From f1d80b825a58ee36336ba937afa5bd9d6c81c65b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 9 Jan 2025 06:32:17 +0000 Subject: [PATCH] Publish Advisories GHSA-28xv-h724-wvrh GHSA-2m7v-fvqp-gr2c GHSA-3c89-47f8-w5c6 GHSA-4g2w-8wrj-cvhc GHSA-6w6j-gqmx-fcg6 GHSA-72qg-x4rx-vrx3 GHSA-75jh-69xw-fw3p GHSA-85j8-g7vp-vxr9 GHSA-8p2p-qc6p-2hr2 GHSA-9h84-4pqr-v7jv GHSA-fhj3-h8c5-7cg5 GHSA-h363-2pf8-49mq GHSA-jq5v-29wx-7grq GHSA-mfx6-jvw8-53fm GHSA-q456-9wf9-v4m8 GHSA-v72x-m5mq-mhp2 GHSA-vgr6-rw4j-x24g GHSA-vgvf-f85f-78qf GHSA-vvxp-46w2-6p8r GHSA-w3v9-f5mj-9857 GHSA-wq9h-2f67-7595 --- .../GHSA-28xv-h724-wvrh.json | 29 ++++++++++ .../GHSA-2m7v-fvqp-gr2c.json | 56 +++++++++++++++++++ .../GHSA-3c89-47f8-w5c6.json | 44 +++++++++++++++ .../GHSA-4g2w-8wrj-cvhc.json | 52 +++++++++++++++++ .../GHSA-6w6j-gqmx-fcg6.json | 52 +++++++++++++++++ .../GHSA-72qg-x4rx-vrx3.json | 29 ++++++++++ .../GHSA-75jh-69xw-fw3p.json | 48 ++++++++++++++++ .../GHSA-85j8-g7vp-vxr9.json | 29 ++++++++++ .../GHSA-8p2p-qc6p-2hr2.json | 29 ++++++++++ .../GHSA-9h84-4pqr-v7jv.json | 56 +++++++++++++++++++ .../GHSA-fhj3-h8c5-7cg5.json | 52 +++++++++++++++++ .../GHSA-h363-2pf8-49mq.json | 52 +++++++++++++++++ .../GHSA-jq5v-29wx-7grq.json | 48 ++++++++++++++++ .../GHSA-mfx6-jvw8-53fm.json | 52 +++++++++++++++++ .../GHSA-q456-9wf9-v4m8.json | 52 +++++++++++++++++ .../GHSA-v72x-m5mq-mhp2.json | 56 +++++++++++++++++++ .../GHSA-vgr6-rw4j-x24g.json | 29 ++++++++++ .../GHSA-vgvf-f85f-78qf.json | 29 ++++++++++ .../GHSA-vvxp-46w2-6p8r.json | 40 +++++++++++++ .../GHSA-w3v9-f5mj-9857.json | 56 +++++++++++++++++++ .../GHSA-wq9h-2f67-7595.json | 56 +++++++++++++++++++ 21 files changed, 946 insertions(+) create mode 100644 advisories/unreviewed/2025/01/GHSA-28xv-h724-wvrh/GHSA-28xv-h724-wvrh.json create mode 100644 advisories/unreviewed/2025/01/GHSA-2m7v-fvqp-gr2c/GHSA-2m7v-fvqp-gr2c.json create mode 100644 advisories/unreviewed/2025/01/GHSA-3c89-47f8-w5c6/GHSA-3c89-47f8-w5c6.json create mode 100644 advisories/unreviewed/2025/01/GHSA-4g2w-8wrj-cvhc/GHSA-4g2w-8wrj-cvhc.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6w6j-gqmx-fcg6/GHSA-6w6j-gqmx-fcg6.json create mode 100644 advisories/unreviewed/2025/01/GHSA-72qg-x4rx-vrx3/GHSA-72qg-x4rx-vrx3.json create mode 100644 advisories/unreviewed/2025/01/GHSA-75jh-69xw-fw3p/GHSA-75jh-69xw-fw3p.json create mode 100644 advisories/unreviewed/2025/01/GHSA-85j8-g7vp-vxr9/GHSA-85j8-g7vp-vxr9.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8p2p-qc6p-2hr2/GHSA-8p2p-qc6p-2hr2.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9h84-4pqr-v7jv/GHSA-9h84-4pqr-v7jv.json create mode 100644 advisories/unreviewed/2025/01/GHSA-fhj3-h8c5-7cg5/GHSA-fhj3-h8c5-7cg5.json create mode 100644 advisories/unreviewed/2025/01/GHSA-h363-2pf8-49mq/GHSA-h363-2pf8-49mq.json create mode 100644 advisories/unreviewed/2025/01/GHSA-jq5v-29wx-7grq/GHSA-jq5v-29wx-7grq.json create mode 100644 advisories/unreviewed/2025/01/GHSA-mfx6-jvw8-53fm/GHSA-mfx6-jvw8-53fm.json create mode 100644 advisories/unreviewed/2025/01/GHSA-q456-9wf9-v4m8/GHSA-q456-9wf9-v4m8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-v72x-m5mq-mhp2/GHSA-v72x-m5mq-mhp2.json create mode 100644 advisories/unreviewed/2025/01/GHSA-vgr6-rw4j-x24g/GHSA-vgr6-rw4j-x24g.json create mode 100644 advisories/unreviewed/2025/01/GHSA-vgvf-f85f-78qf/GHSA-vgvf-f85f-78qf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-vvxp-46w2-6p8r/GHSA-vvxp-46w2-6p8r.json create mode 100644 advisories/unreviewed/2025/01/GHSA-w3v9-f5mj-9857/GHSA-w3v9-f5mj-9857.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wq9h-2f67-7595/GHSA-wq9h-2f67-7595.json diff --git a/advisories/unreviewed/2025/01/GHSA-28xv-h724-wvrh/GHSA-28xv-h724-wvrh.json b/advisories/unreviewed/2025/01/GHSA-28xv-h724-wvrh/GHSA-28xv-h724-wvrh.json new file mode 100644 index 00000000000..c6d870d98de --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-28xv-h724-wvrh/GHSA-28xv-h724-wvrh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28xv-h724-wvrh", + "modified": "2025-01-09T06:30:24Z", + "published": "2025-01-09T06:30:24Z", + "aliases": [ + "CVE-2024-12714" + ], + "details": "The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12714" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/f7fb2aef-16ce-4ae7-927c-2ffbc45fbda5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T06:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2m7v-fvqp-gr2c/GHSA-2m7v-fvqp-gr2c.json b/advisories/unreviewed/2025/01/GHSA-2m7v-fvqp-gr2c/GHSA-2m7v-fvqp-gr2c.json new file mode 100644 index 00000000000..2c103342600 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2m7v-fvqp-gr2c/GHSA-2m7v-fvqp-gr2c.