Skip to content

Add finder credit for GHSA-xg84-4r3q-gjjw - #9446

Open
JunZ-Leo wants to merge 1 commit into
github:JunZ-Leo/advisory-improvement-9446from
JunZ-Leo:patch-1
Open

JunZ-Leo wants to merge 1 commit into
github:JunZ-Leo/advisory-improvement-9446from
JunZ-Leo:patch-1

Conversation

@JunZ-Leo

Copy link
Copy Markdown

Summary

Add missing researcher attribution for CVE-2025-4028 / GHSA-xg84-4r3q-gjjw:

  • Add an OSV FINDER credit for Junz_Leo, linked to GitHub account @JunZ-Leo.
  • Add a short acknowledgment to the description.
  • Add the published CNA CVE record as supporting evidence.

Attribution evidence

I am @JunZ-Leo, the researcher who discovered and reported this vulnerability.

  1. My original report was published on April 16, 2025, under my GitHub account. It identifies the submitter as Junz_Leo and documents my discovery:
    Phpgurukul COVID19 Testing Management System V1.0 /profile.php SQL injection JunZ-Leo/CVE#1
  2. The published CNA CVE record explicitly credits Junz_Leo (VulDB User) with the reporter role and references that same GitHub report:
    https://github.com/CVEProject/cvelistV5/blob/main/cves/2025/4xxx/CVE-2025-4028.json
  3. The existing GitHub advisory already references my report but has no associated credits:
    GHSA-xg84-4r3q-gjjw

Please associate the appropriate formal Finder/Reporter advisory credit with @JunZ-Leo, in addition to the textual acknowledgment. If the OSV credit in this PR does not establish a GitHub account-linked advisory credit, please advise which additional workflow is required.

Scope

Only attribution and its supporting reference are changed. The original technical description is preserved verbatim before the new Credits section. Existing CVSS vectors, severity, affected-product data, CWEs, identifiers, and timestamps are unchanged.

I used a direct advisory-file PR because the improvement form requires an ecosystem for this unreviewed advisory and rejects its pre-existing CVSS v4 vector. This avoids inventing package metadata or changing the vulnerability assessment.

Link Junz_Leo to the original GitHub report and published CNA attribution. Preserve existing vulnerability metadata.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 62df763f-a005-42a2-aa77-16beff6667c6
Copilot AI balanced review requested due to automatic review settings September 11, 2026 09:30
@github-actions
github-actions Bot changed the base branch from main to JunZ-Leo/advisory-improvement-9446 September 11, 2026 09:35

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The attribution matches the cited report and CNA record and uses the valid OSV credit structure.

Pull request overview

Adds verified researcher attribution for CVE-2025-4028.

Changes:

  • Adds textual and structured FINDER credit for Junz_Leo.
  • Adds the CNA CVE record as supporting evidence.
File summaries
File Description
advisories/unreviewed/2025/04/GHSA-xg84-4r3q-gjjw/GHSA-xg84-4r3q-gjjw.json Adds supported finder attribution and references.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants