"-Synchronized-Data."

This commit is contained in:
CVE Team 2025-06-01 09:00:33 +00:00
parent 61eb67e52d
commit 16c6190c85
No known key found for this signature in database
GPG Key ID: BC5FD8F2443B23B7

View File

@ -1,17 +1,118 @@
{
"data_version": "4.0",
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2025-5400",
"ASSIGNER": "cve@mitre.org",
"STATE": "RESERVED"
"ASSIGNER": "cna@vuldb.com",
"STATE": "PUBLIC"
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value": "A vulnerability was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. It has been classified as critical. Affected is an unknown function of the file /user.php of the component GET Parameter Handler. The manipulation of the argument u_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way."
},
{
"lang": "deu",
"value": "Es wurde eine kritische Schwachstelle in chaitak-gorai Blogbook bis 92f5cf90f8a7e6566b576fe0952e14e1c6736513 ausgemacht. Es betrifft eine unbekannte Funktion der Datei /user.php der Komponente GET Parameter Handler. Dank Manipulation des Arguments u_id mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk erfolgen. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung. Dieses Produkt verzichtet auf eine Versionierung und verwendet stattdessen Rolling Releases. Deshalb sind keine Details zu betroffenen oder zu aktualisierende Versionen vorhanden."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "SQL Injection",
"cweId": "CWE-89"
}
]
},
{
"description": [
{
"lang": "eng",
"value": "Injection",
"cweId": "CWE-74"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "chaitak-gorai",
"product": {
"product_data": [
{
"product_name": "Blogbook",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "92f5cf90f8a7e6566b576fe0952e14e1c6736513"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://vuldb.com/?id.310740",
"refsource": "MISC",
"name": "https://vuldb.com/?id.310740"
},
{
"url": "https://vuldb.com/?ctiid.310740",
"refsource": "MISC",
"name": "https://vuldb.com/?ctiid.310740"
},
{
"url": "https://vuldb.com/?submit.582865",
"refsource": "MISC",
"name": "https://vuldb.com/?submit.582865"
},
{
"url": "https://github.com/rllvusgnzm98/Report/blob/main/blogbook/BlogBook%20user.php%20u_id%20Parameter%20SQL%20Injection.md",
"refsource": "MISC",
"name": "https://github.com/rllvusgnzm98/Report/blob/main/blogbook/BlogBook%20user.php%20u_id%20Parameter%20SQL%20Injection.md"
}
]
},
"credits": [
{
"lang": "en",
"value": "bpy9ft (VulDB User)"
}
],
"impact": {
"cvss": [
{
"version": "3.1",
"baseScore": 7.3,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"baseSeverity": "HIGH"
},
{
"version": "3.0",
"baseScore": 7.3,
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"baseSeverity": "HIGH"
},
{
"version": "2.0",
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
}
]
}