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2m7v-fvqp-gr2c", + "modified": "2025-01-09T06:30:23Z", + "published": "2025-01-09T06:30:23Z", + "aliases": [ + "CVE-2024-13210" + ], + "details": "A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical. Affected by this vulnerability is the function uploadPicture of the file src/main/java/org/zdd/bookstore/web/controller/admin/AdminBookController. java. The manipulation of the argument pictureFile leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13210" + }, + { + "type": "WEB", + "url": "https://github.com/donglight/bookstore/issues/10" + }, + { + "type": "WEB", + "url": "https://github.com/donglight/bookstore/issues/10#issue-2760923048" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290815" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290815" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.469686" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T04:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3c89-47f8-w5c6/GHSA-3c89-47f8-w5c6.json b/advisories/unreviewed/2025/01/GHSA-3c89-47f8-w5c6/GHSA-3c89-47f8-w5c6.json new file mode 100644 index 00000000000..afdb85ea22f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3c89-47f8-w5c6/GHSA-3c89-47f8-w5c6.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c89-47f8-w5c6", + "modified": "2025-01-09T06:30:24Z", + "published": "2025-01-09T06:30:24Z", + "aliases": [ + "CVE-2024-6324" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. It was possible to trigger a DoS by creating cyclic references between epics.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6324" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2553716" + }, + { + "type": "WEB", + "url": "https://about.gitlab.com/releases/2025/01/08/patch-release-gitlab-17-7-1-released/#cyclic-reference-of-epics-leads-resource-exhaustion" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/468914" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-407" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T06:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4g2w-8wrj-cvhc/GHSA-4g2w-8wrj-cvhc.json b/advisories/unreviewed/2025/01/GHSA-4g2w-8wrj-cvhc/GHSA-4g2w-8wrj-cvhc.json new file mode 100644 index 00000000000..d2726019f7c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4g2w-8wrj-cvhc/GHSA-4g2w-8wrj-cvhc.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g2w-8wrj-cvhc", + "modified": "2025-01-09T06:30:24Z", + "published": "2025-01-09T06:30:24Z", + "aliases": [ + "CVE-2025-0334" + ], + "details": "A vulnerability has been found in leiyuxi cy-fast 1.0 and classified as critical. Affected by this vulnerability is the function listData of the file /sys/user/listData. The manipulation of the argument order leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0334" + }, + { + "type": "WEB", + "url": "https://github.com/d3do-23/cvelist/blob/main/cy-fast/sqli2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290821" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290821" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.475302" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T06:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6w6j-gqmx-fcg6/GHSA-6w6j-gqmx-fcg6.json b/advisories/unreviewed/2025/01/GHSA-6w6j-gqmx-fcg6/GHSA-6w6j-gqmx-fcg6.json new file mode 100644 index 00000000000..6c1bef06f51 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6w6j-gqmx-fcg6/GHSA-6w6j-gqmx-fcg6.