv-vp66-96qc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gmjv-5x6x-6hfr/GHSA-gmjv-5x6x-6hfr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jghh-64fm-ph6v/GHSA-jghh-64fm-ph6v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p357-62x7-hf5p/GHSA-p357-62x7-hf5p.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pc6c-whfr-9343/GHSA-pc6c-whfr-9343.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pg7p-xxvc-73xx/GHSA-pg7p-xxvc-73xx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qw64-6vcc-8ghx/GHSA-qw64-6vcc-8ghx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v292-qccp-5g6f/GHSA-v292-qccp-5g6f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wm96-jrv9-gggq/GHSA-wm96-jrv9-gggq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xmq2-8hhc-7629/GHSA-xmq2-8hhc-7629.json diff --git a/advisories/unreviewed/2025/04/GHSA-23cx-98wc-24qg/GHSA-23cx-98wc-24qg.json b/advisories/unreviewed/2025/04/GHSA-23cx-98wc-24qg/GHSA-23cx-98wc-24qg.json new file mode 100644 index 00000000000..cb2aaf3c289 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-23cx-98wc-24qg/GHSA-23cx-98wc-24qg.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23cx-98wc-24qg", + "modified": "2025-04-04T06:34:23Z", + "published": "2025-04-04T06:34:23Z", + "aliases": [ + "CVE-2025-3208" + ], + "details": "A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /xray_print.php. The manipulation of the argument itr_no leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3208" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/ZOKEYE/CVE/blob/main/cve2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303162" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303162" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.545960" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T05:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3gc7-fjrx-p6mg/GHSA-3gc7-fjrx-p6mg.json b/advisories/unreviewed/2025/04/GHSA-3gc7-fjrx-p6mg/GHSA-3gc7-fjrx-p6mg.json new file mode 100644 index 00000000000..558b31f48ea --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3gc7-fjrx-p6mg/GHSA-3gc7-fjrx-p6mg.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gc7-fjrx-p6mg", + "modified": "2025-04-04T06:34:23Z", + "published": "2025-04-04T06:34:22Z", + "aliases": [ + "CVE-2025-3194" + ], + "details": "Versions of the package bigint-buffer from 0.0.0 are vulnerable to Buffer Overflow in the toBigIntLE() function. Attackers can exploit this to crash the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3194" + }, + { + "type": "WEB", + "url": "https://github.com/no2chem/bigint-buffer/blob/master/src/index.ts%23L25" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-JS-BIGINTBUFFER-3364597" + }, + { + "type": "WEB", + "url": "https://www.usenix.org/system/files/sec23fall-prepub-262_staicu.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T05:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-436m-r88g-vhmq/GHSA-436m-r88g-vhmq.json b/advisories/unreviewed/2025/04/GHSA-436m-r88g-vhmq/GHSA-436m-r88g-vhmq.json new file mode 100644 index 00000000000..bb955c3d76b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-436m-r88g-vhmq/GHSA-436m-r88g-vhmq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-436m-r88g-vhmq", + "modified": "2025-04-04T06:34:24Z", + "published": "2025-04-04T06:34:24Z", + "aliases": [ + "CVE-2024-42208" + ], + "details": "HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42208" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120347" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T06:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4j95-6ppr-m85x/GHSA-4j95-6ppr-m85x.json b/advisories/unreviewed/2025/04/GHSA-4j95-6ppr-m85x/GHSA-4j95-6ppr-m85x.json new file mode 100644 index 00000000000..53266c27473 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4j95-6ppr-m85x/GHSA-4j95-6ppr-m85x.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4j95-6ppr-m85x", + "modified": "2025-04-04T06:34:22Z", + "published": "2025-04-04T06:34:22Z", + "aliases": [ + "CVE-2025-2075" + ], + "details": "The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.0.2. This is due to add_role() and user_role() functions missing proper capability checks performed through the validate_rest_call() function. This makes it possible for unauthenticated attackers to set the role of arbitrary users to administrator granting full access to the site, though privilege escalation requires an active account on the site so this is considered an authenticated privilege escalation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2075" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3257300/uncanny-automator/trunk/src/core/classes/class-background-actions.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3265280/uncanny-automator/trunk/src/core/classes/class-background-actions.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/86b4b0d6-bda2-47f3-a0b5-9733cb7a11f6?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T05:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4vjr-hfpp-2m7w/GHSA-4vjr-hfpp-2m7w.json b/advisories/unreviewed/2025/04/GHSA-4vjr-hfpp-2m7w/GHSA-4vjr-hfpp-2m7w.json new file mode 100644 index 00000000000..e9c4b320631 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4vjr-hfpp-2m7w/GHSA-4vjr-hfpp-2m7w.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vjr-hfpp-2m7w", + "modified": "2025-04-04T06:34:23Z", + "published": "2025-04-04T06:34:23Z", + "aliases": [ + "CVE-2025-3197" + ], + "details": "Versions of the package expand-object from 0.0.0 are vulnerable to Prototype Pollution in the expand() function in index.js. This function expands the given string into an object and allows a nested property to be set without checking the provided keys for sensitive properties like __proto__.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3197" + }, + { + "type": "WEB", + "url": "https://gist.github.com/miguelafmonteiro/d8f66af61d14e06338b688f90c4dfa7c" + }, + { + "type": "WEB", + "url": "https://github.com/jonschlinkert/expand-object/blob/master/index.js%23L13" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-JS-EXPANDOBJECT-5821390" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1321" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T05:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7q45-mvf9-r93q/GHSA-7q45-mvf9-r93q.json b/advisories/unreviewed/2025/04/GHSA-7q45-mvf9-r93q/GHSA-7q45-mvf9-r93q.json new file mode 100644 index 00000000000..adac1cf7972 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7q45-mvf9-r93q/GHSA-7q45-mvf9-r93q.