Publish Advisories

GHSA-5cfq-mh36-cvhr
GHSA-8w2q-mh8v-whx2
GHSA-9qpj-gvc6-34rv
GHSA-crg8-w24w-qvmq
GHSA-f2cq-m485-xq43
GHSA-gh33-mw8r-hv99
GHSA-jfv8-vg3m-73pc
GHSA-mq9m-c33f-xf29
GHSA-mxc5-jmfp-8w6f
GHSA-w835-4fh5-99v9
GHSA-w966-799g-fp7v
GHSA-xfjh-8mwq-67xv
GHSA-xj54-8cp7-f54r
This commit is contained in:
advisory-database[bot]
2024-06-06 15:32:15 +00:00
parent 6d80a9e365
commit 08db923fd0
13 changed files with 183 additions and 25 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5cfq-mh36-cvhr",
"modified": "2024-06-05T06:30:40Z",
"modified": "2024-06-06T15:30:36Z",
"published": "2024-06-05T06:30:40Z",
"aliases": [
"CVE-2024-2087"
@@ -36,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8w2q-mh8v-whx2",
"modified": "2024-06-04T15:30:59Z",
"modified": "2024-06-06T15:30:36Z",
"published": "2024-06-04T15:30:59Z",
"aliases": [
"CVE-2024-36547"
],
"details": "idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mudi=add",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-04T15:15:47Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9qpj-gvc6-34rv",
"modified": "2024-06-04T15:30:59Z",
"modified": "2024-06-06T15:30:36Z",
"published": "2024-06-04T15:30:59Z",
"aliases": [
"CVE-2024-36548"
],
"details": "idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/vpsCompany_deal.php?mudi=del",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-04T15:15:47Z"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-crg8-w24w-qvmq",
"modified": "2024-06-06T15:30:36Z",
"published": "2024-06-06T15:30:36Z",
"aliases": [
"CVE-2024-36779"
],
"details": "Sourcecodester Stock Management System v1.0 is vulnerable to SQL Injection via editCategories.php.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36779"
},
{
"type": "WEB",
"url": "https://github.com/CveSecLook/cve/issues/42"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-06T13:15:31Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f2cq-m485-xq43",
"modified": "2024-06-06T15:30:36Z",
"published": "2024-06-06T15:30:36Z",
"aliases": [
"CVE-2024-5684"
],
"details": "An attacker with access to the private network (the charger is connected to) or local access to the Ethernet-Interface can exploit a faulty implementation of the JWT-library in order to bypass the password authentication to the web configuration interface and then has full access as the user would have. However, an attacker will not have developer or admin rights. If the implementation of the JWT-library is wrongly configured to accept \"none\"-algorithms, the server will pass insecure JWT. A local, unauthenticated attacker can exploit this vulnerability to bypass the authentication mechanism.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5684"
},
{
"type": "WEB",
"url": "https://asrg.io/security-advisories/vulnerability-in-id-charger-connect-and-pro-from-volkswagen-group-charging-gmbh-elli-evbox-versions-spr3-2b-spr3-51-and-spr3-52"
}
],
"database_specific": {
"cwe_ids": [
"CWE-345"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-06T13:15:32Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gh33-mw8r-hv99",
"modified": "2024-06-05T06:30:39Z",
"modified": "2024-06-06T15:30:36Z",
"published": "2024-06-05T06:30:39Z",
"aliases": [
"CVE-2024-1940"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jfv8-vg3m-73pc",
"modified": "2024-06-06T15:30:36Z",
"published": "2024-06-06T15:30:36Z",
"aliases": [
"CVE-2024-34832"
],
"details": "Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34832"
},
{
"type": "WEB",
"url": "https://github.com/julio-cfa/CVE-2024-34832"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-06T15:15:44Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mq9m-c33f-xf29",
"modified": "2024-06-04T15:30:59Z",
"modified": "2024-06-06T15:30:36Z",
"published": "2024-06-04T15:30:59Z",
"aliases": [
"CVE-2024-36550"
],
"details": "idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=add&nohrefStr=close",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-04T15:15:47Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mxc5-jmfp-8w6f",
"modified": "2024-06-05T06:30:40Z",
"modified": "2024-06-06T15:30:36Z",
"published": "2024-06-05T06:30:40Z",
"aliases": [
"CVE-2024-3667"
@@ -36,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w835-4fh5-99v9",
"modified": "2024-06-04T15:30:59Z",
"modified": "2024-06-06T15:30:36Z",
"published": "2024-06-04T15:30:59Z",
"aliases": [
"CVE-2024-36549"
],
"details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=rev&nohrefStr=close",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-04T15:15:47Z"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w966-799g-fp7v",
"modified": "2024-06-06T15:30:36Z",
"published": "2024-06-06T15:30:36Z",
"aliases": [
"CVE-2024-5675"
],
"details": "Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This vulnerability could allow an attacker to execute arbitrary code, by injecting a malicious payload into the “ViewState” field.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5675"
},
{
"type": "WEB",
"url": "https://www.incibe.es/en/incibe-cert/notices/aviso/unreliable-data-deserialization-vulnerability-mentor"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-06T13:15:31Z"
}
}
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-330"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xj54-8cp7-f54r",
"modified": "2024-06-05T06:30:39Z",
"modified": "2024-06-06T15:30:36Z",
"published": "2024-06-05T06:30:39Z",
"aliases": [
"CVE-2024-1161"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,