Publish Advisories

GHSA-6h7w-j6pv-9qgw
GHSA-6q5v-v3c3-5mrp
GHSA-jpf5-526x-c5hw
GHSA-m4jx-m5hg-qrxx
This commit is contained in:
advisory-database[bot]
2025-05-31 03:32:11 +00:00
parent 5019da3526
commit f0d8892ad6
4 changed files with 161 additions and 1 deletions
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6h7w-j6pv-9qgw",
"modified": "2025-05-31T03:30:33Z",
"published": "2025-05-31T03:30:33Z",
"aliases": [
"CVE-2025-5365"
],
"details": "A vulnerability was found in Campcodes Online Hospital Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/patient-search.php. The manipulation of the argument searchdata leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5365"
},
{
"type": "WEB",
"url": "https://github.com/yuanchaoxxxxx/CVE/issues/1"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.310659"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.310659"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.586700"
},
{
"type": "WEB",
"url": "https://www.campcodes.com"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-31T01:15:20Z"
}
}
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6q5v-v3c3-5mrp",
"modified": "2025-05-31T03:30:33Z",
"published": "2025-05-31T03:30:33Z",
"aliases": [
"CVE-2025-5367"
],
"details": "A vulnerability was found in PHPGurukul Online Shopping Portal Project 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /category.php. The manipulation of the argument Product leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5367"
},
{
"type": "WEB",
"url": "https://github.com/shanranne/myCVE/issues/1"
},
{
"type": "WEB",
"url": "https://phpgurukul.com"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.310660"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.310660"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.586814"
}
],
"database_specific": {
"cwe_ids": [
"CWE-74"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-31T02:15:19Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jpf5-526x-c5hw",
"modified": "2025-05-30T15:30:30Z",
"modified": "2025-05-31T03:30:33Z",
"published": "2025-05-30T15:30:30Z",
"aliases": [
"CVE-2025-40909"
@@ -50,6 +50,10 @@
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/05/23/1"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/05/30/4"
}
],
"database_specific": {
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m4jx-m5hg-qrxx",
"modified": "2025-05-31T03:30:33Z",
"published": "2025-05-31T03:30:33Z",
"aliases": [
"CVE-2018-25111"
],
"details": "django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-25111"
},
{
"type": "WEB",
"url": "https://github.com/django-helpdesk/django-helpdesk/issues/591"
},
{
"type": "WEB",
"url": "https://github.com/django-helpdesk/django-helpdesk/pull/1120"
},
{
"type": "WEB",
"url": "https://github.com/django-helpdesk/django-helpdesk/releases/tag/v1.0.0"
}
],
"database_specific": {
"cwe_ids": [
"CWE-277"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-31T01:15:19Z"
}
}