diff --git a/advisories/unreviewed/2024/08/GHSA-36ph-x9fx-5r9w/GHSA-36ph-x9fx-5r9w.json b/advisories/unreviewed/2024/08/GHSA-36ph-x9fx-5r9w/GHSA-36ph-x9fx-5r9w.json new file mode 100644 index 00000000000..995d1cbb4a2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-36ph-x9fx-5r9w/GHSA-36ph-x9fx-5r9w.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36ph-x9fx-5r9w", + "modified": "2024-08-22T12:30:26Z", + "published": "2024-08-22T12:30:26Z", + "aliases": [ + "CVE-2024-7778" + ], + "details": "The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.10.36 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7778" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/themeisle-companion/tags/2.10.36/obfx_modules/custom-fonts/custom_fonts_admin.php#L376" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3139233" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3139233/#file71" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/themeisle-companion/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/be83c6be-fb6c-462f-b54a-ca12d6d2581f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-22T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-455v-j4c3-4fqr/GHSA-455v-j4c3-4fqr.json b/advisories/unreviewed/2024/08/GHSA-455v-j4c3-4fqr/GHSA-455v-j4c3-4fqr.json new file mode 100644 index 00000000000..0deb0a8f3ea --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-455v-j4c3-4fqr/GHSA-455v-j4c3-4fqr.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-455v-j4c3-4fqr", + "modified": "2024-08-22T12:30:26Z", + "published": "2024-08-22T12:30:26Z", + "aliases": [ + "CVE-2024-6870" + ], + "details": "The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping affecting the rl_upload_image AJAX endpoint. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the 3gp2 file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6870" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/responsive-lightbox/tags/2.4.7/includes/class-remote-library.php#L261" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3137531%40responsive-lightbox&new=3137531%40responsive-lightbox&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/responsive-lightbox/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e4d55309-d178-4b3d-9de6-2cf2769b76fe?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-22T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5fq6-69rp-89qc/GHSA-5fq6-69rp-89qc.json b/advisories/unreviewed/2024/08/GHSA-5fq6-69rp-89qc/GHSA-5fq6-69rp-89qc.json new file mode 100644 index 00000000000..e958ad4d219 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5fq6-69rp-89qc/GHSA-5fq6-69rp-89qc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fq6-69rp-89qc", + "modified": "2024-08-22T12:30:27Z", + "published": "2024-08-22T12:30:27Z", + "aliases": [ + "CVE-2024-39746" + ], + "details": "IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39746" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/297313" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7166018" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-311" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-22T11:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6523-746v-mrwg/GHSA-6523-746v-mrwg.json b/advisories/unreviewed/2024/08/GHSA-6523-746v-mrwg/GHSA-6523-746v-mrwg.json new file mode 100644 index 00000000000..32656635d40 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6523-746v-mrwg/GHSA-6523-746v-mrwg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6523-746v-mrwg", + "modified": "2024-08-22T12:30:27Z", + "published": "2024-08-22T12:30:27Z", + "aliases": [ + "CVE-2024-43331" + ], + "details": "Missing Authorization vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.9.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43331" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-sms/wordpress-wp-sms-plugin-6-9-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-22T12:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7c8c-x5xp-8wgj/GHSA-7c8c-x5xp-8wgj.json b/advisories/unreviewed/2024/08/GHSA-7c8c-x5xp-8wgj/GHSA-7c8c-x5xp-8wgj.json new file mode 100644 index 00000000000..8efb05a0e70 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7c8c-x5xp-8wgj/GHSA-7c8c-x5xp-8wgj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c8c-x5xp-8wgj", + "modified": "2024-08-22T12:30:27Z", + "published": "2024-08-22T12:30:27Z", + "aliases": [ + "CVE-2024-35151" + ], + "details": "IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper authorization controls on APIs.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35151" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/292638" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7165959" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-22T11:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hg8r-px7r-4j3w/GHSA-hg8r-px7r-4j3w.json b/advisories/unreviewed/2024/08/GHSA-hg8r-px7r-4j3w/GHSA-hg8r-px7r-4j3w.json new file mode 100644 index 00000000000..e8e87defc1d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hg8r-px7r-4j3w/GHSA-hg8r-px7r-4j3w.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hg8r-px7r-4j3w", + "modified": "2024-08-22T12:30:27Z", + "published": "2024-08-22T12:30:27Z", + "aliases": [ + "CVE-2024-39744" + ], + "details": "IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39744" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/297236" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7166196" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-22T11:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pcr4-qppj-9v45/GHSA-pcr4-qppj-9v45.json b/advisories/unreviewed/2024/08/GHSA-pcr4-qppj-9v45/GHSA-pcr4-qppj-9v45.json new file mode 100644 index 00000000000..9a4ec8621f2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pcr4-qppj-9v45/GHSA-pcr4-qppj-9v45.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcr4-qppj-9v45", + "modified": "2024-08-22T12:30:27Z", + "published": "2024-08-22T12:30:27Z", + "aliases": [ + "CVE-2024-7848" + ], + "details": "The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'dpk_upvf_update_doc' due to missing validation on the 'docid' user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to gain access to other user's private files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7848" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3136913%40user-private-files&new=3136913%40user-private-files&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0fb06de8-97d6-46c3-83ef-93a209540259?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-22T11:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qv35-6fhq-4w23/GHSA-qv35-6fhq-4w23.json b/advisories/unreviewed/2024/08/GHSA-qv35-6fhq-4w23/GHSA-qv35-6fhq-4w23.json new file mode 100644 index 00000000000..b6a3cce7a62 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qv35-6fhq-4w23/GHSA-qv35-6fhq-4w23.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv35-6fhq-4w23", + "modified": "2024-08-22T12:30:27Z", + "published": "2024-08-22T12:30:27Z", + "aliases": [ + "CVE-2024-39745" + ], + "details": "IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39745" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/297312" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7166195" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-22T11:15:13Z" + } +} \ No newline at end of file