diff --git a/advisories/unreviewed/2023/11/GHSA-27pw-7wxg-pvx9/GHSA-27pw-7wxg-pvx9.json b/advisories/unreviewed/2023/11/GHSA-27pw-7wxg-pvx9/GHSA-27pw-7wxg-pvx9.json new file mode 100644 index 00000000000..ee52b605849 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-27pw-7wxg-pvx9/GHSA-27pw-7wxg-pvx9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27pw-7wxg-pvx9", + "modified": "2023-11-15T15:30:20Z", + "published": "2023-11-15T15:30:20Z", + "aliases": [ + "CVE-2023-42544" + ], + "details": "Improper access control vulnerability in Quick Share prior to 13.5.52.0 allows local attacker to access local files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42544" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T08:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-3248-f5xr-jwg7/GHSA-3248-f5xr-jwg7.json b/advisories/unreviewed/2023/11/GHSA-3248-f5xr-jwg7/GHSA-3248-f5xr-jwg7.json index e8342278718..5f9364e777d 100644 --- a/advisories/unreviewed/2023/11/GHSA-3248-f5xr-jwg7/GHSA-3248-f5xr-jwg7.json +++ b/advisories/unreviewed/2023/11/GHSA-3248-f5xr-jwg7/GHSA-3248-f5xr-jwg7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3248-f5xr-jwg7", - "modified": "2023-11-08T03:30:32Z", + "modified": "2023-11-15T15:30:21Z", "published": "2023-11-08T03:30:32Z", "aliases": [ "CVE-2023-46770" ], "details": "Out-of-bounds vulnerability in the sensor module. Successful exploitation of this vulnerability may cause mistouch prevention errors on users' mobile phones.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-08T03:15:08Z" diff --git a/advisories/unreviewed/2023/11/GHSA-3w8r-3jh9-89v9/GHSA-3w8r-3jh9-89v9.json b/advisories/unreviewed/2023/11/GHSA-3w8r-3jh9-89v9/GHSA-3w8r-3jh9-89v9.json new file mode 100644 index 00000000000..05737492fce --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-3w8r-3jh9-89v9/GHSA-3w8r-3jh9-89v9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w8r-3jh9-89v9", + "modified": "2023-11-15T15:30:21Z", + "published": "2023-11-15T15:30:21Z", + "aliases": [ + "CVE-2023-48087" + ], + "details": "xxl-job-admin 2.4.0 is vulnerable to Insecure Permissions via /xxl-job-admin/joblog/clearLog and /xxl-job-admin/joblog/logDetailCat.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48087" + }, + { + "type": "WEB", + "url": "https://github.com/xuxueli/xxl-job/issues/3330" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-15T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-3x38-82cr-g8gh/GHSA-3x38-82cr-g8gh.json b/advisories/unreviewed/2023/11/GHSA-3x38-82cr-g8gh/GHSA-3x38-82cr-g8gh.json index 4dd4c56df5b..232c15b2b6e 100644 --- a/advisories/unreviewed/2023/11/GHSA-3x38-82cr-g8gh/GHSA-3x38-82cr-g8gh.json +++ b/advisories/unreviewed/2023/11/GHSA-3x38-82cr-g8gh/GHSA-3x38-82cr-g8gh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3x38-82cr-g8gh", - "modified": "2023-11-09T18:34:55Z", + "modified": "2023-11-15T15:30:21Z", "published": "2023-11-09T18:34:55Z", "aliases": [ "CVE-2023-36688" ], "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Mann Simple Site Verify plugin <= 1.0.7 versions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-09T16:15:34Z" diff --git a/advisories/unreviewed/2023/11/GHSA-4g88-4hgm-m99x/GHSA-4g88-4hgm-m99x.json b/advisories/unreviewed/2023/11/GHSA-4g88-4hgm-m99x/GHSA-4g88-4hgm-m99x.json index 27e0b6cb800..94dc272bd9b 100644 --- a/advisories/unreviewed/2023/11/GHSA-4g88-4hgm-m99x/GHSA-4g88-4hgm-m99x.json +++ b/advisories/unreviewed/2023/11/GHSA-4g88-4hgm-m99x/GHSA-4g88-4hgm-m99x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4g88-4hgm-m99x", - "modified": "2023-11-09T18:34:55Z", + "modified": "2023-11-15T15:30:21Z", "published": "2023-11-09T18:34:55Z", "aliases": [ "CVE-2023-45884" ], "details": "Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-09T17:15:08Z" diff --git a/advisories/unreviewed/2023/11/GHSA-5ch2-qvr7-76ch/GHSA-5ch2-qvr7-76ch.json b/advisories/unreviewed/2023/11/GHSA-5ch2-qvr7-76ch/GHSA-5ch2-qvr7-76ch.json new file mode 100644 index 00000000000..9c9c778ed71 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5ch2-qvr7-76ch/GHSA-5ch2-qvr7-76ch.