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w6j-gqmx-fcg6", + "modified": "2025-01-09T06:30:23Z", + "published": "2025-01-09T06:30:23Z", + "aliases": [ + "CVE-2024-13206" + ], + "details": "A vulnerability classified as critical has been found in REVE Antivirus 1.0.0.0 on Linux. This affects an unknown part of the file /usr/local/reveantivirus/tmp/reveinstall. The manipulation leads to incorrect default permissions. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13206" + }, + { + "type": "WEB", + "url": "https://github.com/hawkteam404/RnD_Public/blob/main/reve_av_multiple_vuln.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290799" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290799" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.471160" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T04:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-72qg-x4rx-vrx3/GHSA-72qg-x4rx-vrx3.json b/advisories/unreviewed/2025/01/GHSA-72qg-x4rx-vrx3/GHSA-72qg-x4rx-vrx3.json new file mode 100644 index 00000000000..ac1cc9c6b4c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-72qg-x4rx-vrx3/GHSA-72qg-x4rx-vrx3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72qg-x4rx-vrx3", + "modified": "2025-01-09T06:30:23Z", + "published": "2025-01-09T06:30:23Z", + "aliases": [ + "CVE-2024-10815" + ], + "details": "The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10815" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/309a445a-6261-4bd1-bac0-a78096d0c12b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T06:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-75jh-69xw-fw3p/GHSA-75jh-69xw-fw3p.json b/advisories/unreviewed/2025/01/GHSA-75jh-69xw-fw3p/GHSA-75jh-69xw-fw3p.json new file mode 100644 index 00000000000..9251e92e64a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-75jh-69xw-fw3p/GHSA-75jh-69xw-fw3p.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75jh-69xw-fw3p", + "modified": "2025-01-09T06:30:23Z", + "published": "2025-01-09T06:30:23Z", + "aliases": [ + "CVE-2024-56826" + ], + "details": "A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56826" + }, + { + "type": "WEB", + "url": "https://github.com/uclouvain/openjpeg/issues/1563" + }, + { + "type": "WEB", + "url": "https://github.com/uclouvain/openjpeg/commit/e492644fbded4c820ca55b5e50e598d346e850e8" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-56826" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2335172" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T04:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-85j8-g7vp-vxr9/GHSA-85j8-g7vp-vxr9.json b/advisories/unreviewed/2025/01/GHSA-85j8-g7vp-vxr9/GHSA-85j8-g7vp-vxr9.json new file mode 100644 index 00000000000..9a719bb7bbd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-85j8-g7vp-vxr9/GHSA-85j8-g7vp-vxr9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85j8-g7vp-vxr9", + "modified": "2025-01-09T06:30:24Z", + "published": "2025-01-09T06:30:24Z", + "aliases": [ + "CVE-2024-12717" + ], + "details": "The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12717" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/5564926a-6b1d-43f4-8147-128472f6b93a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T06:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8p2p-qc6p-2hr2/GHSA-8p2p-qc6p-2hr2.json b/advisories/unreviewed/2025/01/GHSA-8p2p-qc6p-2hr2/GHSA-8p2p-qc6p-2hr2.json new file mode 100644 index 00000000000..22787caf6c1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8p2p-qc6p-2hr2/GHSA-8p2p-qc6p-2hr2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p2p-qc6p-2hr2", + "modified": "2025-01-09T06:30:24Z", + "published": "2025-01-09T06:30:24Z", + "aliases": [ + "CVE-2024-12731" + ], + "details": "The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12731" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/e1c3754f-60e0-4a89-b4fc-89056dba3616" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T06:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9h84-4pqr-v7jv/GHSA-9h84-4pqr-v7jv.json b/advisories/unreviewed/2025/01/GHSA-9h84-4pqr-v7jv/GHSA-9h84-4pqr-v7jv.json new file mode 100644 index 00000000000..9e6757473ec --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9h84-4pqr-v7jv/GHSA-9h84-4pqr-v7jv.