diff --git a/advisories/unreviewed/2025/02/GHSA-cc77-xm2j-7rm6/GHSA-cc77-xm2j-7rm6.json b/advisories/unreviewed/2025/02/GHSA-cc77-xm2j-7rm6/GHSA-cc77-xm2j-7rm6.json index 1af94993c09..8b593b40a83 100644 --- a/advisories/unreviewed/2025/02/GHSA-cc77-xm2j-7rm6/GHSA-cc77-xm2j-7rm6.json +++ b/advisories/unreviewed/2025/02/GHSA-cc77-xm2j-7rm6/GHSA-cc77-xm2j-7rm6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-g7v8-vw35-p6rp/GHSA-g7v8-vw35-p6rp.json b/advisories/unreviewed/2025/02/GHSA-g7v8-vw35-p6rp/GHSA-g7v8-vw35-p6rp.json index 6fdb2e22c53..8b6f3660675 100644 --- a/advisories/unreviewed/2025/02/GHSA-g7v8-vw35-p6rp/GHSA-g7v8-vw35-p6rp.json +++ b/advisories/unreviewed/2025/02/GHSA-g7v8-vw35-p6rp/GHSA-g7v8-vw35-p6rp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-5g4q-39w7-g8vv/GHSA-5g4q-39w7-g8vv.json b/advisories/unreviewed/2025/03/GHSA-5g4q-39w7-g8vv/GHSA-5g4q-39w7-g8vv.json index dbf3c9dcbdf..03934532cd0 100644 --- a/advisories/unreviewed/2025/03/GHSA-5g4q-39w7-g8vv/GHSA-5g4q-39w7-g8vv.json +++ b/advisories/unreviewed/2025/03/GHSA-5g4q-39w7-g8vv/GHSA-5g4q-39w7-g8vv.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-87p5-fx92-387x/GHSA-87p5-fx92-387x.json b/advisories/unreviewed/2025/03/GHSA-87p5-fx92-387x/GHSA-87p5-fx92-387x.json index ad9a57cef16..2a19044cc65 100644 --- a/advisories/unreviewed/2025/03/GHSA-87p5-fx92-387x/GHSA-87p5-fx92-387x.json +++ b/advisories/unreviewed/2025/03/GHSA-87p5-fx92-387x/GHSA-87p5-fx92-387x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-87p5-fx92-387x", - "modified": "2025-03-05T12:31:10Z", + "modified": "2025-05-26T03:30:25Z", "published": "2025-03-05T12:31:10Z", "aliases": [ "CVE-2024-13757" diff --git a/advisories/unreviewed/2025/03/GHSA-9563-qrch-r2xp/GHSA-9563-qrch-r2xp.json b/advisories/unreviewed/2025/03/GHSA-9563-qrch-r2xp/GHSA-9563-qrch-r2xp.json index b5a809d6337..2bd32a85f50 100644 --- a/advisories/unreviewed/2025/03/GHSA-9563-qrch-r2xp/GHSA-9563-qrch-r2xp.json +++ b/advisories/unreviewed/2025/03/GHSA-9563-qrch-r2xp/GHSA-9563-qrch-r2xp.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-978f-3hph-xcgf/GHSA-978f-3hph-xcgf.json b/advisories/unreviewed/2025/03/GHSA-978f-3hph-xcgf/GHSA-978f-3hph-xcgf.json index 83f69284e28..df709ce615d 100644 --- a/advisories/unreviewed/2025/03/GHSA-978f-3hph-xcgf/GHSA-978f-3hph-xcgf.json +++ b/advisories/unreviewed/2025/03/GHSA-978f-3hph-xcgf/GHSA-978f-3hph-xcgf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-978f-3hph-xcgf", - "modified": "2025-03-05T12:31:09Z", + "modified": "2025-05-26T03:30:25Z", "published": "2025-03-05T12:31:09Z", "aliases": [ "CVE-2024-11731" diff --git a/advisories/unreviewed/2025/03/GHSA-9pph-j6v9-q8xv/GHSA-9pph-j6v9-q8xv.json b/advisories/unreviewed/2025/03/GHSA-9pph-j6v9-q8xv/GHSA-9pph-j6v9-q8xv.json index 3e31cae172e..7f35f20a298 100644 --- a/advisories/unreviewed/2025/03/GHSA-9pph-j6v9-q8xv/GHSA-9pph-j6v9-q8xv.json +++ b/advisories/unreviewed/2025/03/GHSA-9pph-j6v9-q8xv/GHSA-9pph-j6v9-q8xv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9pph-j6v9-q8xv", - "modified": "2025-03-01T09:30:29Z", + "modified": "2025-05-26T03:30:24Z", "published": "2025-03-01T09:30:29Z", "aliases": [ "CVE-2024-13697" diff --git a/advisories/unreviewed/2025/03/GHSA-fqr8-q3mh-59gh/GHSA-fqr8-q3mh-59gh.json b/advisories/unreviewed/2025/03/GHSA-fqr8-q3mh-59gh/GHSA-fqr8-q3mh-59gh.json index 703d19bf569..420fd44f9b1 100644 --- a/advisories/unreviewed/2025/03/GHSA-fqr8-q3mh-59gh/GHSA-fqr8-q3mh-59gh.json +++ b/advisories/unreviewed/2025/03/GHSA-fqr8-q3mh-59gh/GHSA-fqr8-q3mh-59gh.