diff --git a/advisories/unreviewed/2024/05/GHSA-5qx6-4rcv-pg8j/GHSA-5qx6-4rcv-pg8j.json b/advisories/unreviewed/2024/05/GHSA-5qx6-4rcv-pg8j/GHSA-5qx6-4rcv-pg8j.json new file mode 100644 index 00000000000..99205fba9c5 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-5qx6-4rcv-pg8j/GHSA-5qx6-4rcv-pg8j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qx6-4rcv-pg8j", + "modified": "2024-05-31T09:31:30Z", + "published": "2024-05-31T09:31:29Z", + "aliases": [ + "CVE-2024-5436" + ], + "details": "Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88. We recommend upgrading to version 12.88 or above.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5436" + }, + { + "type": "WEB", + "url": "https://hackerone.com/snapchat" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-704" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-31T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-gggr-w4c4-8w8h/GHSA-gggr-w4c4-8w8h.json b/advisories/unreviewed/2024/05/GHSA-gggr-w4c4-8w8h/GHSA-gggr-w4c4-8w8h.json new file mode 100644 index 00000000000..c79b8ddb2d9 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-gggr-w4c4-8w8h/GHSA-gggr-w4c4-8w8h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gggr-w4c4-8w8h", + "modified": "2024-05-31T09:31:30Z", + "published": "2024-05-31T09:31:29Z", + "aliases": [ + "CVE-2024-5525" + ], + "details": "Improper privilege management vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows a local user to access the application as an administrator without any provided credentials, allowing the attacker to perform administrative actions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5525" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-astrotalks" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-31T08:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-mfv3-73vg-4vjg/GHSA-mfv3-73vg-4vjg.json b/advisories/unreviewed/2024/05/GHSA-mfv3-73vg-4vjg/GHSA-mfv3-73vg-4vjg.json new file mode 100644 index 00000000000..adb2ece9e5d --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-mfv3-73vg-4vjg/GHSA-mfv3-73vg-4vjg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfv3-73vg-4vjg", + "modified": "2024-05-31T09:31:29Z", + "published": "2024-05-31T09:31:29Z", + "aliases": [ + "CVE-2024-5524" + ], + "details": "Information exposure vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows unregistered users to access all internal links of the application without providing any credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5524" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-astrotalks" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-31T08:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-pwh7-phvx-rxgv/GHSA-pwh7-phvx-rxgv.json b/advisories/unreviewed/2024/05/GHSA-pwh7-phvx-rxgv/GHSA-pwh7-phvx-rxgv.json new file mode 100644 index 00000000000..65ca8585cb7 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-pwh7-phvx-rxgv/GHSA-pwh7-phvx-rxgv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwh7-phvx-rxgv", + "modified": "2024-05-31T09:31:29Z", + "published": "2024-05-31T09:31:29Z", + "aliases": [ + "CVE-2024-5523" + ], + "details": "SQL injection vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability could allow an authenticated local user to send a specially crafted SQL query to the 'searchString' parameter and retrieve all information stored in the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5523" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-astrotalks" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-31T08:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-qfp7-gc56-5hcj/GHSA-qfp7-gc56-5hcj.json b/advisories/unreviewed/2024/05/GHSA-qfp7-gc56-5hcj/GHSA-qfp7-gc56-5hcj.json new file mode 100644 index 00000000000..eb34199eb08 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-qfp7-gc56-5hcj/GHSA-qfp7-gc56-5hcj.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfp7-gc56-5hcj", + "modified": "2024-05-31T09:31:29Z", + "published": "2024-05-31T09:31:29Z", + "aliases": [ + "CVE-2024-5427" + ], + "details": "The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Reservation Form shortcode in all versions up to, and including, 2.2.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5427" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/trunk/core/shortcodes/views/reservation/reservation-form-template.php#L22" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3095135/#file8" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wp-cafe/#description" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/336e2429-97ab-4948-9d21-f0121216d2d1?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-31T07:15:10Z" + } +} \ No newline at end of file