Auto-Update: 2025-04-09T06:00:20.402681+00:00

This commit is contained in:
cad-safe-bot 2025-04-09 06:03:58 +00:00
parent 4694a2c254
commit 16170ac027
3 changed files with 74 additions and 12 deletions

View File

@ -0,0 +1,64 @@
{
"id": "CVE-2025-3100",
"sourceIdentifier": "security@wordfence.com",
"published": "2025-04-09T05:15:43.253",
"lastModified": "2025-04-09T05:15:43.253",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The WP Project Manager \u2013 Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping in tasks discussion. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions granted by an Administrator, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security@wordfence.com",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.1,
"impactScore": 2.7
}
]
},
"weaknesses": [
{
"source": "security@wordfence.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"references": [
{
"url": "https://plugins.trac.wordpress.org/browser/wedevs-project-manager/trunk/src/File/Helper/File.php#L56",
"source": "security@wordfence.com"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3268509/wedevs-project-manager/trunk/bootstrap/loaders.php",
"source": "security@wordfence.com"
},
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4d62b087-b0ca-4fa8-921b-5eeb3fa76596?source=cve",
"source": "security@wordfence.com"
}
]
}

View File

@ -13,13 +13,13 @@ Repository synchronizes with the NVD every 2 hours.
### Last Repository Update
```plain
2025-04-09T04:00:20.081154+00:00
2025-04-09T06:00:20.402681+00:00
```
### Most recent CVE Modification Timestamp synchronized with NVD
```plain
2025-04-09T03:15:16.847000+00:00
2025-04-09T05:15:43.253000+00:00
```
### Last Data Feed Release
@ -33,17 +33,14 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/
### Total Number of included CVEs
```plain
289258
289259
```
### CVEs added in the last Commit
Recently added CVEs: `4`
Recently added CVEs: `1`
- [CVE-2025-29988](CVE-2025/CVE-2025-299xx/CVE-2025-29988.json) (`2025-04-09T03:15:15.737`)
- [CVE-2025-32460](CVE-2025/CVE-2025-324xx/CVE-2025-32460.json) (`2025-04-09T02:15:15.137`)
- [CVE-2025-32461](CVE-2025/CVE-2025-324xx/CVE-2025-32461.json) (`2025-04-09T02:15:16.253`)
- [CVE-2025-32464](CVE-2025/CVE-2025-324xx/CVE-2025-32464.json) (`2025-04-09T03:15:16.847`)
- [CVE-2025-3100](CVE-2025/CVE-2025-31xx/CVE-2025-3100.json) (`2025-04-09T05:15:43.253`)
### CVEs modified in the last Commit

