diff --git a/advisories/unreviewed/2025/04/GHSA-3gj8-7m6f-hprr/GHSA-3gj8-7m6f-hprr.json b/advisories/unreviewed/2025/04/GHSA-3gj8-7m6f-hprr/GHSA-3gj8-7m6f-hprr.json new file mode 100644 index 00000000000..1029ce19c3b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3gj8-7m6f-hprr/GHSA-3gj8-7m6f-hprr.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gj8-7m6f-hprr", + "modified": "2025-04-06T09:30:25Z", + "published": "2025-04-06T09:30:24Z", + "aliases": [ + "CVE-2025-3312" + ], + "details": "A vulnerability, which was classified as critical, has been found in PHPGurukul Men Salon Management System 1.0. This issue affects some unknown processing of the file /admin/add-customer-services.php. The manipulation of the argument sids[] leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3312" + }, + { + "type": "WEB", + "url": "https://github.com/FIGHTINGTMQ/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303509" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303509" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.550199" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-06T07:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jr5f-8mx2-859f/GHSA-jr5f-8mx2-859f.json b/advisories/unreviewed/2025/04/GHSA-jr5f-8mx2-859f/GHSA-jr5f-8mx2-859f.json new file mode 100644 index 00000000000..fb49ae5508f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jr5f-8mx2-859f/GHSA-jr5f-8mx2-859f.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr5f-8mx2-859f", + "modified": "2025-04-06T09:30:24Z", + "published": "2025-04-06T09:30:24Z", + "aliases": [ + "CVE-2025-3313" + ], + "details": "A vulnerability, which was classified as critical, was found in PHPGurukul Men Salon Management System 1.0. Affected is an unknown function of the file /admin/add-customer.php. The manipulation of the argument Name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3313" + }, + { + "type": "WEB", + "url": "https://github.com/ltranquility/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303510" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303510" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.550884" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-06T08:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p4fv-wj6g-wc78/GHSA-p4fv-wj6g-wc78.json b/advisories/unreviewed/2025/04/GHSA-p4fv-wj6g-wc78/GHSA-p4fv-wj6g-wc78.json new file mode 100644 index 00000000000..4b176b4a84d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p4fv-wj6g-wc78/GHSA-p4fv-wj6g-wc78.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4fv-wj6g-wc78", + "modified": "2025-04-06T09:30:24Z", + "published": "2025-04-06T09:30:24Z", + "aliases": [ + "CVE-2025-3311" + ], + "details": "A vulnerability classified as critical was found in PHPGurukul Men Salon Management System 1.0. This vulnerability affects unknown code of the file /admin/about-us.php. The manipulation of the argument pagetitle leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3311" + }, + { + "type": "WEB", + "url": "https://github.com/FIGHTINGTMQ/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303508" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303508" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.550196" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-06T07:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vc28-9jgm-3qpx/GHSA-vc28-9jgm-3qpx.json b/advisories/unreviewed/2025/04/GHSA-vc28-9jgm-3qpx/GHSA-vc28-9jgm-3qpx.json new file mode 100644 index 00000000000..68ba6d287f2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vc28-9jgm-3qpx/GHSA-vc28-9jgm-3qpx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vc28-9jgm-3qpx", + "modified": "2025-04-06T09:30:24Z", + "published": "2025-04-06T09:30:24Z", + "aliases": [ + "CVE-2025-32370" + ], + "details": "Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is processed through TryZipProviderSafe, there is additional functionality to create files with other extensions. NOTE: this is a separate issue not necessarily related to SVG or XSS.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32370" + }, + { + "type": "WEB", + "url": "https://devnet.kentico.com/download/hotfixes" + }, + { + "type": "WEB", + "url": "https://labs.watchtowr.com/xss-to-rce-by-abusing-custom-file-handlers-kentico-xperience-cms-cve-2025-2748" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-912" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-06T07:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w447-6x96-2x3p/GHSA-w447-6x96-2x3p.json b/advisories/unreviewed/2025/04/GHSA-w447-6x96-2x3p/GHSA-w447-6x96-2x3p.json new file mode 100644 index 00000000000..251b94cf3a2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w447-6x96-2x3p/GHSA-w447-6x96-2x3p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w447-6x96-2x3p", + "modified": "2025-04-06T09:30:24Z", + "published": "2025-04-06T09:30:24Z", + "aliases": [ + "CVE-2025-32369" + ], + "details": "Kentico Xperience before 13.0.181 allows authenticated users to distribute malicious content (for stored XSS) via certain interactions with the media library file upload feature.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32369" + }, + { + "type": "WEB", + "url": "https://devnet.kentico.com/download/hotfixes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-06T06:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wjj3-prjm-f4m2/GHSA-wjj3-prjm-f4m2.json b/advisories/unreviewed/2025/04/GHSA-wjj3-prjm-f4m2/GHSA-wjj3-prjm-f4m2.json new file mode 100644 index 00000000000..06626c3b1ce --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wjj3-prjm-f4m2/GHSA-wjj3-prjm-f4m2.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjj3-prjm-f4m2", + "modified": "2025-04-06T09:30:25Z", + "published": "2025-04-06T09:30:25Z", + "aliases": [ + "CVE-2025-3314" + ], + "details": "A vulnerability has been found in SourceCodester Apartment Visitor Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /forgotpw.php. The manipulation of the argument secode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3314" + }, + { + "type": "WEB", + "url": "https://github.com/tongjt123/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.303511" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.303511" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.551257" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-06T09:15:14Z" + } +} \ No newline at end of file