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-fwv7-rrjm-6m82/GHSA-fwv7-rrjm-6m82.json b/advisories/unreviewed/2025/03/GHSA-fwv7-rrjm-6m82/GHSA-fwv7-rrjm-6m82.json index 1d7524be34d..585c5f8416b 100644 --- a/advisories/unreviewed/2025/03/GHSA-fwv7-rrjm-6m82/GHSA-fwv7-rrjm-6m82.json +++ b/advisories/unreviewed/2025/03/GHSA-fwv7-rrjm-6m82/GHSA-fwv7-rrjm-6m82.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-gjf5-5c3r-89f6/GHSA-gjf5-5c3r-89f6.json b/advisories/unreviewed/2025/03/GHSA-gjf5-5c3r-89f6/GHSA-gjf5-5c3r-89f6.json index 41e513280c0..e4465d62d80 100644 --- a/advisories/unreviewed/2025/03/GHSA-gjf5-5c3r-89f6/GHSA-gjf5-5c3r-89f6.json +++ b/advisories/unreviewed/2025/03/GHSA-gjf5-5c3r-89f6/GHSA-gjf5-5c3r-89f6.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-j48h-86ph-5xjx/GHSA-j48h-86ph-5xjx.json b/advisories/unreviewed/2025/03/GHSA-j48h-86ph-5xjx/GHSA-j48h-86ph-5xjx.json index bbc36c026cb..89a273f402b 100644 --- a/advisories/unreviewed/2025/03/GHSA-j48h-86ph-5xjx/GHSA-j48h-86ph-5xjx.json +++ b/advisories/unreviewed/2025/03/GHSA-j48h-86ph-5xjx/GHSA-j48h-86ph-5xjx.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-m8hc-hmrj-mf93/GHSA-m8hc-hmrj-mf93.json b/advisories/unreviewed/2025/03/GHSA-m8hc-hmrj-mf93/GHSA-m8hc-hmrj-mf93.json index a1eaca16a85..5bff06bc130 100644 --- a/advisories/unreviewed/2025/03/GHSA-m8hc-hmrj-mf93/GHSA-m8hc-hmrj-mf93.json +++ b/advisories/unreviewed/2025/03/GHSA-m8hc-hmrj-mf93/GHSA-m8hc-hmrj-mf93.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m8hc-hmrj-mf93", - "modified": "2025-03-11T09:30:30Z", + "modified": "2025-05-26T03:30:25Z", "published": "2025-03-11T09:30:30Z", "aliases": [ "CVE-2024-13228" diff --git a/advisories/unreviewed/2025/03/GHSA-pw2f-j76p-vrqv/GHSA-pw2f-j76p-vrqv.json b/advisories/unreviewed/2025/03/GHSA-pw2f-j76p-vrqv/GHSA-pw2f-j76p-vrqv.json index 72769d71264..5ab7d6b4acf 100644 --- a/advisories/unreviewed/2025/03/GHSA-pw2f-j76p-vrqv/GHSA-pw2f-j76p-vrqv.json +++ b/advisories/unreviewed/2025/03/GHSA-pw2f-j76p-vrqv/GHSA-pw2f-j76p-vrqv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pw2f-j76p-vrqv", - "modified": "2025-03-05T09:30:52Z", + "modified": "2025-05-26T03:30:25Z", "published": "2025-03-05T09:30:52Z", "aliases": [ "CVE-2024-13350" diff --git a/advisories/unreviewed/2025/03/GHSA-qj3j-gr5j-56r7/GHSA-qj3j-gr5j-56r7.json b/advisories/unreviewed/2025/03/GHSA-qj3j-gr5j-56r7/GHSA-qj3j-gr5j-56r7.json index 1998f2ad1aa..5d4b3b2f131 100644 --- a/advisories/unreviewed/2025/03/GHSA-qj3j-gr5j-56r7/GHSA-qj3j-gr5j-56r7.json +++ b/advisories/unreviewed/2025/03/GHSA-qj3j-gr5j-56r7/GHSA-qj3j-gr5j-56r7.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-x5gg-v967-8wc4/GHSA-x5gg-v967-8wc4.json b/advisories/unreviewed/2025/03/GHSA-x5gg-v967-8wc4/GHSA-x5gg-v967-8wc4.json index a66ed190701..b0108c611ce 100644 --- a/advisories/unreviewed/2025/03/GHSA-x5gg-v967-8wc4/GHSA-x5gg-v967-8wc4.json +++ b/advisories/unreviewed/2025/03/GHSA-x5gg-v967-8wc4/GHSA-x5gg-v967-8wc4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x5gg-v967-8wc4", - "modified": "2025-03-01T06:30:53Z", + "modified": "2025-05-26T03:30:24Z", "published": "2025-03-01T06:30:53Z", "aliases": [ "CVE-2024-13901" diff --git a/advisories/unreviewed/2025/03/GHSA-x8w2-qrcv-wgc3/GHSA-x8w2-qrcv-wgc3.json b/advisories/unreviewed/2025/03/GHSA-x8w2-qrcv-wgc3/GHSA-x8w2-qrcv-wgc3.json index d296475557d..8be70d2fdea 100644 --- a/advisories/unreviewed/2025/03/GHSA-x8w2-qrcv-wgc3/GHSA-x8w2-qrcv-wgc3.json +++ b/advisories/unreviewed/2025/03/GHSA-x8w2-qrcv-wgc3/GHSA-x8w2-qrcv-wgc3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x8w2-qrcv-wgc3", - "modified": "2025-03-13T06:30:34Z", + "modified": "2025-05-26T03:30:25Z", "published": "2025-03-13T06:30:34Z", "aliases": [ "CVE-2025-1561" diff --git a/advisories/unreviewed/2025/05/GHSA-7x63-6wwc-qg67/GHSA-7x63-6wwc-qg67.json b/advisories/unreviewed/2025/05/GHSA-7x63-6wwc-qg67/GHSA-7x63-6wwc-qg67.json new file mode 100644 index 00000000000..527bb5f3f48 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7x63-6wwc-qg67/GHSA-7x63-6wwc-qg67.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x63-6wwc-qg67", + "modified": "2025-05-26T03:30:25Z", + "published": "2025-05-26T03:30:25Z", + "aliases": [ + "CVE-2025-5163" + ], + "details": "A vulnerability, which was classified as problematic, was found in yangshare 技术杨工 warehouseManager 仓库管理系统 1.0. This affects an unknown part. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5163" + }, + { + "type": "WEB", + "url": "https://github.com/sumingwjl/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310251" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310251" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.576315" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-26T02:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mcm6-cpvx-gpc6/GHSA-mcm6-cpvx-gpc6.json b/advisories/unreviewed/2025/05/GHSA-mcm6-cpvx-gpc6/GHSA-mcm6-cpvx-gpc6.json new file mode 100644 index 00000000000..791d09f17fe --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mcm6-cpvx-gpc6/GHSA-mcm6-cpvx-gpc6.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcm6-cpvx-gpc6", + "modified": "2025-05-26T03:30:25Z", + "published": "2025-05-26T03:30:25Z", + "aliases": [ + "CVE-2025-5161" + ], + "details": "A vulnerability classified as problematic was found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected by this vulnerability is the function operationDailyOut of the file /safeEvent/download. The manipulation of the argument filename leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5161" + }, + { + "type": "WEB", + "url": "https://flowus.cn/share/d78abd42-5de8-45f1-a941-a11a2581be0c?code=G8A6P3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310249" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310249" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.578678" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-26T01:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q22v-8f6w-43w8/GHSA-q22v-8f6w-43w8.json b/advisories/unreviewed/2025/05/GHSA-q22v-8f6w-43w8/GHSA-q22v-8f6w-43w8.json new file mode 100644 index 00000000000..855c2be19ed --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q22v-8f6w-43w8/GHSA-q22v-8f6w-43w8.