"-Synchronized-Data."

This commit is contained in:
CVE Team 2025-02-24 12:00:31 +00:00
parent 9d06b2ba9a
commit 74cb481d33
No known key found for this signature in database
GPG Key ID: BC5FD8F2443B23B7
4 changed files with 140 additions and 6 deletions

View File

@ -85,6 +85,11 @@
"url": "https://github.com/google/gvisor/commit/83f75082e5b03fafca9201d9d9939028f712b0b2",
"refsource": "MISC",
"name": "https://github.com/google/gvisor/commit/83f75082e5b03fafca9201d9d9939028f712b0b2"
},
{
"url": "https://www.ndss-symposium.org/wp-content/uploads/2025-122-paper.pdf",
"refsource": "MISC",
"name": "https://www.ndss-symposium.org/wp-content/uploads/2025-122-paper.pdf"
}
]
},
@ -93,5 +98,19 @@
},
"source": {
"discovery": "UNKNOWN"
}
},
"credits": [
{
"lang": "en",
"value": "Amit Klein (Hebrew University of Jerusalem)"
},
{
"lang": "en",
"value": "Inon Kaplan (Independent researcher)"
},
{
"lang": "en",
"value": "Ron Even (Independent researcher)"
}
]
}

View File

@ -76,6 +76,11 @@
"url": "https://github.com/google/gvisor/commit/5d2bf2546805afa09a6f6d9b23ec267823e32205",
"refsource": "MISC",
"name": "https://github.com/google/gvisor/commit/5d2bf2546805afa09a6f6d9b23ec267823e32205"
},
{
"url": "https://www.ndss-symposium.org/wp-content/uploads/2025-122-paper.pdf",
"refsource": "MISC",
"name": "https://www.ndss-symposium.org/wp-content/uploads/2025-122-paper.pdf"
}
]
},
@ -84,5 +89,19 @@
},
"source": {
"discovery": "UNKNOWN"
}
},
"credits": [
{
"lang": "en",
"value": "Amit Klein (Hebrew University of Jerusalem)"
},
{
"lang": "en",
"value": "Inon Kaplan (Independent researcher)"
},
{
"lang": "en",
"value": "Ron Even (Independent researcher)"
}
]
}

View File

@ -1,17 +1,95 @@
{
"data_version": "4.0",
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2025-1488",
"ASSIGNER": "cve@mitre.org",
"STATE": "RESERVED"
"ASSIGNER": "security@wordfence.com",
"STATE": "PUBLIC"
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value": "The WPO365 | MICROSOFT 365 GRAPH MAILER plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.2. This is due to insufficient validation on the redirect url supplied via the 'redirect_to' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if 1. they can successfully trick them into performing an action and 2. the plugin is activated but not configured."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-601 URL Redirection to Untrusted Site ('Open Redirect')",
"cweId": "CWE-601"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "wpo365",
"product": {
"product_data": [
{
"product_name": "WPO365 | MICROSOFT 365 GRAPH MAILER",
"version": {
"version_data": [
{
"version_affected": "<=",
"version_name": "*",
"version_value": "3.2"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3a1782c3-ae0b-42f1-aa5e-dabfa2a5bbcd?source=cve",
"refsource": "MISC",
"name": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3a1782c3-ae0b-42f1-aa5e-dabfa2a5bbcd?source=cve"
},
{
"url": "https://wordpress.org/plugins/wpo365-msgraphmailer/#developers",
"refsource": "MISC",
"name": "https://wordpress.org/plugins/wpo365-msgraphmailer/#developers"
},
{
"url": "https://www.wpo365.com/change-log/",
"refsource": "MISC",
"name": "https://www.wpo365.com/change-log/"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3244747/",
"refsource": "MISC",
"name": "https://plugins.trac.wordpress.org/changeset/3244747/"
}
]
},
"credits": [
{
"lang": "en",
"value": "Krzysztof Zaj\u0105c"
}
],
"impact": {
"cvss": [
{
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N",
"baseScore": 4.7,
"baseSeverity": "MEDIUM"
}
]
}

View File

@ -0,0 +1,18 @@
{
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2025-1633",
"ASSIGNER": "cve@mitre.org",
"STATE": "RESERVED"
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
}
]
}
}