Skip to content

Commit 1594750

Browse files

File tree

advisories/unreviewed/2024/07/GHSA-cfxc-ch9m-pr95/GHSA-cfxc-ch9m-pr95.json

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,16 +1,20 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-cfxc-ch9m-pr95",
4-
"modified": "2024-07-09T03:31:44Z",
4+
"modified": "2026-07-30T00:31:17Z",
55
"published": "2024-07-09T03:31:44Z",
66
"aliases": [
77
"CVE-2024-4944"
88
],
9-
"details": "A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged.\n",
9+
"details": "A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged.",
1010
"severity": [
1111
{
1212
"type": "CVSS_V3",
1313
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
1418
}
1519
],
1620
"affected": [],
@@ -19,6 +23,10 @@
1923
"type": "ADVISORY",
2024
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4944"
2125
},
26+
{
27+
"type": "WEB",
28+
"url": "https://psirt.watchguard.com/CVE-2024-4944"
29+
},
2230
{
2331
"type": "WEB",
2432
"url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00010"
Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-47xc-xmwq-4cxw",
4+
"modified": "2026-07-30T00:31:18Z",
5+
"published": "2026-07-30T00:31:18Z",
6+
"aliases": [
7+
"CVE-2026-16339"
8+
],
9+
"details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16339"
16+
}
17+
],
18+
"database_specific": {
19+
"cwe_ids": [],
20+
"severity": null,
21+
"github_reviewed": false,
22+
"github_reviewed_at": null,
23+
"nvd_published_at": "2026-07-29T23:16:29Z"
24+
}
25+
}
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-4p7v-v4v3-f9cp",
4+
"modified": "2026-07-30T00:31:18Z",
5+
"published": "2026-07-30T00:31:18Z",
6+
"aliases": [
7+
"CVE-2025-67405"
8+
],
9+
"details": "Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-67405"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/automated/20250811-casap-automated-enrollment-system-update_password.php-new_password-sqli/20250811-casap-automated-enrollment-system-update_password.php-new_password-sqli.md"
20+
}
21+
],
22+
"database_specific": {
23+
"cwe_ids": [],
24+
"severity": null,
25+
"github_reviewed": false,
26+
"github_reviewed_at": null,
27+
"nvd_published_at": "2026-07-29T22:16:51Z"
28+
}
29+
}
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-4xg3-6338-9rxr",
4+
"modified": "2026-07-30T00:31:18Z",
5+
"published": "2026-07-30T00:31:18Z",
6+
"aliases": [
7+
"CVE-2025-67403"
8+
],
9+
"details": "Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-67403"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/automated/20250811-casap-automated-enrollment-system-update_class.php-class_name-sqli/20250811-casap-automated-enrollment-system-update_class.php-class_name-sqli.md"
20+
}
21+
],
22+
"database_specific": {
23+
"cwe_ids": [],
24+
"severity": null,
25+
"github_reviewed": false,
26+
"github_reviewed_at": null,
27+
"nvd_published_at": "2026-07-29T22:16:51Z"
28+
}
29+
}
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-786x-w3wg-jwf8",
4+
"modified": "2026-07-30T00:31:18Z",
5+
"published": "2026-07-30T00:31:18Z",
6+
"aliases": [
7+
"CVE-2025-67407"
8+
],
9+
"details": "Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-67407"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/automated/20250811-casap-automated-enrollment-system-update_student.php-fname-sqli/20250811-casap-automated-enrollment-system-update_student.php-fname-sqli.md"
20+
}
21+
],
22+
"database_specific": {
23+
"cwe_ids": [],
24+
"severity": null,
25+
"github_reviewed": false,
26+
"github_reviewed_at": null,
27+
"nvd_published_at": "2026-07-29T22:16:51Z"
28+
}
29+
}
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-8933-qpw2-wm45",
4+
"modified": "2026-07-30T00:31:18Z",
5+
"published": "2026-07-30T00:31:18Z",
6+
"aliases": [
7+
"CVE-2025-67406"
8+
],
9+