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q22v-8f6w-43w8", + "modified": "2025-05-26T03:30:26Z", + "published": "2025-05-26T03:30:25Z", + "aliases": [ + "CVE-2025-5164" + ], + "details": "A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component JWT Handler. The manipulation leads to use of hard-coded cryptographic key\n . The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5164" + }, + { + "type": "WEB", + "url": "https://github.com/147536951/Qiany1/blob/main/Perfreeblog_3.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310252" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310252" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.576433" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-26T03:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q55x-cgc8-49xh/GHSA-q55x-cgc8-49xh.json b/advisories/unreviewed/2025/05/GHSA-q55x-cgc8-49xh/GHSA-q55x-cgc8-49xh.json new file mode 100644 index 00000000000..dcd449cbfa8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q55x-cgc8-49xh/GHSA-q55x-cgc8-49xh.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q55x-cgc8-49xh", + "modified": "2025-05-26T03:30:25Z", + "published": "2025-05-26T03:30:25Z", + "aliases": [ + "CVE-2025-5165" + ], + "details": "A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function MDCImporter::ValidateSurfaceHeader of the file assimp/code/AssetLib/MDC/MDCLoader.cpp. The manipulation of the argument pcSurface2 leads to out-of-bounds read. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5165" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6128" + }, + { + "type": "WEB", + "url": "https://github.com/assimp/assimp/issues/6167" + }, + { + "type": "WEB", + "url": "https://github.com/user-attachments/files/20204942/reproducer.zip" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310253" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310253" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.578000" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-26T03:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vqh7-q5w4-vwr6/GHSA-vqh7-q5w4-vwr6.json b/advisories/unreviewed/2025/05/GHSA-vqh7-q5w4-vwr6/GHSA-vqh7-q5w4-vwr6.json new file mode 100644 index 00000000000..10e8e3d2983 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vqh7-q5w4-vwr6/GHSA-vqh7-q5w4-vwr6.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqh7-q5w4-vwr6", + "modified": "2025-05-26T03:30:25Z", + "published": "2025-05-26T03:30:25Z", + "aliases": [ + "CVE-2025-5162" + ], + "details": "A vulnerability, which was classified as critical, has been found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected by this issue is some unknown functionality of the file /safeEvent/importFile/. The manipulation of the argument logGeneralFile/logGeneralFile_2 leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5162" + }, + { + "type": "WEB", + "url": "https://flowus.cn/share/ce6c4094-8d97-466c-8fcc-df3f3d6f314e?code=G8A6P3" + }, + { + "type": "WEB", + "url": "https://flowus.cn/share/d6c310ac-a179-499f-9e9a-5c0de80b19be?code=G8A6P3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310250" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310250" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.578679" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-26T01:15:21Z" + } +} \ No newline at end of file