From 00e028f5a03bdf5575a7b319ae1f9a3f51ba4240 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 9 Dec 2024 06:32:23 +0000 Subject: [PATCH] Publish Advisories GHSA-7w2c-w47h-789w GHSA-2f87-f3xg-gj6p GHSA-2mjf-6957-c593 GHSA-2v3j-xqf9-rv5m GHSA-73xm-gvm5-fvj6 GHSA-8hwf-74p7-79cc GHSA-9crh-2mgm-xrq3 GHSA-gch6-mvxw-6r79 GHSA-hhq4-hjcp-jxv5 GHSA-j2j2-g57m-gq9p GHSA-m7m4-7vv7-53gq GHSA-vp24-qmwf-69f2 GHSA-xw9r-xwcq-fwq5 --- .../GHSA-7w2c-w47h-789w.json | 6 +- .../GHSA-2f87-f3xg-gj6p.json | 36 ++++++++++++ .../GHSA-2mjf-6957-c593.json | 36 ++++++++++++ .../GHSA-2v3j-xqf9-rv5m.json | 29 ++++++++++ .../GHSA-73xm-gvm5-fvj6.json | 36 ++++++++++++ .../GHSA-8hwf-74p7-79cc.json | 36 ++++++++++++ .../GHSA-9crh-2mgm-xrq3.json | 56 +++++++++++++++++++ .../GHSA-gch6-mvxw-6r79.json | 56 +++++++++++++++++++ .../GHSA-hhq4-hjcp-jxv5.json | 36 ++++++++++++ .../GHSA-j2j2-g57m-gq9p.json | 52 +++++++++++++++++ .../GHSA-m7m4-7vv7-53gq.json | 36 ++++++++++++ .../GHSA-vp24-qmwf-69f2.json | 56 +++++++++++++++++++ .../GHSA-xw9r-xwcq-fwq5.json | 36 ++++++++++++ 13 files changed, 506 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/12/GHSA-2f87-f3xg-gj6p/GHSA-2f87-f3xg-gj6p.json create mode 100644 advisories/unreviewed/2024/12/GHSA-2mjf-6957-c593/GHSA-2mjf-6957-c593.json create mode 100644 advisories/unreviewed/2024/12/GHSA-2v3j-xqf9-rv5m/GHSA-2v3j-xqf9-rv5m.json create mode 100644 advisories/unreviewed/2024/12/GHSA-73xm-gvm5-fvj6/GHSA-73xm-gvm5-fvj6.json create mode 100644 advisories/unreviewed/2024/12/GHSA-8hwf-74p7-79cc/GHSA-8hwf-74p7-79cc.json create mode 100644 advisories/unreviewed/2024/12/GHSA-9crh-2mgm-xrq3/GHSA-9crh-2mgm-xrq3.json create mode 100644 advisories/unreviewed/2024/12/GHSA-gch6-mvxw-6r79/GHSA-gch6-mvxw-6r79.json create mode 100644 advisories/unreviewed/2024/12/GHSA-hhq4-hjcp-jxv5/GHSA-hhq4-hjcp-jxv5.json create mode 100644 advisories/unreviewed/2024/12/GHSA-j2j2-g57m-gq9p/GHSA-j2j2-g57m-gq9p.json create mode 100644 advisories/unreviewed/2024/12/GHSA-m7m4-7vv7-53gq/GHSA-m7m4-7vv7-53gq.json create mode 100644 advisories/unreviewed/2024/12/GHSA-vp24-qmwf-69f2/GHSA-vp24-qmwf-69f2.json create mode 100644 advisories/unreviewed/2024/12/GHSA-xw9r-xwcq-fwq5/GHSA-xw9r-xwcq-fwq5.json diff --git a/advisories/github-reviewed/2023/06/GHSA-7w2c-w47h-789w/GHSA-7w2c-w47h-789w.json b/advisories/github-reviewed/2023/06/GHSA-7w2c-w47h-789w/GHSA-7w2c-w47h-789w.json index 0e54858c498..a1f2b3d84b4 100644 --- a/advisories/github-reviewed/2023/06/GHSA-7w2c-w47h-789w/GHSA-7w2c-w47h-789w.json +++ b/advisories/github-reviewed/2023/06/GHSA-7w2c-w47h-789w/GHSA-7w2c-w47h-789w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7w2c-w47h-789w", - "modified": "2023-07-11T20:19:37Z", + "modified": "2024-12-09T06:30:55Z", "published": "2023-06-12T19:50:34Z", "aliases": [ "CVE-2023-34246" @@ -68,6 +68,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/07/msg00016.html" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00010.html" + }, { "type": "WEB", "url": "https://www.rfc-editor.org/rfc/rfc8252#section-8.6" diff --git a/advisories/unreviewed/2024/12/GHSA-2f87-f3xg-gj6p/GHSA-2f87-f3xg-gj6p.json b/advisories/unreviewed/2024/12/GHSA-2f87-f3xg-gj6p/GHSA-2f87-f3xg-gj6p.json new file mode 100644 index 00000000000..2f820b419ea --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2f87-f3xg-gj6p/GHSA-2f87-f3xg-gj6p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f87-f3xg-gj6p", + "modified": "2024-12-09T06:30:55Z", + "published": "2024-12-09T06:30:55Z", + "aliases": [ + "CVE-2024-53281" + ], + "details": "Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Network WOL functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53281" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_09" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T04:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2mjf-6957-c593/GHSA-2mjf-6957-c593.json b/advisories/unreviewed/2024/12/GHSA-2mjf-6957-c593/GHSA-2mjf-6957-c593.json new file mode 100644 index 00000000000..b7eb5f52221 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2mjf-6957-c593/GHSA-2mjf-6957-c593.