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5ch2-qvr7-76ch", + "modified": "2023-11-15T15:30:21Z", + "published": "2023-11-15T15:30:21Z", + "aliases": [ + "CVE-2023-5676" + ], + "details": "In Eclipse OpenJ9 before version 0.41.0, the JVM can be forced into an infinite busy hang on a spinlock or a segmentation fault if a shutdown signal (SIGTERM, SIGINT or SIGHUP) is received before the JVM has finished initializing.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5676" + }, + { + "type": "WEB", + "url": "https://github.com/eclipse-openj9/openj9/pull/18085" + }, + { + "type": "WEB", + "url": "https://gitlab.eclipse.org/security/cve-assignement/-/issues/13" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-364" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-15T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-65wf-2455-72cw/GHSA-65wf-2455-72cw.json b/advisories/unreviewed/2023/11/GHSA-65wf-2455-72cw/GHSA-65wf-2455-72cw.json new file mode 100644 index 00000000000..399d78c50f0 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-65wf-2455-72cw/GHSA-65wf-2455-72cw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65wf-2455-72cw", + "modified": "2023-11-15T15:30:20Z", + "published": "2023-11-15T15:30:20Z", + "aliases": [ + "CVE-2023-42545" + ], + "details": "Use of implicit intent for sensitive communication vulnerability in Phone prior to versions 12.7.20.12 in Android 11, 13.1.48, 13.5.28 in Android 12, and 14.7.38 in Android 13 allows attackers to access location data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42545" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T08:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-6733-7rp7-vf3m/GHSA-6733-7rp7-vf3m.json b/advisories/unreviewed/2023/11/GHSA-6733-7rp7-vf3m/GHSA-6733-7rp7-vf3m.json new file mode 100644 index 00000000000..fc43ae5a979 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-6733-7rp7-vf3m/GHSA-6733-7rp7-vf3m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6733-7rp7-vf3m", + "modified": "2023-11-15T15:30:21Z", + "published": "2023-11-15T15:30:21Z", + "aliases": [ + "CVE-2023-48088" + ], + "details": "xxl-job-admin 2.4.0 is vulnerable to Cross Site Scripting (XSS) via /xxl-job-admin/joblog/logDetailPage.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48088" + }, + { + "type": "WEB", + "url": "https://github.com/xuxueli/xxl-job/issues/3329" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-15T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7f2c-c54p-7m36/GHSA-7f2c-c54p-7m36.json b/advisories/unreviewed/2023/11/GHSA-7f2c-c54p-7m36/GHSA-7f2c-c54p-7m36.json new file mode 100644 index 00000000000..c2d92dd8637 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-7f2c-c54p-7m36/GHSA-7f2c-c54p-7m36.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f2c-c54p-7m36", + "modified": "2023-11-15T15:30:20Z", + "published": "2023-11-15T15:30:20Z", + "aliases": [ + "CVE-2023-46851" + ], + "details": "Allura Discussion and Allura Forum importing does not restrict URL values specified in attachments. Project administrators can run these imports, which could cause Allura to read local files and expose them.  Exposing internal files then can lead to other exploits, like session hijacking, or remote code execution.\n\nThis issue affects Apache Allura from 1.0.1 through 1.15.0.\n\nUsers are recommended to upgrade to version 1.16.0, which fixes the issue.  If you are unable to upgrade, set \"disable_entry_points.allura.importers = forge-tracker, forge-discussion\" in your .ini config file.