From bfeb68857a0af9fcb5e863bbd104c586d75eefcc Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sun, 2 Mar 2025 06:34:53 +0000 Subject: [PATCH] Publish GHSA-4qxw-jwh4-2vjv --- .../GHSA-4qxw-jwh4-2vjv.json | 52 +++++++++++++++++++ 1 file changed, 52 insertions(+) create mode 100644 advisories/unreviewed/2025/03/GHSA-4qxw-jwh4-2vjv/GHSA-4qxw-jwh4-2vjv.json diff --git a/advisories/unreviewed/2025/03/GHSA-4qxw-jwh4-2vjv/GHSA-4qxw-jwh4-2vjv.json b/advisories/unreviewed/2025/03/GHSA-4qxw-jwh4-2vjv/GHSA-4qxw-jwh4-2vjv.json new file mode 100644 index 00000000000..92927de8d49 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4qxw-jwh4-2vjv/GHSA-4qxw-jwh4-2vjv.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qxw-jwh4-2vjv", + "modified": "2025-03-02T06:33:26Z", + "published": "2025-03-02T06:33:26Z", + "aliases": [ + "CVE-2025-1809" + ], + "details": "A vulnerability was found in Pixsoft Sol up to 7.6.6c and classified as critical. This issue affects some unknown processing of the file /pix_projetos/servlet?act=login&submit=1&evento=0&pixrnd=0125021816444195731041 of the component Login Endpoint. The manipulation of the argument txtUsuario leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1809" + }, + { + "type": "WEB", + "url": "https://github.com/yago3008/cves" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298067" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298067" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.503275" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-02T06:15:22Z" + } +} \ No newline at end of file