diff --git a/advisories/unreviewed/2025/04/GHSA-3f9h-26qj-9vvx/GHSA-3f9h-26qj-9vvx.json b/advisories/unreviewed/2025/04/GHSA-3f9h-26qj-9vvx/GHSA-3f9h-26qj-9vvx.json new file mode 100644 index 00000000000..a6e07ce97c8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3f9h-26qj-9vvx/GHSA-3f9h-26qj-9vvx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3f9h-26qj-9vvx", + "modified": "2025-04-21T09:32:10Z", + "published": "2025-04-21T09:32:10Z", + "aliases": [ + "CVE-2025-25228" + ], + "details": "A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the product management area in backend.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25228" + }, + { + "type": "WEB", + "url": "https://github.com/AdamWallwork/CVEs/tree/main/2025/CVE-2025-25228" + }, + { + "type": "WEB", + "url": "https://virtuemart.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T08:15:29Z" + } +} \ No newline at end of file