From f187a07ab0b538ee34295319a8942430afbf4972 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 10 May 2025 09:32:04 +0000 Subject: [PATCH] Publish GHSA-3j83-vjvj-964q --- .../GHSA-3j83-vjvj-964q.json | 56 +++++++++++++++++++ 1 file changed, 56 insertions(+) create mode 100644 advisories/unreviewed/2025/05/GHSA-3j83-vjvj-964q/GHSA-3j83-vjvj-964q.json diff --git a/advisories/unreviewed/2025/05/GHSA-3j83-vjvj-964q/GHSA-3j83-vjvj-964q.json b/advisories/unreviewed/2025/05/GHSA-3j83-vjvj-964q/GHSA-3j83-vjvj-964q.json new file mode 100644 index 00000000000..01f85db5720 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3j83-vjvj-964q/GHSA-3j83-vjvj-964q.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j83-vjvj-964q", + "modified": "2025-05-10T09:30:30Z", + "published": "2025-05-10T09:30:30Z", + "aliases": [ + "CVE-2025-4497" + ], + "details": "A vulnerability was found in code-projects Simple Banking System up to 1.0. It has been rated as critical. This issue affects some unknown processing of the component Sign In. The manipulation of the argument password2 leads to buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4497" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/zzzxc643/cve/blob/main/Banking_System.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.308213" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.308213" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.567082" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-10T07:15:44Z" + } +} \ No newline at end of file