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h84-4pqr-v7jv", + "modified": "2025-01-09T06:30:23Z", + "published": "2025-01-09T06:30:23Z", + "aliases": [ + "CVE-2024-13211" + ], + "details": "A vulnerability was found in SingMR HouseRent 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file src/main/java/com/house/wym/controller/AdminController.java. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13211" + }, + { + "type": "WEB", + "url": "https://github.com/SingMR/HouseRent/issues/12" + }, + { + "type": "WEB", + "url": "https://github.com/SingMR/HouseRent/issues/12#issue-2762124045" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290816" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290816" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.471427" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T04:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fhj3-h8c5-7cg5/GHSA-fhj3-h8c5-7cg5.json b/advisories/unreviewed/2025/01/GHSA-fhj3-h8c5-7cg5/GHSA-fhj3-h8c5-7cg5.json new file mode 100644 index 00000000000..b5c694ef8d6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fhj3-h8c5-7cg5/GHSA-fhj3-h8c5-7cg5.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhj3-h8c5-7cg5", + "modified": "2025-01-09T06:30:23Z", + "published": "2025-01-09T06:30:23Z", + "aliases": [ + "CVE-2025-0328" + ], + "details": "A vulnerability, which was classified as critical, has been found in KaiYuanTong ECT Platform up to 2.0.0. Affected by this issue is some unknown functionality of the file /public/server/runCode.php of the component HTTP POST Request Handler. The manipulation of the argument code leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0328" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/ASPsoVCrLqKK" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290792" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290792" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.470601" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h363-2pf8-49mq/GHSA-h363-2pf8-49mq.json b/advisories/unreviewed/2025/01/GHSA-h363-2pf8-49mq/GHSA-h363-2pf8-49mq.json new file mode 100644 index 00000000000..1e642b2fa54 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h363-2pf8-49mq/GHSA-h363-2pf8-49mq.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h363-2pf8-49mq", + "modified": "2025-01-09T06:30:23Z", + "published": "2025-01-09T06:30:23Z", + "aliases": [ + "CVE-2025-0331" + ], + "details": "A vulnerability, which was classified as critical, has been found in YunzMall up to 2.4.2. This issue affects the function changePwd of the file /app/platform/controllers/ResetpwdController.php of the component HTTP POST Request Handler. The manipulation of the argument pwd leads to weak password recovery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0331" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/DsijzdQDJSAp" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290819" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290819" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.471663" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-640" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T05:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jq5v-29wx-7grq/GHSA-jq5v-29wx-7grq.json b/advisories/unreviewed/2025/01/GHSA-jq5v-29wx-7grq/GHSA-jq5v-29wx-7grq.json new file mode 100644 index 00000000000..f5fedddc909 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jq5v-29wx-7grq/GHSA-jq5v-29wx-7grq.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq5v-29wx-7grq", + "modified": "2025-01-09T06:30:23Z", + "published": "2025-01-09T06:30:23Z", + "aliases": [ + "CVE-2024-56827" + ], + "details": "A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56827" + }, + { + "type": "WEB", + "url": "https://github.com/uclouvain/openjpeg/issues/1564" + }, + { + "type": "WEB", + "url": "https://github.com/uclouvain/openjpeg/commit/e492644fbded4c820ca55b5e50e598d346e850e8" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-56827" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2335174" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T04:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mfx6-jvw8-53fm/GHSA-mfx6-jvw8-53fm.json b/advisories/unreviewed/2025/01/GHSA-mfx6-jvw8-53fm/GHSA-mfx6-jvw8-53fm.json new file mode 100644 index 00000000000..dbc9c2d1f71 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mfx6-jvw8-53fm/GHSA-mfx6-jvw8-53fm.