From f0262f3260ae9e67938a649645da5fb9eca273fa Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 13 Mar 2025 09:33:26 +0000 Subject: [PATCH] Publish Advisories GHSA-958j-rf6g-qg28 GHSA-786g-4r53-jp5v GHSA-9j8w-rhj2-qxqp GHSA-hq92-6qrm-cxxj GHSA-m9h9-765x-qwq4 --- .../GHSA-958j-rf6g-qg28.json | 10 ++++- .../GHSA-786g-4r53-jp5v.json | 36 +++++++++++++++++ .../GHSA-9j8w-rhj2-qxqp.json | 40 +++++++++++++++++++ .../GHSA-hq92-6qrm-cxxj.json | 40 +++++++++++++++++++ .../GHSA-m9h9-765x-qwq4.json | 40 +++++++++++++++++++ 5 files changed, 165 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-786g-4r53-jp5v/GHSA-786g-4r53-jp5v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9j8w-rhj2-qxqp/GHSA-9j8w-rhj2-qxqp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hq92-6qrm-cxxj/GHSA-hq92-6qrm-cxxj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m9h9-765x-qwq4/GHSA-m9h9-765x-qwq4.json diff --git a/advisories/unreviewed/2025/02/GHSA-958j-rf6g-qg28/GHSA-958j-rf6g-qg28.json b/advisories/unreviewed/2025/02/GHSA-958j-rf6g-qg28/GHSA-958j-rf6g-qg28.json index d08eac9ab41..06d65e08913 100644 --- a/advisories/unreviewed/2025/02/GHSA-958j-rf6g-qg28/GHSA-958j-rf6g-qg28.json +++ b/advisories/unreviewed/2025/02/GHSA-958j-rf6g-qg28/GHSA-958j-rf6g-qg28.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-958j-rf6g-qg28", - "modified": "2025-02-16T18:30:27Z", + "modified": "2025-03-13T09:31:46Z", "published": "2025-02-16T18:30:27Z", "aliases": [ "CVE-2025-1354" @@ -38,6 +38,14 @@ { "type": "WEB", "url": "https://www.asus.com" + }, + { + "type": "WEB", + "url": "https://www.asus.com/supportonly/rt-n10e/helpdesk_bios" + }, + { + "type": "WEB", + "url": "https://www.asus.com/supportonly/rt-n12e/helpdesk_bios" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-786g-4r53-jp5v/GHSA-786g-4r53-jp5v.json b/advisories/unreviewed/2025/03/GHSA-786g-4r53-jp5v/GHSA-786g-4r53-jp5v.json new file mode 100644 index 00000000000..04266bd583b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-786g-4r53-jp5v/GHSA-786g-4r53-jp5v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-786g-4r53-jp5v", + "modified": "2025-03-13T09:31:46Z", + "published": "2025-03-13T09:31:46Z", + "aliases": [ + "CVE-2025-2271" + ], + "details": "A vulnerability exists in Issuetrak v17.2.2 and prior that allows a low-privileged user to access audit results of other users by exploiting an Insecure Direct Object Reference (IDOR) vulnerability in the Issuetrak audit component. The vulnerability enables unauthorized access to sensitive information, including user details, network and hardware information, installed programs, running processes, drives, and printers. Due to improper access controls, an attacker can retrieve audit data belonging to other users, potentially leading to unauthorized data exposure, privacy violations, and security risks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2271" + }, + { + "type": "WEB", + "url": "https://helpcenter.issuetrak.com/home/2340-issuetrak-release-notes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-13T07:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9j8w-rhj2-qxqp/GHSA-9j8w-rhj2-qxqp.json b/advisories/unreviewed/2025/03/GHSA-9j8w-rhj2-qxqp/GHSA-9j8w-rhj2-qxqp.json new file mode 100644 index 00000000000..3f31c6d2ece --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9j8w-rhj2-qxqp/GHSA-9j8w-rhj2-qxqp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9j8w-rhj2-qxqp", + "modified": "2025-03-13T09:31:46Z", + "published": "2025-03-13T09:31:46Z", + "aliases": [ + "CVE-2025-25175" + ], + "details": "A vulnerability has been identified in Simcenter Femap V2401 (All versions < V2401.0003), Simcenter Femap V2406 (All versions < V2406.0002). The affected application contains a memory corruption vulnerability while parsing specially crafted .NEU files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-25443)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25175" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-920092.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-13T09:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hq92-6qrm-cxxj/GHSA-hq92-6qrm-cxxj.json b/advisories/unreviewed/2025/03/GHSA-hq92-6qrm-cxxj/GHSA-hq92-6qrm-cxxj.json new file mode 100644 index 00000000000..799d2354b4d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hq92-6qrm-cxxj/GHSA-hq92-6qrm-cxxj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hq92-6qrm-cxxj", + "modified": "2025-03-13T09:31:46Z", + "published": "2025-03-13T09:31:46Z", + "aliases": [ + "CVE-2025-1119" + ], + "details": "The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.8.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1119" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3250719/simply-schedule-appointments/trunk/booking-app-new/page-appointment-edit.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1be557db-daa8-4d86-819a-462f29da884b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-13T07:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m9h9-765x-qwq4/GHSA-m9h9-765x-qwq4.json b/advisories/unreviewed/2025/03/GHSA-m9h9-765x-qwq4/GHSA-m9h9-765x-qwq4.json new file mode 100644 index 00000000000..60d7db0c4ae --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m9h9-765x-qwq4/GHSA-m9h9-765x-qwq4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9h9-765x-qwq4", + "modified": "2025-03-13T09:31:46Z", + "published": "2025-03-13T09:31:46Z", + "aliases": [ + "CVE-2025-1785" + ], + "details": "The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' action. This makes it possible for authenticated attackers, with Author-level access and above, to overwrite select file types outside of the originally intended directory, which may cause a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1785" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3252990%40download-manager&new=3252990%40download-manager&sfp_email=&sfph_mail=#file4" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bc5c7974-4c10-4880-8823-2accee3c0da4?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-13T08:15:10Z" + } +} \ No newline at end of file