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46851" + }, + { + "type": "WEB", + "url": "https://allura.apache.org/posts/2023-allura-1.16.0.html" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/hqk0vltl7qgrq215zgwjfoj0khbov0gx" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7vf8-rmp2-v23x/GHSA-7vf8-rmp2-v23x.json b/advisories/unreviewed/2023/11/GHSA-7vf8-rmp2-v23x/GHSA-7vf8-rmp2-v23x.json index 23815376cb9..73379316f4d 100644 --- a/advisories/unreviewed/2023/11/GHSA-7vf8-rmp2-v23x/GHSA-7vf8-rmp2-v23x.json +++ b/advisories/unreviewed/2023/11/GHSA-7vf8-rmp2-v23x/GHSA-7vf8-rmp2-v23x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7vf8-rmp2-v23x", - "modified": "2023-11-09T03:30:19Z", + "modified": "2023-11-15T15:30:21Z", "published": "2023-11-09T03:30:19Z", "aliases": [ "CVE-2023-47007" ], "details": "An issue in ASUS RT-AX57 v.3.0.0.4_386_52041 allows a remote attacker to execute arbitrary code via a crafted request to the lan_ifname field in the sub_391B8 function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-09T01:15:07Z" diff --git a/advisories/unreviewed/2023/11/GHSA-897x-xvj8-42rq/GHSA-897x-xvj8-42rq.json b/advisories/unreviewed/2023/11/GHSA-897x-xvj8-42rq/GHSA-897x-xvj8-42rq.json new file mode 100644 index 00000000000..a3f8fdeb904 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-897x-xvj8-42rq/GHSA-897x-xvj8-42rq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-897x-xvj8-42rq", + "modified": "2023-11-15T15:30:21Z", + "published": "2023-11-15T15:30:21Z", + "aliases": [ + "CVE-2023-5245" + ], + "details": "FileUtil.extract() enumerates all zip file entries and extracts each file without validating whether file paths in the archive are outside the intended directory.\n\nWhen creating an instance of TensorflowModel using the saved_model format and an exported tensorflow model, the apply() function invokes the vulnerable implementation of FileUtil.extract().\n\nArbitrary file creation can directly lead to code execution\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5245" + }, + { + "type": "WEB", + "url": "https://github.com/combust/mleap/pull/866#issuecomment-1738032225" + }, + { + "type": "WEB", + "url": "https://research.jfrog.com/vulnerabilities/mleap-path-traversal-rce-xray-532656/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-15T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-96x6-ppmq-j9wc/GHSA-96x6-ppmq-j9wc.json b/advisories/unreviewed/2023/11/GHSA-96x6-ppmq-j9wc/GHSA-96x6-ppmq-j9wc.json new file mode 100644 index 00000000000..11fff1185fd --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-96x6-ppmq-j9wc/GHSA-96x6-ppmq-j9wc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96x6-ppmq-j9wc", + "modified": "2023-11-15T15:30:20Z", + "published": "2023-11-15T15:30:20Z", + "aliases": [ + "CVE-2023-42553" + ], + "details": "Improper authorization verification vulnerability in Samsung Email prior to version 6.1.90.4 allows attackers to read sandbox data of email.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42553" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T08:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9jpw-fc84-wc8p/GHSA-9jpw-fc84-wc8p.json b/advisories/unreviewed/2023/11/GHSA-9jpw-fc84-wc8p/GHSA-9jpw-fc84-wc8p.json index bf5c1277aff..fe8198a0059 100644 --- a/advisories/unreviewed/2023/11/GHSA-9jpw-fc84-wc8p/GHSA-9jpw-fc84-wc8p.json +++ b/advisories/unreviewed/2023/11/GHSA-9jpw-fc84-wc8p/GHSA-9jpw-fc84-wc8p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9jpw-fc84-wc8p", - "modified": "2023-11-08T18:30:31Z", + "modified": "2023-11-15T15:30:21Z", "published": "2023-11-08T18:30:31Z", "aliases": [ "CVE-2023-46621" ], "details": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Enej Bajgoric / Gagan Sandhu / CTLT DEV User Avatar plugin <= 1.4.11 versions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-08T16:15:10Z" diff --git a/advisories/unreviewed/2023/11/GHSA-cp9w-gp2m-qfm3/GHSA-cp9w-gp2m-qfm3.json b/advisories/unreviewed/2023/11/GHSA-cp9w-gp2m-qfm3/GHSA-cp9w-gp2m-qfm3.json new file mode 100644 index 00000000000..65e17968edf --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cp9w-gp2m-qfm3/GHSA-cp9w-gp2m-qfm3.