From 16c6190c85e01ed15eb6ea05a52e1fcd4b620260 Mon Sep 17 00:00:00 2001 From: CVE Team Date: Sun, 1 Jun 2025 09:00:33 +0000 Subject: [PATCH] "-Synchronized-Data." --- 2025/5xxx/CVE-2025-5400.json | 109 +++++++++++++++++++++++++++++++++-- 1 file changed, 105 insertions(+), 4 deletions(-) diff --git a/2025/5xxx/CVE-2025-5400.json b/2025/5xxx/CVE-2025-5400.json index 38569c6dbbd..a2dd599d1d2 100644 --- a/2025/5xxx/CVE-2025-5400.json +++ b/2025/5xxx/CVE-2025-5400.json @@ -1,17 +1,118 @@ { + "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", - "data_version": "4.0", "CVE_data_meta": { "ID": "CVE-2025-5400", - "ASSIGNER": "cve@mitre.org", - "STATE": "RESERVED" + "ASSIGNER": "cna@vuldb.com", + "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "A vulnerability was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. It has been classified as critical. Affected is an unknown function of the file /user.php of the component GET Parameter Handler. The manipulation of the argument u_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way." + }, + { + "lang": "deu", + "value": "Es wurde eine kritische Schwachstelle in chaitak-gorai Blogbook bis 92f5cf90f8a7e6566b576fe0952e14e1c6736513 ausgemacht. Es betrifft eine unbekannte Funktion der Datei /user.php der Komponente GET Parameter Handler. Dank Manipulation des Arguments u_id mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk erfolgen. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung. Dieses Produkt verzichtet auf eine Versionierung und verwendet stattdessen Rolling Releases. Deshalb sind keine Details zu betroffenen oder zu aktualisierende Versionen vorhanden." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "SQL Injection", + "cweId": "CWE-89" + } + ] + }, + { + "description": [ + { + "lang": "eng", + "value": "Injection", + "cweId": "CWE-74" + } + ] + } + ] + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "vendor_name": "chaitak-gorai", + "product": { + "product_data": [ + { + "product_name": "Blogbook", + "version": { + "version_data": [ + { + "version_affected": "=", + "version_value": "92f5cf90f8a7e6566b576fe0952e14e1c6736513" + } + ] + } + } + ] + } + } + ] + } + }, + "references": { + "reference_data": [ + { + "url": "https://vuldb.com/?id.310740", + "refsource": "MISC", + "name": "https://vuldb.com/?id.310740" + }, + { + "url": "https://vuldb.com/?ctiid.310740", + "refsource": "MISC", + "name": "https://vuldb.com/?ctiid.310740" + }, + { + "url": "https://vuldb.com/?submit.582865", + "refsource": "MISC", + "name": "https://vuldb.com/?submit.582865" + }, + { + "url": "https://github.com/rllvusgnzm98/Report/blob/main/blogbook/BlogBook%20user.php%20u_id%20Parameter%20SQL%20Injection.md", + "refsource": "MISC", + "name": "https://github.com/rllvusgnzm98/Report/blob/main/blogbook/BlogBook%20user.php%20u_id%20Parameter%20SQL%20Injection.md" + } + ] + }, + "credits": [ + { + "lang": "en", + "value": "bpy9ft (VulDB User)" + } + ], + "impact": { + "cvss": [ + { + "version": "3.1", + "baseScore": 7.3, + "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "baseSeverity": "HIGH" + }, + { + "version": "3.0", + "baseScore": 7.3, + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", + "baseSeverity": "HIGH" + }, + { + "version": "2.0", + "baseScore": 7.5, + "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P" } ] }