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q45-mvf9-r93q", + "modified": "2025-04-04T06:34:24Z", + "published": "2025-04-04T06:34:24Z", + "aliases": [ + "CVE-2025-2836" + ], + "details": "The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘payment_method’ parameter in all versions up to, and including, 6.0.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2836" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/custom-registration-form-builder-with-submission-manager/tags/6.0.4.3/includes/class_registration_magic.php#L1215" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/custom-registration-form-builder-with-submission-manager/tags/6.0.4.3/libs/factory/class_rm_form_factory_revamp.php#L1274" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/custom-registration-form-builder-with-submission-manager/tags/6.0.4.3/libs/factory/class_rm_form_factory_revamp.php#L1820" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3265041" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9c0c3932-bdb0-4edb-bfec-2ed52cbc5cb6?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T06:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-842m-396f-hgpg/GHSA-842m-396f-hgpg.json b/advisories/unreviewed/2025/04/GHSA-842m-396f-hgpg/GHSA-842m-396f-hgpg.json new file mode 100644 index 00000000000..7ae269f10a0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-842m-396f-hgpg/GHSA-842m-396f-hgpg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-842m-396f-hgpg", + "modified": "2025-04-04T06:34:24Z", + "published": "2025-04-04T06:34:24Z", + "aliases": [ + "CVE-2025-2270" + ], + "details": "The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.9.1 via the createCdObj function. This makes it possible for unauthenticated attackers to include and execute files with the specific filenames on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in some cases.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2270" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/countdown-builder/trunk/classes/RegisterPostType.php#L116" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c2260d6b-1a41-4757-a063-8b8857ef416a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T06:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8c9q-c5r4-q67m/GHSA-8c9q-c5r4-q67m.json b/advisories/unreviewed/2025/04/GHSA-8c9q-c5r4-q67m/GHSA-8c9q-c5r4-q67m.json new file mode 100644 index 00000000000..ab3d86631b9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8c9q-c5r4-q67m/GHSA-8c9q-c5r4-q67m.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8c9q-c5r4-q67m", + "modified": "2025-04-04T06:34:23Z", + "published": "2025-04-04T06:34:23Z", + "aliases": [ + "CVE-2025-3209" + ], + "details": "A vulnerability was found in code-projects Patient Record Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add_patient.php. The manipulation of the argument itr_no leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3209" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/yjlhk/cve/blob/main/README.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303163" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303163" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.545961" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T05:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8mmw-qfv3-2mgw/GHSA-8mmw-qfv3-2mgw.json b/advisories/unreviewed/2025/04/GHSA-8mmw-qfv3-2mgw/GHSA-8mmw-qfv3-2mgw.json new file mode 100644 index 00000000000..4e6bec9d320 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8mmw-qfv3-2mgw/GHSA-8mmw-qfv3-2mgw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mmw-qfv3-2mgw", + "modified": "2025-04-04T06:34:24Z", + "published": "2025-04-04T06:34:24Z", + "aliases": [ + "CVE-2024-13645" + ], + "details": "The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all versions up to, and including, 5.3 via module parameter. This makes it possible for unauthenticated attackers to Instantiate a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13645" + }, + { + "type": "WEB", + "url": "https://tagdiv.com/tagdiv-composer-page-builder-basics" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4124003c-4864-48f1-acba-9a613d9c99ae?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T06:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9376-rv54-429x/GHSA-9376-rv54-429x.json b/advisories/unreviewed/2025/04/GHSA-9376-rv54-429x/GHSA-9376-rv54-429x.json new file mode 100644 index 00000000000..6db58f78963 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9376-rv54-429x/GHSA-9376-rv54-429x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9376-rv54-429x", + "modified": "2025-04-04T06:34:24Z", + "published": "2025-04-04T06:34:24Z", + "aliases": [ + "CVE-2024-13708" + ], + "details": "The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in versions 4.0.1 to 7.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13708" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/woocommerce-jetpack/trunk/includes/class-wcj-checkout-files-upload.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f58b3971-e1e4-4337-82a3-99c9079c6696?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T06:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9gmr-vw8q-4xjq/GHSA-9gmr-vw8q-4xjq.json b/advisories/unreviewed/2025/04/GHSA-9gmr-vw8q-4xjq/GHSA-9gmr-vw8q-4xjq.json new file mode 100644 index 00000000000..c50674b1095 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9gmr-vw8q-4xjq/GHSA-9gmr-vw8q-4xjq.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gmr-vw8q-4xjq", + "modified": "2025-04-04T06:34:24Z", + "published": "2025-04-04T06:34:24Z", + "aliases": [ + "CVE-2025-3211" + ], + "details": "A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /birthing_print.php. The manipulation of the argument itr_no leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3211" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/codinglosser/cve/blob/main/README.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303165" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303165" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.545964" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-04T06:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fq5x-7292-2p5r/GHSA-fq5x-7292-2p5r.json b/advisories/unreviewed/2025/04/GHSA-fq5x-7292-2p5r/GHSA-fq5x-7292-2p5r.json new file mode 100644 index 00000000000..2b1a5ae2b32 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fq5x-7292-2p5r/GHSA-fq5x-7292-2p5r.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq5x-7292-2p5r", + "modified": "2025-04-04T06:34:22Z", + "published": "2025-04-04T06:34:22Z", + "aliases": [ + "CVE-2025-3191" + ], + "details": "All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the