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp9w-gp2m-qfm3", + "modified": "2023-11-15T15:30:20Z", + "published": "2023-11-15T15:30:20Z", + "aliases": [ + "CVE-2023-46845" + ], + "details": "EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code execution vulnerability due to improper settings of the template engine Twig included in the product. As a result, arbitrary code may be executed on the server where the product is running by a user with an administrative privilege.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46845" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN29195731/" + }, + { + "type": "WEB", + "url": "https://www.ec-cube.net/info/weakness/20231026/index.php" + }, + { + "type": "WEB", + "url": "https://www.ec-cube.net/info/weakness/20231026/index_3.php" + }, + { + "type": "WEB", + "url": "https://www.ec-cube.net/info/weakness/20231026/index_40.php" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T08:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-g5gr-7qpp-2p9m/GHSA-g5gr-7qpp-2p9m.json b/advisories/unreviewed/2023/11/GHSA-g5gr-7qpp-2p9m/GHSA-g5gr-7qpp-2p9m.json new file mode 100644 index 00000000000..1d62a83ace7 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-g5gr-7qpp-2p9m/GHSA-g5gr-7qpp-2p9m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5gr-7qpp-2p9m", + "modified": "2023-11-15T15:30:20Z", + "published": "2023-11-15T15:30:20Z", + "aliases": [ + "CVE-2022-45350" + ], + "details": "Improper Neutralization of Formula Elements in a CSV File vulnerability in Pär Thernström Simple History – user activity log, audit tool.This issue affects Simple History – user activity log, audit tool: from n/a through 3.3.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45350" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/simple-history/wordpress-simple-history-plugin-3-3-1-csv-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1236" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-h3c6-r6p2-gr6c/GHSA-h3c6-r6p2-gr6c.json b/advisories/unreviewed/2023/11/GHSA-h3c6-r6p2-gr6c/GHSA-h3c6-r6p2-gr6c.json index 643eac1308a..44fbeecfec9 100644 --- a/advisories/unreviewed/2023/11/GHSA-h3c6-r6p2-gr6c/GHSA-h3c6-r6p2-gr6c.json +++ b/advisories/unreviewed/2023/11/GHSA-h3c6-r6p2-gr6c/GHSA-h3c6-r6p2-gr6c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h3c6-r6p2-gr6c", - "modified": "2023-11-08T03:30:32Z", + "modified": "2023-11-15T15:30:21Z", "published": "2023-11-08T03:30:32Z", "aliases": [ "CVE-2023-46769" ], "details": "Use-After-Free (UAF) vulnerability in the dubai module. Successful exploitation of this vulnerability will affect availability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-08T03:15:07Z" diff --git a/advisories/unreviewed/2023/11/GHSA-h4p3-9fc9-2447/GHSA-h4p3-9fc9-2447.json b/advisories/unreviewed/2023/11/GHSA-h4p3-9fc9-2447/GHSA-h4p3-9fc9-2447.json new file mode 100644 index 00000000000..ebdfc012142 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-h4p3-9fc9-2447/GHSA-h4p3-9fc9-2447.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4p3-9fc9-2447", + "modified": "2023-11-15T15:30:20Z", + "published": "2023-11-15T15:30:20Z", + "aliases": [ + "CVE-2023-5076" + ], + "details": "The Ziteboard Online Whiteboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ziteboard' shortcode in versions up to, and including, 2.