From 4347cee299cf38e816b227e164e0265963c57bd1 Mon Sep 17 00:00:00 2001 From: CVE Team Date: Sat, 22 Mar 2025 18:00:31 +0000 Subject: [PATCH] "-Synchronized-Data." --- 2025/2xxx/CVE-2025-2622.json | 114 +++++++++++++++++++++++++++++++++-- 2025/2xxx/CVE-2025-2623.json | 109 +++++++++++++++++++++++++++++++-- 2 files changed, 215 insertions(+), 8 deletions(-) diff --git a/2025/2xxx/CVE-2025-2622.json b/2025/2xxx/CVE-2025-2622.json index 73993e24c97..78f33f07e3e 100644 --- a/2025/2xxx/CVE-2025-2622.json +++ b/2025/2xxx/CVE-2025-2622.json @@ -1,17 +1,123 @@ { + "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", - "data_version": "4.0", "CVE_data_meta": { "ID": "CVE-2025-2622", - "ASSIGNER": "cve@mitre.org", - "STATE": "RESERVED" + "ASSIGNER": "cna@vuldb.com", + "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "A vulnerability was found in aizuda snail-job 1.4.0. It has been classified as critical. Affected is the function getRuntime of the file /snail-job/workflow/check-node-expression of the component Workflow-Task Management Module. The manipulation of the argument nodeExpression leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used." + }, + { + "lang": "deu", + "value": "Es wurde eine kritische Schwachstelle in aizuda snail-job 1.4.0 ausgemacht. Betroffen hiervon ist die Funktion getRuntime der Datei /snail-job/workflow/check-node-expression der Komponente Workflow-Task Management Module. Mittels dem Manipulieren des Arguments nodeExpression mit unbekannten Daten kann eine deserialization-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff \u00fcber das Netzwerk. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "Deserialization", + "cweId": "CWE-502" + } + ] + }, + { + "description": [ + { + "lang": "eng", + "value": "Improper Input Validation", + "cweId": "CWE-20" + } + ] + } + ] + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "vendor_name": "aizuda", + "product": { + "product_data": [ + { + "product_name": "snail-job", + "version": { + "version_data": [ + { + "version_affected": "=", + "version_value": "1.4.0" + } + ] + } + } + ] + } + } + ] + } + }, + "references": { + "reference_data": [ + { + "url": "https://vuldb.com/?id.300624", + "refsource": "MISC", + "name": "https://vuldb.com/?id.300624" + }, + { + "url": "https://vuldb.com/?ctiid.300624", + "refsource": "MISC", + "name": "https://vuldb.com/?ctiid.300624" + }, + { + "url": "https://vuldb.com/?submit.518999", + "refsource": "MISC", + "name": "https://vuldb.com/?submit.518999" + }, + { + "url": "https://gitee.com/aizuda/snail-job/issues/IBSQ24", + "refsource": "MISC", + "name": "https://gitee.com/aizuda/snail-job/issues/IBSQ24" + }, + { + "url": "https://gitee.com/aizuda/snail-job/issues/IBSQ24#note_38500450_link", + "refsource": "MISC", + "name": "https://gitee.com/aizuda/snail-job/issues/IBSQ24#note_38500450_link" + } + ] + }, + "credits": [ + { + "lang": "en", + "value": "startr4ck (VulDB User)" + } + ], + "impact": { + "cvss": [ + { + "version": "3.1", + "baseScore": 6.3, + "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", + "baseSeverity": "MEDIUM" + }, + { + "version": "3.0", + "baseScore": 6.3, + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", + "baseSeverity": "MEDIUM" + }, + { + "version": "2.0", + "baseScore": 6.5, + "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P" } ] } diff --git a/2025/2xxx/CVE-2025-2623.json b/2025/2xxx/CVE-2025-2623.json index fc92ec4abde..183a493081b 100644 --- a/2025/2xxx/CVE-2025-2623.json +++ b/2025/2xxx/CVE-2025-2623.json @@ -1,17 +1,118 @@ { + "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", - "data_version": "4.0", "CVE_data_meta": { "ID": "CVE-2025-2623", - "ASSIGNER": "cve@mitre.org", - "STATE": "RESERVED" + "ASSIGNER": "cna@vuldb.com", + "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "A vulnerability was found in westboy CicadasCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /system/cms/content/save. The manipulation of the argument title/content/laiyuan leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used." + }, + { + "lang": "deu", + "value": "In westboy CicadasCMS 1.0 wurde eine problematische Schwachstelle ausgemacht. Es geht um eine nicht n\u00e4her bekannte Funktion der Datei /system/cms/content/save. Mittels Manipulieren des Arguments title/content/laiyuan mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk erfolgen. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "Cross Site Scripting", + "cweId": "CWE-79" + } + ] + }, + { + "description": [ + { + "lang": "eng", + "value": "Code Injection", + "cweId": "CWE-94" + } + ] + } + ] + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "vendor_name": "westboy", + "product": { + "product_data": [ + { + "product_name": "CicadasCMS", + "version": { + "version_data": [ + { + "version_affected": "=", + "version_value": "1.0" + } + ] + } + } + ] + } + } + ] + } + }, + "references": { + "reference_data": [ + { + "url": "https://vuldb.com/?id.300625", + "refsource": "MISC", + "name": "https://vuldb.com/?id.300625" + }, + { + "url": "https://vuldb.com/?ctiid.300625", + "refsource": "MISC", + "name": "https://vuldb.com/?ctiid.300625" + }, + { + "url": "https://vuldb.com/?submit.519294", + "refsource": "MISC", + "name": "https://vuldb.com/?submit.519294" + }, + { + "url": "https://github.com/IceFoxH/VULN/issues/10", + "refsource": "MISC", + "name": "https://github.com/IceFoxH/VULN/issues/10" + } + ] + }, + "credits": [ + { + "lang": "en", + "value": "icefoxh (VulDB User)" + } + ], + "impact": { + "cvss": [ + { + "version": "3.1", + "baseScore": 3.5, + "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N", + "baseSeverity": "LOW" + }, + { + "version": "3.0", + "baseScore": 3.5, + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N", + "baseSeverity": "LOW" + }, + { + "version": "2.0", + "baseScore": 4, + "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N" } ] }