"details": "https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). The component is: control/activate_case.php,?id=1. The attack vector is: A SQL Injection vulnerability exists in the activate_case.php in parameter id endpoint of Advocate office management system. Unsanitized user input in the specified parameter is interpolated directly into an SQL query, allowing attackers to infer or extract data and, in some cases, execute stacked/time-based payloads. ¶¶ Affected Component & Parameter Affected Endpoint URL: http://localhost/advocate/kortex_lite/control/activate_case.php?id=1 HTTP Method: GET Vulnerable File: activate_case.php Parameter: id Vector Location: GET Injection Techniques (as identified by sqlmap) Type: error-based Title: MySQL >= 5.1 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (EXTRACTVALUE) Payload: id=1 AND EXTRACTVALUE(6268,CONCAT(0x5c,0x71766b6a71,(SELECT (ELT(6268=6268,1))),0x716a7a6b71)) Type: time-based blind Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP) Payload: id=1 AND (SELECT 4464 FROM (SELECT(SLEEP(5)))aHqo) Proof of Concept (Burp Repeater)",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-67406"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/advocate/20250811-advocate-office-management-system-activate_case.php-id-sqli/20250811-advocate-office-management-system-activate_case.php-id-sqli.md"
20+
}
21+
],
22+
"database_specific": {
23+
"cwe_ids": [],
24+
"severity": null,
25+
"github_reviewed": false,
26+
"github_reviewed_at": null,
27+
"nvd_published_at": "2026-07-29T22:16:51Z"
28+
}
29+
}
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-9r9x-mp6x-7vh3",
4+
"modified": "2026-07-30T00:31:18Z",
5+
"published": "2026-07-30T00:31:18Z",
6+
"aliases": [
7+
"CVE-2025-69945"
8+
],
9+
"details": "kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-69945"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/hospitalmanagementsystemproject/20250811-hospital-management-system-edit-patient.php-editid-sqli/20250811-hospital-management-system-edit-patient.php-editid-sqli.md"
20+
}
21+
],
22+
"database_specific": {
23+
"cwe_ids": [],
24+
"severity": null,
25+
"github_reviewed": false,
26+
"github_reviewed_at": null,
27+
"nvd_published_at": "2026-07-29T22:16:52Z"
28+
}
29+
}
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-fjfr-wjrh-qmv2",
4+
"modified": "2026-07-30T00:31:18Z",
5+
"published": "2026-07-30T00:31:18Z",
6+
"aliases": [
7+
"CVE-2025-67408"
8+
],
9+
"details": "Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-67408"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/automated/20250811-casap-automated-enrollment-system-save_user.php-status-sqli/20250811-casap-automated-enrollment-system-save_user.php-status-sqli.md"
20+
}
21+
],
22+
"database_specific": {
23+
"cwe_ids": [],
24+
"severity": null,
25+
"github_reviewed": false,
26+
"github_reviewed_at": null,
27+
"nvd_published_at": "2026-07-29T22:16:51Z"
28+
}
29+
}
Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-fv9j-hvjm-h9xh",
4+
"modified": "2026-07-30T00:31:18Z",
5+
"published": "2026-07-30T00:31:18Z",
6+
"aliases": [
7+
"CVE-2025-69949"
8+
],
9+
"details": "kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-69949"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/hospitalmanagementsystemproject/20250811-hospital-management-system-check_availability.php-email-sqli/20250811-hospital-management-system-check_availability.php-email-sqli.md"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/hospitalmanagementsystemproject/20250811-hospital-management-system-check_availability.php-emailid-sqli/20250811-hospital-management-system-check_availability.php-emailid-sqli.md"
24+
}
25+
],
26+
"database_specific": {
27+
"cwe_ids": [],
28+
"severity": null,
29+
"github_reviewed": false,
30+
"github_reviewed_at": null,
31+
"nvd_published_at": "2026-07-29T22:16:52Z"
32+
}
33+
}
Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-ghxv-gf56-x785",
4+
"modified": "2026-07-30T00:31:18Z",
5+
"published": "2026-07-30T00:31:18Z",
6+
"aliases": [
7+
"CVE-2025-69943"
8+
],
9+
"details": "kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.",
10+
"severity": [],
11+
"affected": [],
12+
"references": [
13+
{
14+
"type": "ADVISORY",
15+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-69943"
16+
},
17+
{
18+
"type": "WEB",
19+
"url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/hospitalmanagementsystemproject/20250811-hospital-management-system-get_doctor.php-doctor-sqli/20250811-hospital-management-system-get_doctor.php-doctor-sqli.md"
20+
},
21+
{
22+
"type": "WEB",
23+
"url": "https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/hospitalmanagementsystemproject/20250811-hospital-management-system-get_doctor.php-specilizationid-sqli/20250811-hospital-management-system-get_doctor.php-specilizationid-sqli.md"
24+
}
25+
],
26+
"database_specific": {
27+
"cwe_ids": [],
28+
"severity": null,
29+
"github_reviewed": false,
30+
"github_reviewed_at": null,
31+
"nvd_published_at": "2026-07-29T22:16:51Z"
32+
}
33+
}

0 commit comments

Comments
 (0)