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfx6-jvw8-53fm", + "modified": "2025-01-09T06:30:23Z", + "published": "2025-01-09T06:30:23Z", + "aliases": [ + "CVE-2024-13209" + ], + "details": "A vulnerability was found in Redaxo CMS 5.18.1. It has been classified as problematic. Affected is an unknown function of the file /index.php?page=structure&category_id=1&article_id=1&clang=1&function=edit_art&artstart=0 of the component Structure Management Page. The manipulation of the argument Article Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13209" + }, + { + "type": "WEB", + "url": "https://geochen.medium.com/redaxo-cms-5-18-1-cross-site-scripting-7c9a872c72f6" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290814" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290814" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.466396" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T04:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q456-9wf9-v4m8/GHSA-q456-9wf9-v4m8.json b/advisories/unreviewed/2025/01/GHSA-q456-9wf9-v4m8/GHSA-q456-9wf9-v4m8.json new file mode 100644 index 00000000000..48b111ef12a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q456-9wf9-v4m8/GHSA-q456-9wf9-v4m8.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q456-9wf9-v4m8", + "modified": "2025-01-09T06:30:23Z", + "published": "2025-01-09T06:30:23Z", + "aliases": [ + "CVE-2025-0333" + ], + "details": "A vulnerability, which was classified as critical, was found in leiyuxi cy-fast 1.0. Affected is the function listData of the file /sys/role/listData. The manipulation of the argument order leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0333" + }, + { + "type": "WEB", + "url": "https://github.com/d3do-23/cvelist/blob/main/cy-fast/sqli1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290820" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290820" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.475297" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T05:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v72x-m5mq-mhp2/GHSA-v72x-m5mq-mhp2.json b/advisories/unreviewed/2025/01/GHSA-v72x-m5mq-mhp2/GHSA-v72x-m5mq-mhp2.json new file mode 100644 index 00000000000..15ce843308f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v72x-m5mq-mhp2/GHSA-v72x-m5mq-mhp2.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v72x-m5mq-mhp2", + "modified": "2025-01-09T06:30:23Z", + "published": "2025-01-09T06:30:23Z", + "aliases": [ + "CVE-2024-13213" + ], + "details": "A vulnerability classified as problematic was found in SingMR HouseRent 1.0. This vulnerability affects unknown code of the file /toAdminUpdateHousePage?hID=30. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13213" + }, + { + "type": "WEB", + "url": "https://github.com/SingMR/HouseRent/issues/15" + }, + { + "type": "WEB", + "url": "https://github.com/SingMR/HouseRent/issues/15#issue-2762127702" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290818" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290818" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.471444" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T04:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vgr6-rw4j-x24g/GHSA-vgr6-rw4j-x24g.json b/advisories/unreviewed/2025/01/GHSA-vgr6-rw4j-x24g/GHSA-vgr6-rw4j-x24g.json new file mode 100644 index 00000000000..9f5b5d83af1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vgr6-rw4j-x24g/GHSA-vgr6-rw4j-x24g.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgr6-rw4j-x24g", + "modified": "2025-01-09T06:30:24Z", + "published": "2025-01-09T06:30:24Z", + "aliases": [ + "CVE-2024-12736" + ], + "details": "The BU Section Editing WordPress plugin through 0.9.