From cd76f415bb75c44eb8f5ef36887b28b4d946ee7c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sun, 6 Apr 2025 12:31:53 +0000 Subject: [PATCH] Publish Advisories GHSA-2365-7mr9-wqp2 GHSA-6qh2-pgmg-mwcw GHSA-94g7-vr86-j7x5 --- .../GHSA-2365-7mr9-wqp2.json | 48 ++++++++++++++++ .../GHSA-6qh2-pgmg-mwcw.json | 56 +++++++++++++++++++ .../GHSA-94g7-vr86-j7x5.json | 56 +++++++++++++++++++ 3 files changed, 160 insertions(+) create mode 100644 advisories/unreviewed/2025/04/GHSA-2365-7mr9-wqp2/GHSA-2365-7mr9-wqp2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6qh2-pgmg-mwcw/GHSA-6qh2-pgmg-mwcw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-94g7-vr86-j7x5/GHSA-94g7-vr86-j7x5.json diff --git a/advisories/unreviewed/2025/04/GHSA-2365-7mr9-wqp2/GHSA-2365-7mr9-wqp2.json b/advisories/unreviewed/2025/04/GHSA-2365-7mr9-wqp2/GHSA-2365-7mr9-wqp2.json new file mode 100644 index 00000000000..857c05ac6db --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2365-7mr9-wqp2/GHSA-2365-7mr9-wqp2.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2365-7mr9-wqp2", + "modified": "2025-04-06T12:30:27Z", + "published": "2025-04-06T12:30:27Z", + "aliases": [ + "CVE-2025-3317" + ], + "details": "A vulnerability classified as problematic has been found in fumiao opencms up to a0fafa5cff58719e9b27c2a2eec204cc165ce14f. Affected is an unknown function of the file opencms-dev/src/main/webapp/view/admin/document/dataPage.jsp. The manipulation of the argument path leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3317" + }, + { + "type": "WEB", + "url": "https://gitee.com/fumiao/opencms/issues/IBLJLM" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303516" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303516" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-06T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6qh2-pgmg-mwcw/GHSA-6qh2-pgmg-mwcw.json b/advisories/unreviewed/2025/04/GHSA-6qh2-pgmg-mwcw/GHSA-6qh2-pgmg-mwcw.json new file mode 100644 index 00000000000..218d76afadd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6qh2-pgmg-mwcw/GHSA-6qh2-pgmg-mwcw.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qh2-pgmg-mwcw", + "modified": "2025-04-06T12:30:27Z", + "published": "2025-04-06T12:30:27Z", + "aliases": [ + "CVE-2025-3315" + ], + "details": "A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /view-report.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3315" + }, + { + "type": "WEB", + "url": "https://github.com/alc9700jmo/CVE/issues/11" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303512" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303512" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.551262" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-06T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-94g7-vr86-j7x5/GHSA-94g7-vr86-j7x5.json b/advisories/unreviewed/2025/04/GHSA-94g7-vr86-j7x5/GHSA-94g7-vr86-j7x5.json new file mode 100644 index 00000000000..826af5438e0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-94g7-vr86-j7x5/GHSA-94g7-vr86-j7x5.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94g7-vr86-j7x5", + "modified": "2025-04-06T12:30:27Z", + "published": "2025-04-06T12:30:27Z", + "aliases": [ + "CVE-2025-3316" + ], + "details": "A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/search-invoices.php. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3316" + }, + { + "type": "WEB", + "url": "https://github.com/zhaolu33/CVE/issues/3" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303515" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303515" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.551749" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-06T11:15:39Z" + } +} \ No newline at end of file