Publish Advisories

GHSA-3v74-7fxr-9p4j
GHSA-456f-p7fp-957g
GHSA-6285-g4cj-gv36
GHSA-69rc-cf64-54v3
GHSA-9vwh-vqcj-qvf3
GHSA-c4wh-v84h-4q8g
GHSA-f29p-fvxc-743q
GHSA-v7rw-f6q6-rhwq
GHSA-xqr2-347w-52hc
This commit is contained in:
advisory-database[bot]
2025-05-23 12:32:59 +00:00
parent 154f376306
commit e23db49608
9 changed files with 396 additions and 0 deletions
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3v74-7fxr-9p4j",
"modified": "2025-05-23T12:31:22Z",
"published": "2025-05-23T12:31:22Z",
"aliases": [
"CVE-2025-5106"
],
"details": "A vulnerability was found in Fujian Kelixun 1.0. It has been classified as critical. This affects an unknown part of the file /app/fax/fax_view.php of the component Filename Handler. The manipulation of the argument fax_file leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5106"
},
{
"type": "WEB",
"url": "https://github.com/byxs0x0/SQL/issues/2"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.310083"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.310083"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.569404"
}
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T12:15:19Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-456f-p7fp-957g",
"modified": "2025-05-23T12:31:21Z",
"published": "2025-05-23T12:31:21Z",
"aliases": [
"CVE-2025-36527"
],
"details": "Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-36527"
},
{
"type": "WEB",
"url": "https://www.manageengine.com/products/active-directory-audit/cve-2025-36527.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T11:15:31Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6285-g4cj-gv36",
"modified": "2025-05-23T12:31:21Z",
"published": "2025-05-23T12:31:21Z",
"aliases": [
"CVE-2025-4379"
],
"details": "DobryCMS in versions 2.* and lower is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in szukaj parameter allows arbitrary JavaScript to be executed on victim's browser when specially crafted URL is opened.\n\nA hotfix for affected versions was released on 29.04.2025. It removes the vulnerability without incrementing the version.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4379"
},
{
"type": "WEB",
"url": "https://cert.pl/en/posts/2025/05/CVE-2025-4379"
},
{
"type": "WEB",
"url": "https://cert.pl/posts/2025/05/CVE-2025-4379"
},
{
"type": "WEB",
"url": "https://studiofabryka.pl/Systemy_CMS.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T10:15:20Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-69rc-cf64-54v3",
"modified": "2025-05-23T12:31:22Z",
"published": "2025-05-23T12:31:22Z",
"aliases": [
"CVE-2025-5105"
],
"details": "A vulnerability was found in TOZED ZLT W51 up to 1.4.2 and classified as critical. Affected by this issue is some unknown functionality of the component Service Port 7777. The manipulation leads to improper clearing of heap memory before release. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5105"
},
{
"type": "WEB",
"url": "https://github.com/Zephkek/LeakyTozed"
},
{
"type": "WEB",
"url": "https://github.com/Zephkek/LeakyTozed#41-proof-of-concept"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.310082"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.310082"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.568495"
}
],
"database_specific": {
"cwe_ids": [
"CWE-244"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T12:15:19Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9vwh-vqcj-qvf3",
"modified": "2025-05-23T12:31:21Z",
"published": "2025-05-23T12:31:21Z",
"aliases": [
"CVE-2025-3893"
],
"details": "While editing pages managed by MegaBIP a user with high privileges is prompted to give a reasoning for performing this action. Input provided by the the user is not sanitized, leading to SQL Injection vulnerability. \nVersion 5.20 of MegaBIP fixes this issue.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3893"
},
{
"type": "WEB",
"url": "https://cert.pl/en/posts/2025/05/CVE-2025-3893"
},
{
"type": "WEB",
"url": "https://megabip.pl/index.php?id=24,145"
},
{
"type": "WEB",
"url": "https://www.gov.pl/web/cyfryzacja/rekomendacja-pelnomocnika-rzadu-ds-cyberbezpieczenstwa-dotyczaca-biuletynow-informacji-publicznej"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T11:15:32Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c4wh-v84h-4q8g",
"modified": "2025-05-23T12:31:21Z",
"published": "2025-05-23T12:31:21Z",
"aliases": [
"CVE-2025-41407"
],
"details": "Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41407"
},
{
"type": "WEB",
"url": "https://www.manageengine.com/products/active-directory-audit/cve-2025-41407.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T11:15:33Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f29p-fvxc-743q",
"modified": "2025-05-23T12:31:21Z",
"published": "2025-05-23T12:31:21Z",
"aliases": [
"CVE-2025-3895"
],
"details": "Token used for resetting passwords in MegaBIP software are generated using a small space of random values combined with a queryable value.\n It allows an unauthenticated attacker who know user login names to brute force these tokens and change account passwords (including these belonging to administrators). \nVersion 5.20 of MegaBIP fixes this issue.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3895"
},
{
"type": "WEB",
"url": "https://cert.pl/en/posts/2025/05/CVE-2025-3893"
},
{
"type": "WEB",
"url": "https://megabip.pl/index.php?id=24,145"
},
{
"type": "WEB",
"url": "https://www.gov.pl/web/cyfryzacja/rekomendacja-pelnomocnika-rzadu-ds-cyberbezpieczenstwa-dotyczaca-biuletynow-informacji-publicznej"
}
],
"database_specific": {
"cwe_ids": [
"CWE-334"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T11:15:32Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v7rw-f6q6-rhwq",
"modified": "2025-05-23T12:31:21Z",
"published": "2025-05-23T12:31:21Z",
"aliases": [
"CVE-2024-13945"
],
"details": "Stored Absolute Path Traversal vulnerabilities in ASPECT could expose sensitive data \nif administrator credentials become compromised.\n\nThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13945"
},
{
"type": "WEB",
"url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021&LanguageCode=en&DocumentPartId=pdf&Action=Launch"
}
],
"database_specific": {
"cwe_ids": [
"CWE-36"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T10:15:19Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xqr2-347w-52hc",
"modified": "2025-05-23T12:31:21Z",
"published": "2025-05-23T12:31:21Z",
"aliases": [
"CVE-2025-3894"
],
"details": "Text editor embedded into MegaBIP software does not neutralize user input allowing Stored XSS attacks on other users. In order to use the editor high privileges are required.  \nVersion 5.20 of MegaBIP fixes this issue.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3894"
},
{
"type": "WEB",
"url": "https://cert.pl/en/posts/2025/05/CVE-2025-3893"
},
{
"type": "WEB",
"url": "https://megabip.pl/index.php?id=24,145"
},
{
"type": "WEB",
"url": "https://www.gov.pl/web/cyfryzacja/rekomendacja-pelnomocnika-rzadu-ds-cyberbezpieczenstwa-dotyczaca-biuletynow-informacji-publicznej"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-23T11:15:32Z"
}
}