From d9b0404da55fa2a044d15cae4aa067e96952b15d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 10 Apr 2025 06:31:59 +0000 Subject: [PATCH] Publish Advisories GHSA-5h88-xc4r-2q76 GHSA-f3qc-cx62-rrww GHSA-rp6h-6758-g8ch --- .../GHSA-5h88-xc4r-2q76.json | 34 ++++++++++++ .../GHSA-f3qc-cx62-rrww.json | 52 +++++++++++++++++++ .../GHSA-rp6h-6758-g8ch.json | 44 ++++++++++++++++ 3 files changed, 130 insertions(+) create mode 100644 advisories/unreviewed/2025/04/GHSA-5h88-xc4r-2q76/GHSA-5h88-xc4r-2q76.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f3qc-cx62-rrww/GHSA-f3qc-cx62-rrww.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rp6h-6758-g8ch/GHSA-rp6h-6758-g8ch.json diff --git a/advisories/unreviewed/2025/04/GHSA-5h88-xc4r-2q76/GHSA-5h88-xc4r-2q76.json b/advisories/unreviewed/2025/04/GHSA-5h88-xc4r-2q76/GHSA-5h88-xc4r-2q76.json new file mode 100644 index 00000000000..5af364b95fc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5h88-xc4r-2q76/GHSA-5h88-xc4r-2q76.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5h88-xc4r-2q76", + "modified": "2025-04-10T06:30:24Z", + "published": "2025-04-10T06:30:24Z", + "aliases": [ + "CVE-2025-0539" + ], + "details": "In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allowing a suitably positioned attacker to compromise the account running Octopus Server and potentially the host infrastructure itself.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0539" + }, + { + "type": "WEB", + "url": "https://advisories.octopus.com/post/2025/sa2025-06" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T06:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f3qc-cx62-rrww/GHSA-f3qc-cx62-rrww.json b/advisories/unreviewed/2025/04/GHSA-f3qc-cx62-rrww/GHSA-f3qc-cx62-rrww.json new file mode 100644 index 00000000000..df8e06a237f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f3qc-cx62-rrww/GHSA-f3qc-cx62-rrww.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3qc-cx62-rrww", + "modified": "2025-04-10T06:30:23Z", + "published": "2025-04-10T06:30:23Z", + "aliases": [ + "CVE-2025-3489" + ], + "details": "A vulnerability was found in Nababur Simple-User-Management-System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /register.php. The manipulation of the argument name/username leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3489" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.304298" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.304298" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.545504" + }, + { + "type": "WEB", + "url": "https://www.websecurityinsights.my.id/2025/03/simple-user-management-system-v-10-name.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T04:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rp6h-6758-g8ch/GHSA-rp6h-6758-g8ch.json b/advisories/unreviewed/2025/04/GHSA-rp6h-6758-g8ch/GHSA-rp6h-6758-g8ch.json new file mode 100644 index 00000000000..db934c35904 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rp6h-6758-g8ch/GHSA-rp6h-6758-g8ch.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rp6h-6758-g8ch", + "modified": "2025-04-10T06:30:23Z", + "published": "2025-04-10T06:30:23Z", + "aliases": [ + "CVE-2025-3102" + ], + "details": "The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78. This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3102" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/suretriggers/trunk/src/Controllers/RestController.php#L59" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3266499%40suretriggers%2Ftrunk&old=3264905%40suretriggers%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ec017311-f150-4a14-a4b4-b5634f574e2b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-697" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T05:15:38Z" + } +} \ No newline at end of file