CVE-2025-0300
published 2025-01-07CVE-2025-0300: A vulnerability classified as critical was found in code-projects Online Book Shop 1.0. Affected by this vulnerability is an unknown functionality of the file…
PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.53%
41.5th percentile
A vulnerability classified as critical was found in code-projects Online Book Shop 1.0. Affected by this vulnerability is an unknown functionality of the file /subcat.php. The manipulation of the argument cat leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| code-projects | online_book_shop | — | — |
| fabian | online_book_shop | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f74m-5p64-49qj: A vulnerability classified as critical was found in code-projects Online Book Shop 1
ghsa_unreviewed·2025-01-07
CVE-2025-0300 [MEDIUM] CWE-74 GHSA-f74m-5p64-49qj: A vulnerability classified as critical was found in code-projects Online Book Shop 1
A vulnerability classified as critical was found in code-projects Online Book Shop 1.0. Affected by this vulnerability is an unknown functionality of the file /subcat.php. The manipulation of the argument cat leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Red Hat
kernel: powerpc64/ftrace: fix clobbered r15 during livepatching
vendor_redhat·2025-07-04·CVSS 7.8
CVE-2025-38233 [HIGH] kernel: powerpc64/ftrace: fix clobbered r15 during livepatching
kernel: powerpc64/ftrace: fix clobbered r15 during livepatching
In the Linux kernel, the following vulnerability has been resolved:
powerpc64/ftrace: fix clobbered r15 during livepatching
While r15 is clobbered always with PPC_FTRACE_OUT_OF_LINE, it is
not restored in livepatch sequence leading to not so obvious fails
like below:
BUG: Unable to handle kernel data access on write at 0xc0000000000f9078
Faulting instruction address: 0xc0000000018ff958
Oops: Kernel access of bad area, sig: 11 [#1]
...
NIP: c0000000018ff958 LR: c0000000018ff930 CTR: c0000000009c0790
REGS: c00000005f2e7790 TRAP: 0300 Tainted: G K (6.14.0+)
MSR: 8000000000009033 CR: 2822880b XER: 20040000
CFAR: c0000000008addc0 DAR: c0000000000f9078 DSISR: 0a000000 IRQMASK: 1
GPR00: c0000000018f2584 c00000005f2e7a30 c00000000280
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-38233 kernel: powerpc64/ftrace: fix clobbered r15 during livepatching
bugzilla·2025-07-04·CVSS 7.8
CVE-2025-38233 [HIGH] CVE-2025-38233 kernel: powerpc64/ftrace: fix clobbered r15 during livepatching
CVE-2025-38233 kernel: powerpc64/ftrace: fix clobbered r15 during livepatching
In the Linux kernel, the following vulnerability has been resolved:
powerpc64/ftrace: fix clobbered r15 during livepatching
While r15 is clobbered always with PPC_FTRACE_OUT_OF_LINE, it is
not restored in livepatch sequence leading to not so obvious fails
like below:
BUG: Unable to handle kernel data access on write at 0xc0000000000f9078
Faulting instruction address: 0xc0000000018ff958
Oops: Kernel access of bad area, sig: 11 [#1]
...
NIP: c0000000018ff958 LR: c0000000018ff930 CTR: c0000000009c0790
REGS: c00000005f2e7790 TRAP: 0300 Tainted: G K (6.14.0+)
MSR: 8000000000009033 CR: 2822880b XER: 20040000
CFAR: c0000000008addc0 DAR: c0000000000f9078 DSISR: 0a000000 IRQMASK: 1
GPR00: c0000000018f2584 c00000005f2
Bugzilla
CVE-2024-11734 org.keycloak:keycloak-quarkus-server: Denial of Service in Keycloak Server via Security Headers
bugzilla·2024-11-26·CVSS 6.5
CVE-2024-11734 [MEDIUM] CVE-2024-11734 org.keycloak:keycloak-quarkus-server: Denial of Service in Keycloak Server via Security Headers
CVE-2024-11734 org.keycloak:keycloak-quarkus-server: Denial of Service in Keycloak Server via Security Headers
A potential Denial of Service (DoS) vulnerability has been identified in Keycloak, which could allow an administrative user with the rights to change realm settings to disrupt the service. This is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that is already terminated, leading to a failure of said request.
Service disruption may happen, users will be unable to access applications relying on
Keycloak, or any of the consoles provided by Keycloak itself on the affected realm.
Discussion:
This issue has been addressed in the following products:
RHBK 26.0.8
Via RHSA-2025:0300 https://access.redhat.com
Bugzilla
CVE-2024-11736 org.keycloak:keycloak-quarkus-server: Unrestricted admin use of system and environment variables
bugzilla·2024-11-26·CVSS 4.9
CVE-2024-11736 [MEDIUM] CVE-2024-11736 org.keycloak:keycloak-quarkus-server: Unrestricted admin use of system and environment variables
CVE-2024-11736 org.keycloak:keycloak-quarkus-server: Unrestricted admin use of system and environment variables
A security vulnerability has been identified that allows admin users to access sensitive server environment variables and system properties through user-configurable URLs. Specifically, when configuring backchannel logout URLs or admin URLs, admin users can include placeholders like ${env.VARNAME} or ${PROPNAME}. The server replaces these placeholders with the actual values of environment variables or system properties during URL processing.
Discussion:
This issue has been addressed in the following products:
RHBK 26.0.8
Via RHSA-2025:0300 https://access.redhat.com/errata/RHSA-2025:0300
---
This issue has been addressed in the following products:
Red Hat build of Keycloak
2025-01-07
Published