From d14a668231b224595614751b6c469ebf87613b2e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 24 Feb 2025 06:32:32 +0000 Subject: [PATCH] Publish Advisories GHSA-33vw-m9w6-c8vf GHSA-g43j-hxv3-vq63 GHSA-gxcp-qqh4-j6r9 GHSA-p35r-x5m5-9rgr GHSA-q8ph-mxvw-mjvr GHSA-qv7v-32wc-p652 GHSA-rhv9-gvq2-f88v GHSA-vc8r-j6fr-x85j --- .../GHSA-33vw-m9w6-c8vf.json | 29 +++++++++++ .../GHSA-g43j-hxv3-vq63.json | 48 +++++++++++++++++ .../GHSA-gxcp-qqh4-j6r9.json | 29 +++++++++++ .../GHSA-p35r-x5m5-9rgr.json | 52 +++++++++++++++++++ .../GHSA-q8ph-mxvw-mjvr.json | 48 +++++++++++++++++ .../GHSA-qv7v-32wc-p652.json | 29 +++++++++++ .../GHSA-rhv9-gvq2-f88v.json | 48 +++++++++++++++++ .../GHSA-vc8r-j6fr-x85j.json | 48 +++++++++++++++++ 8 files changed, 331 insertions(+) create mode 100644 advisories/unreviewed/2025/02/GHSA-33vw-m9w6-c8vf/GHSA-33vw-m9w6-c8vf.json create mode 100644 advisories/unreviewed/2025/02/GHSA-g43j-hxv3-vq63/GHSA-g43j-hxv3-vq63.json create mode 100644 advisories/unreviewed/2025/02/GHSA-gxcp-qqh4-j6r9/GHSA-gxcp-qqh4-j6r9.json create mode 100644 advisories/unreviewed/2025/02/GHSA-p35r-x5m5-9rgr/GHSA-p35r-x5m5-9rgr.json create mode 100644 advisories/unreviewed/2025/02/GHSA-q8ph-mxvw-mjvr/GHSA-q8ph-mxvw-mjvr.json create mode 100644 advisories/unreviewed/2025/02/GHSA-qv7v-32wc-p652/GHSA-qv7v-32wc-p652.json create mode 100644 advisories/unreviewed/2025/02/GHSA-rhv9-gvq2-f88v/GHSA-rhv9-gvq2-f88v.json create mode 100644 advisories/unreviewed/2025/02/GHSA-vc8r-j6fr-x85j/GHSA-vc8r-j6fr-x85j.json diff --git a/advisories/unreviewed/2025/02/GHSA-33vw-m9w6-c8vf/GHSA-33vw-m9w6-c8vf.json b/advisories/unreviewed/2025/02/GHSA-33vw-m9w6-c8vf/GHSA-33vw-m9w6-c8vf.json new file mode 100644 index 00000000000..e4e9cc5edff --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-33vw-m9w6-c8vf/GHSA-33vw-m9w6-c8vf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33vw-m9w6-c8vf", + "modified": "2025-02-24T06:31:07Z", + "published": "2025-02-24T06:31:06Z", + "aliases": [ + "CVE-2024-12308" + ], + "details": "The Logo Slider WordPress plugin before 4.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12308" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/fa82ada7-357b-4f01-a0d6-ff633b188a80" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T06:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g43j-hxv3-vq63/GHSA-g43j-hxv3-vq63.json b/advisories/unreviewed/2025/02/GHSA-g43j-hxv3-vq63/GHSA-g43j-hxv3-vq63.json new file mode 100644 index 00000000000..b5439f949cd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g43j-hxv3-vq63/GHSA-g43j-hxv3-vq63.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g43j-hxv3-vq63", + "modified": "2025-02-24T06:31:06Z", + "published": "2025-02-24T06:31:06Z", + "aliases": [ + "CVE-2025-1617" + ], + "details": "A vulnerability, which was classified as problematic, was found in Netis WF2780 2.1.41925. This affects an unknown part of the component Wireless 2.4G Menu. The manipulation of the argument SSID leads to cross site scripting. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1617" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.296607" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.296607" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.501472" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T04:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gxcp-qqh4-j6r9/GHSA-gxcp-qqh4-j6r9.json b/advisories/unreviewed/2025/02/GHSA-gxcp-qqh4-j6r9/GHSA-gxcp-qqh4-j6r9.json new file mode 100644 index 00000000000..015112a6093 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gxcp-qqh4-j6r9/GHSA-gxcp-qqh4-j6r9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxcp-qqh4-j6r9", + "modified": "2025-02-24T06:31:07Z", + "published": "2025-02-24T06:31:06Z", + "aliases": [ + "CVE-2024-13822" + ], + "details": "The Photo Contest | Competition | Video Contest WordPress plugin through 2.8.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13822" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/1f0f1553-1987-428c-9fe3-ffb3f6b0aecc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p35r-x5m5-9rgr/GHSA-p35r-x5m5-9rgr.json b/advisories/unreviewed/2025/02/GHSA-p35r-x5m5-9rgr/GHSA-p35r-x5m5-9rgr.json new file mode 100644 index 00000000000..7b7cd86aaa2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p35r-x5m5-9rgr/GHSA-p35r-x5m5-9rgr.