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5076" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/2988896/ziteboard-online-whiteboard" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f5608f50-e17a-471f-b644-dceb64d82f0c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T08:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-h974-rh4p-qm47/GHSA-h974-rh4p-qm47.json b/advisories/unreviewed/2023/11/GHSA-h974-rh4p-qm47/GHSA-h974-rh4p-qm47.json new file mode 100644 index 00000000000..a7a7ddd1ef9 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-h974-rh4p-qm47/GHSA-h974-rh4p-qm47.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h974-rh4p-qm47", + "modified": "2023-11-15T15:30:21Z", + "published": "2023-11-15T15:30:21Z", + "aliases": [ + "CVE-2023-4602" + ], + "details": "The Namaste! LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'course_id' parameter in versions up to, and including, 2.6.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4602" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1wliD7YvLqL2xWnR6jLEnWgoWRKsv9dCI/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/2966178/" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d014f512-9030-49ce-945d-4900594fb373?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-15T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-hgg2-x3jc-9xcr/GHSA-hgg2-x3jc-9xcr.json b/advisories/unreviewed/2023/11/GHSA-hgg2-x3jc-9xcr/GHSA-hgg2-x3jc-9xcr.json index 8fb4eadd66d..4a4d34dfe4a 100644 --- a/advisories/unreviewed/2023/11/GHSA-hgg2-x3jc-9xcr/GHSA-hgg2-x3jc-9xcr.json +++ b/advisories/unreviewed/2023/11/GHSA-hgg2-x3jc-9xcr/GHSA-hgg2-x3jc-9xcr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hgg2-x3jc-9xcr", - "modified": "2023-11-09T18:34:55Z", + "modified": "2023-11-15T15:30:21Z", "published": "2023-11-09T18:34:55Z", "aliases": [ "CVE-2023-25994" ], "details": "Cross-Site Request Forgery (CSRF) vulnerability in Alex Benfica Publish to Schedule plugin <= 4.4.2 versions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-09T16:15:34Z" diff --git a/advisories/unreviewed/2023/11/GHSA-m3mr-93pv-j56f/GHSA-m3mr-93pv-j56f.json b/advisories/unreviewed/2023/11/GHSA-m3mr-93pv-j56f/GHSA-m3mr-93pv-j56f.json index a7bc7acfde9..6046370f65e 100644 --- a/advisories/unreviewed/2023/11/GHSA-m3mr-93pv-j56f/GHSA-m3mr-93pv-j56f.json +++ b/advisories/unreviewed/2023/11/GHSA-m3mr-93pv-j56f/GHSA-m3mr-93pv-j56f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m3mr-93pv-j56f", - "modified": "2023-11-09T03:30:19Z", + "modified": "2023-11-15T15:30:21Z", "published": "2023-11-09T03:30:19Z", "aliases": [ "CVE-2023-47006" ], "details": "An issue in ASUS RT-AX57 v.3.0.0.4_386_52041 allows a remote attacker to execute arbitrary code via a crafted request to the lan_ipaddr field in the sub_6FC74 function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-09T01:15:07Z" diff --git a/advisories/unreviewed/2023/11/GHSA-mhqf-p484-rpwx/GHSA-mhqf-p484-rpwx.json b/advisories/unreviewed/2023/11/GHSA-mhqf-p484-rpwx/GHSA-mhqf-p484-rpwx.json index e8cfe0490b5..52ece508733 100644 --- a/advisories/unreviewed/2023/11/GHSA-mhqf-p484-rpwx/GHSA-mhqf-p484-rpwx.json +++ b/advisories/unreviewed/2023/11/GHSA-mhqf-p484-rpwx/GHSA-mhqf-p484-rpwx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mhqf-p484-rpwx", - "modified": "2023-11-09T03:30:19Z", + "modified": "2023-11-15T15:30:21Z", "published": "2023-11-09T03:30:19Z", "aliases": [ "CVE-2023-47005" ], "details": "An issue in ASUS RT-AX57 v.3.0.0.4_386_52041 allows a remote attacker to execute arbitrary code via a crafted request to the lan_ifname field in the sub_ln 2C318 function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-09T01:15:07Z" diff --git a/advisories/unreviewed/2023/11/GHSA-mhxm-82f9-q2pw/GHSA-mhxm-82f9-q2pw.json b/advisories/unreviewed/2023/11/GHSA-mhxm-82f9-q2pw/GHSA-mhxm-82f9-q2pw.json index 811d9006f41..90d485017a9 100644 --- a/advisories/unreviewed/2023/11/GHSA-mhxm-82f9-q2pw/GHSA-mhxm-82f9-q2pw.json +++ b/advisories/unreviewed/2023/11/GHSA-mhxm-82f9-q2pw/GHSA-mhxm-82f9-q2pw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mhxm-82f9-q2pw", - "modified": "2023-11-08T03:30:32Z", + "modified": "2023-11-15T15:30:20Z", "published": "2023-11-08T03:30:32Z", "aliases": [ "CVE-2023-46768" ], "details": "Multi-thread vulnerability in the idmap module. Successful exploitation of this vulnerability may cause features to perform abnormally.