diff --git a/advisories/unreviewed/2025/01/GHSA-f2qp-wp2r-vcg2/GHSA-f2qp-wp2r-vcg2.json b/advisories/unreviewed/2025/01/GHSA-f2qp-wp2r-vcg2/GHSA-f2qp-wp2r-vcg2.json new file mode 100644 index 00000000000..7296bf268e0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f2qp-wp2r-vcg2/GHSA-f2qp-wp2r-vcg2.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2qp-wp2r-vcg2", + "modified": "2025-01-02T09:30:39Z", + "published": "2025-01-02T09:30:39Z", + "aliases": [ + "CVE-2024-13093" + ], + "details": "A vulnerability, which was classified as critical, has been found in code-projects Job Recruitment 1.0. This issue affects some unknown processing of the file /_parse/_call_main_search_ajax.php of the component Seeker Profile Handler. The manipulation of the argument s1 leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13093" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/UnrealdDei/cve/blob/main/sql10.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289901" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289901" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.472442" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T09:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h3wj-59pf-9xf2/GHSA-h3wj-59pf-9xf2.json b/advisories/unreviewed/2025/01/GHSA-h3wj-59pf-9xf2/GHSA-h3wj-59pf-9xf2.json new file mode 100644 index 00000000000..d78a9ca83b7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h3wj-59pf-9xf2/GHSA-h3wj-59pf-9xf2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3wj-59pf-9xf2", + "modified": "2025-01-02T09:30:38Z", + "published": "2025-01-02T09:30:38Z", + "aliases": [ + "CVE-2024-12912" + ], + "details": "An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution.\nRefer to the '01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12912" + }, + { + "type": "WEB", + "url": "https://www.asus.com/content/asus-product-security-advisory" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T09:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wj84-6vm5-wxqw/GHSA-wj84-6vm5-wxqw.json b/advisories/unreviewed/2025/01/GHSA-wj84-6vm5-wxqw/GHSA-wj84-6vm5-wxqw.json new file mode 100644 index 00000000000..8dbd171f89e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wj84-6vm5-wxqw/GHSA-wj84-6vm5-wxqw.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj84-6vm5-wxqw", + "modified": "2025-01-02T09:30:38Z", + "published": "2025-01-02T09:30:38Z", + "aliases": [ + "CVE-2024-13092" + ], + "details": "A vulnerability classified as critical was found in code-projects Job Recruitment 1.0. This vulnerability affects unknown code of the file /_parse/_call_job/search_ajax.php of the component Job Post Handler. The manipulation of the argument n leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13092" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/UnrealdDei/cve/blob/main/sql9.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289900" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289900" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.472441" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T09:15:17Z" + } +} \ No newline at end of file