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p35r-x5m5-9rgr", + "modified": "2025-02-24T06:31:07Z", + "published": "2025-02-24T06:31:07Z", + "aliases": [ + "CVE-2025-1618" + ], + "details": "A vulnerability has been found in vTiger CRM 6.4.0 and classified as problematic. This vulnerability affects unknown code of the file /modules/Mobile/index.php. The manipulation of the argument _operation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1618" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.296608" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.296608" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.501840" + }, + { + "type": "WEB", + "url": "https://www.vtiger.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T05:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-q8ph-mxvw-mjvr/GHSA-q8ph-mxvw-mjvr.json b/advisories/unreviewed/2025/02/GHSA-q8ph-mxvw-mjvr/GHSA-q8ph-mxvw-mjvr.json new file mode 100644 index 00000000000..598d79bb61a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-q8ph-mxvw-mjvr/GHSA-q8ph-mxvw-mjvr.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8ph-mxvw-mjvr", + "modified": "2025-02-24T06:31:04Z", + "published": "2025-02-24T06:31:04Z", + "aliases": [ + "CVE-2025-1615" + ], + "details": "A vulnerability classified as problematic was found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this vulnerability is an unknown functionality of the component NAT Submenu. The manipulation of the argument Description leads to cross site scripting. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1615" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.296605" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.296605" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.501408" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qv7v-32wc-p652/GHSA-qv7v-32wc-p652.json b/advisories/unreviewed/2025/02/GHSA-qv7v-32wc-p652/GHSA-qv7v-32wc-p652.json new file mode 100644 index 00000000000..e525d47f56b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qv7v-32wc-p652/GHSA-qv7v-32wc-p652.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv7v-32wc-p652", + "modified": "2025-02-24T06:31:07Z", + "published": "2025-02-24T06:31:06Z", + "aliases": [ + "CVE-2024-13605" + ], + "details": "The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13605" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d5543b3b-1c28-481b-aba4-9a07d160e1f2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T06:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rhv9-gvq2-f88v/GHSA-rhv9-gvq2-f88v.json b/advisories/unreviewed/2025/02/GHSA-rhv9-gvq2-f88v/GHSA-rhv9-gvq2-f88v.json new file mode 100644 index 00000000000..de8dbbb09f4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rhv9-gvq2-f88v/GHSA-rhv9-gvq2-f88v.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhv9-gvq2-f88v", + "modified": "2025-02-24T06:31:06Z", + "published": "2025-02-24T06:31:06Z", + "aliases": [ + "CVE-2025-1616" + ], + "details": "A vulnerability, which was classified as critical, has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this issue is some unknown functionality of the component Diagnosis. The manipulation of the argument Destination Address leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1616" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.296606" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.296606" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.501483" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T04:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vc8r-j6fr-x85j/GHSA-vc8r-j6fr-x85j.json b/advisories/unreviewed/2025/02/GHSA-vc8r-j6fr-x85j/GHSA-vc8r-j6fr-x85j.json new file mode 100644 index 00000000000..df7c45c143f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vc8r-j6fr-x85j/GHSA-vc8r-j6fr-x85j.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vc8r-j6fr-x85j", + "modified": "2025-02-24T06:31:07Z", + "published": "2025-02-24T06:31:07Z", + "aliases": [ + "CVE-2025-1629" + ], + "details": "A vulnerability was found in Excitel Broadband Private my Excitel App 3.13.0 on Android. It has been classified as problematic. Affected is an unknown function of the component One-Time Password Handler. The manipulation leads to improper restriction of excessive authentication attempts. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1629" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.296610" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.296610" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.501868" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T05:15:11Z" + } +} \ No newline at end of file