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-08T03:15:07Z" diff --git a/advisories/unreviewed/2023/11/GHSA-p56w-h56q-c97x/GHSA-p56w-h56q-c97x.json b/advisories/unreviewed/2023/11/GHSA-p56w-h56q-c97x/GHSA-p56w-h56q-c97x.json index 1f3df9236d6..74d3e6d7794 100644 --- a/advisories/unreviewed/2023/11/GHSA-p56w-h56q-c97x/GHSA-p56w-h56q-c97x.json +++ b/advisories/unreviewed/2023/11/GHSA-p56w-h56q-c97x/GHSA-p56w-h56q-c97x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p56w-h56q-c97x", - "modified": "2023-11-09T21:30:38Z", + "modified": "2023-11-15T15:30:20Z", "published": "2023-11-08T00:30:24Z", "aliases": [ "CVE-2023-6002" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-117" + "CWE-117", + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-p62q-5483-h57v/GHSA-p62q-5483-h57v.json b/advisories/unreviewed/2023/11/GHSA-p62q-5483-h57v/GHSA-p62q-5483-h57v.json new file mode 100644 index 00000000000..06f9abc73f5 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-p62q-5483-h57v/GHSA-p62q-5483-h57v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p62q-5483-h57v", + "modified": "2023-11-15T15:30:21Z", + "published": "2023-11-15T15:30:21Z", + "aliases": [ + "CVE-2023-5720" + ], + "details": "A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5720" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-5720" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2245700" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-526" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-15T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-qcqr-cxwj-882p/GHSA-qcqr-cxwj-882p.json b/advisories/unreviewed/2023/11/GHSA-qcqr-cxwj-882p/GHSA-qcqr-cxwj-882p.json new file mode 100644 index 00000000000..ea4c3f0c4db --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-qcqr-cxwj-882p/GHSA-qcqr-cxwj-882p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcqr-cxwj-882p", + "modified": "2023-11-15T15:30:20Z", + "published": "2023-11-15T15:30:20Z", + "aliases": [ + "CVE-2023-42552" + ], + "details": "Implicit intent hijacking vulnerability in Firewall application prior to versions 12.1.00.24 in Android 11, 13.1.00.16 in Android 12 and 14.1.00.7 in Android 13 allows 3rd party application to tamper the database of Firewall.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42552" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T08:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-qg6m-h5wv-r4h8/GHSA-qg6m-h5wv-r4h8.json b/advisories/unreviewed/2023/11/GHSA-qg6m-h5wv-r4h8/GHSA-qg6m-h5wv-r4h8.json new file mode 100644 index 00000000000..0ce0a7b8e65 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-qg6m-h5wv-r4h8/GHSA-qg6m-h5wv-r4h8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg6m-h5wv-r4h8", + "modified": "2023-11-15T15:30:20Z", + "published": "2023-11-15T15:30:20Z", + "aliases": [ + "CVE-2023-42555" + ], + "details": "Use of implicit intent for sensitive communication vulnerability in EasySetup prior to version 11.1.13 allows attackers to get the bluetooth address of user device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42555" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T08:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-qr7v-3hq9-cr46/GHSA-qr7v-3hq9-cr46.json b/advisories/unreviewed/2023/11/GHSA-qr7v-3hq9-cr46/GHSA-qr7v-3hq9-cr46.json index 93f1a31ed2c..883b140bbf4 100644 --- a/advisories/unreviewed/2023/11/GHSA-qr7v-3hq9-cr46/GHSA-qr7v-3hq9-cr46.json +++ b/advisories/unreviewed/2023/11/GHSA-qr7v-3hq9-cr46/GHSA-qr7v-3hq9-cr46.