View File

@ -287782,7 +287782,7 @@ CVE-2025-29982,0,0,23affa7daecc4825576e77403823b6557774b9426b2d4d0f7cba7e9e66506
CVE-2025-29985,0,0,2aeb5a8f8ec35aa18845c0d4af21956a36a7c943d3b098b90b6c6bf8f695e5ce,2025-04-08T18:13:53.347000
CVE-2025-29986,0,0,99c178153f6bbbad7e209292a65a7c4e43cf8706f8ea6bc3168202624c16c250,2025-04-08T18:13:53.347000
CVE-2025-29987,0,0,962644397d15823d289c2ad8de7be5eae2dfe8787c0957eaa9f9d8409e9ed1a4,2025-04-07T14:18:34.453000
CVE-2025-29988,1,1,55bacafb376b01dc4d16039d43fd7743ecd0a2c985d6dd6d151ce353f48232bd,2025-04-09T03:15:15.737000
CVE-2025-29988,0,0,55bacafb376b01dc4d16039d43fd7743ecd0a2c985d6dd6d151ce353f48232bd,2025-04-09T03:15:15.737000
CVE-2025-2999,0,0,81444588dd7906e6c8cac51c6c8e57e7e231b44db369bc45695ecb3a2d560ed4,2025-04-01T20:26:22.890000
CVE-2025-29991,0,0,40bf08e0cf4babdcbf62be0cd1c52dbd14323391ac7d7ab9cf689de3abb126a1,2025-04-07T14:18:34.453000
CVE-2025-29993,0,0,5a3aa3d216416e2fe2b892d0a3793dacda985a3191a3f3e25b8b0846fab45986,2025-03-27T16:45:27.850000
@ -288332,6 +288332,7 @@ CVE-2025-30971,0,0,92b14f174c92599de02a891c3fcb3bebb1869a41eef00ab5d9b6626db1c99
CVE-2025-3098,0,0,ce95a008105100dc05dac96d60492ad8c2a1a9010656c6a251be6a7755736abb,2025-04-02T14:58:07.527000
CVE-2025-30987,0,0,1ddeca9f293b13339e82c187149d285418438fc60231797e7c68c5fcad6fe64b,2025-04-01T20:26:30.593000
CVE-2025-3099,0,0,9e53ac247011e5c9d18381ea42caceb1c07bbbabd16a29680a8aab5d54621675,2025-04-02T14:58:07.527000
CVE-2025-3100,1,1,b54d4c37e8adb05fbf9af87aa5f70a2392a159113dc9f8c80daee2c68af64123,2025-04-09T05:15:43.253000
CVE-2025-31001,0,0,4265bbb6e115d79eef571dbbe3c6c20ebe4772d8a6b0bb96964817d20c125ddf,2025-04-01T20:26:11.547000
CVE-2025-31010,0,0,2eedda8f330a9beae819a4cd9d50315b7c3705aef34f39a70e86c91cbd492554,2025-03-28T18:11:40.180000
CVE-2025-31016,0,0,9f9353b55280d52026be79b202ae8bc2b442e0024607fdee2a6c539bec9857cb,2025-04-01T20:26:30.593000
@ -289122,9 +289123,9 @@ CVE-2025-3242,0,0,7a3796558c3172b29f1754f0aa43f7d570abcefa6f88716250c661d5fd24e2
CVE-2025-3243,0,0,b05341f12b748941f8ca2dc4c2b8a53c07658570f17c96676f3c5904a6066c66,2025-04-07T14:18:15.560000
CVE-2025-3244,0,0,a20bb1d848a28a44d0b8d510e43cbe068220041e655dcf96cf8633b9bc977caf,2025-04-07T14:18:15.560000
CVE-2025-3245,0,0,396ea3bbe154112d349f915c8c28a6610578699cecf486191d9d012a69d9c5b9,2025-04-07T14:18:15.560000
CVE-2025-32460,1,1,c21410b5e6e36877989fe1b65ff9455675dc9eddeeaf1356945ec843be766230,2025-04-09T02:15:15.137000
CVE-2025-32461,1,1,777383737583a36a93f808b62fdcd270b508ef3c699e07ca333b0a9cbd41b015,2025-04-09T02:15:16.253000
CVE-2025-32464,1,1,4a2efd97c1d0568588269f1b8e568d51d9c1e6fe9587f46f6410a701df9deda8,2025-04-09T03:15:16.847000
CVE-2025-32460,0,0,c21410b5e6e36877989fe1b65ff9455675dc9eddeeaf1356945ec843be766230,2025-04-09T02:15:15.137000
CVE-2025-32461,0,0,777383737583a36a93f808b62fdcd270b508ef3c699e07ca333b0a9cbd41b015,2025-04-09T02:15:16.253000
CVE-2025-32464,0,0,4a2efd97c1d0568588269f1b8e568d51d9c1e6fe9587f46f6410a701df9deda8,2025-04-09T03:15:16.847000
CVE-2025-3248,0,0,4c1d83c706cdfdbb3cf09231feeb35ab401e2dab4e1a5c8dcf5ba4fbd153922a,2025-04-08T18:14:17.307000
CVE-2025-3249,0,0,733737203692403dc364c9398a90d84cb34e7925fec94f7c4725b719e6f271e1,2025-04-07T14:18:15.560000
CVE-2025-3250,0,0,86c9421f263345a046bec996216d445d7aebcf0cefe445ca2d4279fffb4f74bd,2025-04-07T14:18:15.560000

Can't render this file because it is too large.