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12736" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d3c6a4c1-8358-4f8b-b58d-3f712052668f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T06:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vgvf-f85f-78qf/GHSA-vgvf-f85f-78qf.json b/advisories/unreviewed/2025/01/GHSA-vgvf-f85f-78qf/GHSA-vgvf-f85f-78qf.json new file mode 100644 index 00000000000..0df511aae9b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vgvf-f85f-78qf/GHSA-vgvf-f85f-78qf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgvf-f85f-78qf", + "modified": "2025-01-09T06:30:24Z", + "published": "2025-01-09T06:30:23Z", + "aliases": [ + "CVE-2024-12715" + ], + "details": "The Asgard Security Scanner WordPress plugin through 0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12715" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/e1456295-75ba-4dc2-9b1a-dc16a2000db2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T06:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vvxp-46w2-6p8r/GHSA-vvxp-46w2-6p8r.json b/advisories/unreviewed/2025/01/GHSA-vvxp-46w2-6p8r/GHSA-vvxp-46w2-6p8r.json new file mode 100644 index 00000000000..8cec29bde65 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vvxp-46w2-6p8r/GHSA-vvxp-46w2-6p8r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvxp-46w2-6p8r", + "modified": "2025-01-09T06:30:23Z", + "published": "2025-01-09T06:30:23Z", + "aliases": [ + "CVE-2025-0306" + ], + "details": "A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vulnerable service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0306" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-0306" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2336100" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-385" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T04:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w3v9-f5mj-9857/GHSA-w3v9-f5mj-9857.json b/advisories/unreviewed/2025/01/GHSA-w3v9-f5mj-9857/GHSA-w3v9-f5mj-9857.json new file mode 100644 index 00000000000..be359114824 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w3v9-f5mj-9857/GHSA-w3v9-f5mj-9857.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3v9-f5mj-9857", + "modified": "2025-01-09T06:30:24Z", + "published": "2025-01-09T06:30:24Z", + "aliases": [ + "CVE-2025-0335" + ], + "details": "A vulnerability was found in code-projects Online Bike Rental System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the component Change Image Handler. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other endpoints might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0335" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/Huandtx/cve/blob/main/cve/Online%20Bike%20Rental%20System/File_upload1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290822" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290822" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.475365" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T06:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wq9h-2f67-7595/GHSA-wq9h-2f67-7595.json b/advisories/unreviewed/2025/01/GHSA-wq9h-2f67-7595/GHSA-wq9h-2f67-7595.json new file mode 100644 index 00000000000..6afc38aa4fe --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wq9h-2f67-7595/GHSA-wq9h-2f67-7595.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq9h-2f67-7595", + "modified": "2025-01-09T06:30:23Z", + "published": "2025-01-09T06:30:23Z", + "aliases": [ + "CVE-2024-13212" + ], + "details": "A vulnerability classified as critical has been found in SingMR HouseRent 1.0. This affects the function singleUpload/upload of the file src/main/java/com/house/wym/controller/AddHouseController.java. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13212" + }, + { + "type": "WEB", + "url": "https://github.com/SingMR/HouseRent/issues/13" + }, + { + "type": "WEB", + "url": "https://github.com/SingMR/HouseRent/issues/13#issue-2762125363" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290817" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290817" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.471441" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T04:15:12Z" + } +} \ No newline at end of file