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qr7v-3hq9-cr46", - "modified": "2023-11-09T03:30:19Z", + "modified": "2023-11-15T15:30:21Z", "published": "2023-11-09T03:30:19Z", "aliases": [ "CVE-2023-47008" ], "details": "An issue in ASUS RT-AX57 v.3.0.0.4_386_52041 allows a remote attacker to execute arbitrary code via a crafted request to the ifname field in the sub_4CCE4 function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-09T01:15:07Z" diff --git a/advisories/unreviewed/2023/11/GHSA-v5h3-wx8w-wpmx/GHSA-v5h3-wx8w-wpmx.json b/advisories/unreviewed/2023/11/GHSA-v5h3-wx8w-wpmx/GHSA-v5h3-wx8w-wpmx.json new file mode 100644 index 00000000000..04aeffd8800 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-v5h3-wx8w-wpmx/GHSA-v5h3-wx8w-wpmx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5h3-wx8w-wpmx", + "modified": "2023-11-15T15:30:20Z", + "published": "2023-11-15T15:30:20Z", + "aliases": [ + "CVE-2023-42554" + ], + "details": "Improper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42554" + }, + { + "type": "WEB", + "url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=11" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T08:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-v8fc-qxvj-f3mg/GHSA-v8fc-qxvj-f3mg.json b/advisories/unreviewed/2023/11/GHSA-v8fc-qxvj-f3mg/GHSA-v8fc-qxvj-f3mg.json index 804fd6df4a6..7f707c1163a 100644 --- a/advisories/unreviewed/2023/11/GHSA-v8fc-qxvj-f3mg/GHSA-v8fc-qxvj-f3mg.json +++ b/advisories/unreviewed/2023/11/GHSA-v8fc-qxvj-f3mg/GHSA-v8fc-qxvj-f3mg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v8fc-qxvj-f3mg", - "modified": "2023-11-09T18:34:55Z", + "modified": "2023-11-15T15:30:21Z", "published": "2023-11-09T18:34:55Z", "aliases": [ "CVE-2023-45885" ], "details": "Cross Site Scripting (XSS) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to run arbitrary code via the new component feature in the flexibleLayout plugin.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-09T17:15:08Z" diff --git a/advisories/unreviewed/2023/11/GHSA-vfrw-m2c3-hh6g/GHSA-vfrw-m2c3-hh6g.json b/advisories/unreviewed/2023/11/GHSA-vfrw-m2c3-hh6g/GHSA-vfrw-m2c3-hh6g.json new file mode 100644 index 00000000000..d4787dddc3b --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-vfrw-m2c3-hh6g/GHSA-vfrw-m2c3-hh6g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfrw-m2c3-hh6g", + "modified": "2023-11-15T15:30:20Z", + "published": "2023-11-15T15:30:20Z", + "aliases": [ + "CVE-2022-47442" + ], + "details": "Improper Neutralization of Formula Elements in a CSV File vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a through 1.2.3.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47442" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/userswp/wordpress-userswp-front-end-login-form-user-registration-user-profile-members-directory-plugin-for-wordpress-plugin-1-2-3-9-csv-injection?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1236" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-07T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-x98f-2rgf-qwqh/GHSA-x98f-2rgf-qwqh.json b/advisories/unreviewed/2023/11/GHSA-x98f-2rgf-qwqh/GHSA-x98f-2rgf-qwqh.json new file mode 100644 index 00000000000..2df9887d307 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-x98f-2rgf-qwqh/GHSA-x98f-2rgf-qwqh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x98f-2rgf-qwqh", + "modified": "2023-11-15T15:30:21Z", + "published": "2023-11-15T15:30:21Z", + "aliases": [ + "CVE-2023-48089" + ], + "details": "xxl-job-admin 2.4.0 is vulnerable to Remote Code Execution (RCE) via /xxl-job-admin/jobcode/save.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48089" + }, + { + "type": "WEB", + "url": "https://github.com/xuxueli/xxl-job/issues/3333" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-15T15:15:07Z" + } +} \ No newline at end of file