diff --git a/advisories/unreviewed/2025/04/GHSA-5h88-xc4r-2q76/GHSA-5h88-xc4r-2q76.json b/advisories/unreviewed/2025/04/GHSA-5h88-xc4r-2q76/GHSA-5h88-xc4r-2q76.json new file mode 100644 index 00000000000..5af364b95fc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5h88-xc4r-2q76/GHSA-5h88-xc4r-2q76.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h88-xc4r-2q76", + "modified": "2025-04-10T06:30:24Z", + "published": "2025-04-10T06:30:24Z", + "aliases": [ + "CVE-2025-0539" + ], + "details": "In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allowing a suitably positioned attacker to compromise the account running Octopus Server and potentially the host infrastructure itself.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0539" + }, + { + "type": "WEB", + "url": "https://advisories.octopus.com/post/2025/sa2025-06" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T06:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f3qc-cx62-rrww/GHSA-f3qc-cx62-rrww.json b/advisories/unreviewed/2025/04/GHSA-f3qc-cx62-rrww/GHSA-f3qc-cx62-rrww.json new file mode 100644 index 00000000000..df8e06a237f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f3qc-cx62-rrww/GHSA-f3qc-cx62-rrww.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3qc-cx62-rrww", + "modified": "2025-04-10T06:30:23Z", + "published": "2025-04-10T06:30:23Z", + "aliases": [ + "CVE-2025-3489" + ], + "details": "A vulnerability was found in Nababur Simple-User-Management-System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /register.php. The manipulation of the argument name/username leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3489" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.304298" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.304298" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.545504" + }, + { + "type": "WEB", + "url": "https://www.websecurityinsights.my.id/2025/03/simple-user-management-system-v-10-name.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T04:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rp6h-6758-g8ch/GHSA-rp6h-6758-g8ch.json b/advisories/unreviewed/2025/04/GHSA-rp6h-6758-g8ch/GHSA-rp6h-6758-g8ch.json new file mode 100644 index 00000000000..db934c35904 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rp6h-6758-g8ch/GHSA-rp6h-6758-g8ch.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rp6h-6758-g8ch", + "modified": "2025-04-10T06:30:23Z", + "published": "2025-04-10T06:30:23Z", + "aliases": [ + "CVE-2025-3102" + ], + "details": "The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78. This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3102" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/suretriggers/trunk/src/Controllers/RestController.php#L59" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3266499%40suretriggers%2Ftrunk&old=3264905%40suretriggers%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ec017311-f150-4a14-a4b4-b5634f574e2b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-697" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T05:15:38Z" + } +} \ No newline at end of file