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mjf-6957-c593", + "modified": "2024-12-09T06:30:56Z", + "published": "2024-12-09T06:30:56Z", + "aliases": [ + "CVE-2024-53283" + ], + "details": "Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Router Port Forward functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53283" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_09" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T04:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-2v3j-xqf9-rv5m/GHSA-2v3j-xqf9-rv5m.json b/advisories/unreviewed/2024/12/GHSA-2v3j-xqf9-rv5m/GHSA-2v3j-xqf9-rv5m.json new file mode 100644 index 00000000000..c0346cc69dc --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-2v3j-xqf9-rv5m/GHSA-2v3j-xqf9-rv5m.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v3j-xqf9-rv5m", + "modified": "2024-12-09T06:30:56Z", + "published": "2024-12-09T06:30:56Z", + "aliases": [ + "CVE-2024-9651" + ], + "details": "The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9651" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/a2c56e42-3b3a-4e23-933f-40cf63e222c0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T06:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-73xm-gvm5-fvj6/GHSA-73xm-gvm5-fvj6.json b/advisories/unreviewed/2024/12/GHSA-73xm-gvm5-fvj6/GHSA-73xm-gvm5-fvj6.json new file mode 100644 index 00000000000..57f722b9466 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-73xm-gvm5-fvj6/GHSA-73xm-gvm5-fvj6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73xm-gvm5-fvj6", + "modified": "2024-12-09T06:30:56Z", + "published": "2024-12-09T06:30:56Z", + "aliases": [ + "CVE-2024-53285" + ], + "details": "Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53285" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_09" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T04:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8hwf-74p7-79cc/GHSA-8hwf-74p7-79cc.json b/advisories/unreviewed/2024/12/GHSA-8hwf-74p7-79cc/GHSA-8hwf-74p7-79cc.json new file mode 100644 index 00000000000..63b3d5f4e6a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8hwf-74p7-79cc/GHSA-8hwf-74p7-79cc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hwf-74p7-79cc", + "modified": "2024-12-09T06:30:55Z", + "published": "2024-12-09T06:30:55Z", + "aliases": [ + "CVE-2024-53282" + ], + "details": "Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect MAC Filter functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53282" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_09" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T04:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9crh-2mgm-xrq3/GHSA-9crh-2mgm-xrq3.json b/advisories/unreviewed/2024/12/GHSA-9crh-2mgm-xrq3/GHSA-9crh-2mgm-xrq3.json new file mode 100644 index 00000000000..7da7a1525b8 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9crh-2mgm-xrq3/GHSA-9crh-2mgm-xrq3.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9crh-2mgm-xrq3", + "modified": "2024-12-09T06:30:56Z", + "published": "2024-12-09T06:30:56Z", + "aliases": [ + "CVE-2024-12359" + ], + "details": "A vulnerability was found in code-projects Admin Dashboard 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /vendor_management.php. The manipulation of the argument username leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting product names.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12359" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://hackmd.io/@salt9487/HyTgLR-V1l" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287278" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287278" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.458634" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-gch6-mvxw-6r79/GHSA-gch6-mvxw-6r79.json b/advisories/unreviewed/2024/12/GHSA-gch6-mvxw-6r79/GHSA-gch6-mvxw-6r79.json new file mode 100644 index 00000000000..2c4dc14ca67 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-gch6-mvxw-6r79/GHSA-gch6-mvxw-6r79.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gch6-mvxw-6r79", + "modified": "2024-12-09T06:30:56Z", + "published": "2024-12-09T06:30:56Z", + "aliases": [ + "CVE-2024-12357" + ], + "details": "A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument page leads to file inclusion. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12357" + }, + { + "type": "WEB", + "url": "https://pastebin.com/Qupf8YbH" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287276" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287276" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.457505" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T05:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hhq4-hjcp-jxv5/GHSA-hhq4-hjcp-jxv5.json b/advisories/unreviewed/2024/12/GHSA-hhq4-hjcp-jxv5/GHSA-hhq4-hjcp-jxv5.json new file mode 100644 index 00000000000..c2e10dbe275 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hhq4-hjcp-jxv5/GHSA-hhq4-hjcp-jxv5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhq4-hjcp-jxv5", + "modified": "2024-12-09T06:30:55Z", + "published": "2024-12-09T06:30:55Z", + "aliases": [ + "CVE-2024-53280" + ], + "details": "Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in network center policy route functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53280" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_09" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T04:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j2j2-g57m-gq9p/GHSA-j2j2-g57m-gq9p.json b/advisories/unreviewed/2024/12/GHSA-j2j2-g57m-gq9p/GHSA-j2j2-g57m-gq9p.json new file mode 100644 index 00000000000..6e95e76a3bf --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j2j2-g57m-gq9p/GHSA-j2j2-g57m-gq9p.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2j2-g57m-gq9p", + "modified": "2024-12-09T06:30:56Z", + "published": "2024-12-09T06:30:56Z", + "aliases": [ + "CVE-2024-12358" + ], + "details": "A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown part of the file /api/job/add/. The manipulation of the argument glueSource leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12358" + }, + { + "type": "WEB", + "url": "https://github.com/jxp98/VulResearch/blob/main/2024/12/1.Datax-Web%20-%20Remote%20Code%20Execution.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287277" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287277" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.457865" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m7m4-7vv7-53gq/GHSA-m7m4-7vv7-53gq.json b/advisories/unreviewed/2024/12/GHSA-m7m4-7vv7-53gq/GHSA-m7m4-7vv7-53gq.json new file mode 100644 index 00000000000..77b962e9736 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m7m4-7vv7-53gq/GHSA-m7m4-7vv7-53gq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7m4-7vv7-53gq", + "modified": "2024-12-09T06:30:56Z", + "published": "2024-12-09T06:30:56Z", + "aliases": [ + "CVE-2024-53284" + ], + "details": "Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53284" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_09" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T04:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vp24-qmwf-69f2/GHSA-vp24-qmwf-69f2.json b/advisories/unreviewed/2024/12/GHSA-vp24-qmwf-69f2/GHSA-vp24-qmwf-69f2.json new file mode 100644 index 00000000000..d447cb0afe7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vp24-qmwf-69f2/GHSA-vp24-qmwf-69f2.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp24-qmwf-69f2", + "modified": "2024-12-09T06:30:56Z", + "published": "2024-12-09T06:30:56Z", + "aliases": [ + "CVE-2024-12360" + ], + "details": "A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as critical. This issue affects some unknown processing of the file class_update.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12360" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/bjtyyy/CVE/blob/main/Online%20Class%20and%20Exam%20Scheduling%20System.docx" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.287279" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.287279" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.458891" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-xw9r-xwcq-fwq5/GHSA-xw9r-xwcq-fwq5.json b/advisories/unreviewed/2024/12/GHSA-xw9r-xwcq-fwq5/GHSA-xw9r-xwcq-fwq5.json new file mode 100644 index 00000000000..05d6f1bceca --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-xw9r-xwcq-fwq5/GHSA-xw9r-xwcq-fwq5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw9r-xwcq-fwq5", + "modified": "2024-12-09T06:30:55Z", + "published": "2024-12-09T06:30:55Z", + "aliases": [ + "CVE-2024-53279" + ], + "details": "Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in file station functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53279" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_24_09" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-09T04:15:04Z" + } +} \ No newline at end of file