From 0e3e53dc0fc81d9b729b9a64cc8c549726cd8e17 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 31 May 2024 09:33:06 +0000 Subject: [PATCH] Publish Advisories GHSA-5qx6-4rcv-pg8j GHSA-gggr-w4c4-8w8h GHSA-mfv3-73vg-4vjg GHSA-pwh7-phvx-rxgv GHSA-qfp7-gc56-5hcj --- .../GHSA-5qx6-4rcv-pg8j.json | 35 +++++++++++++ .../GHSA-gggr-w4c4-8w8h.json | 38 ++++++++++++++ .../GHSA-mfv3-73vg-4vjg.json | 38 ++++++++++++++ .../GHSA-pwh7-phvx-rxgv.json | 38 ++++++++++++++ .../GHSA-qfp7-gc56-5hcj.json | 50 +++++++++++++++++++ 5 files changed, 199 insertions(+) create mode 100644 advisories/unreviewed/2024/05/GHSA-5qx6-4rcv-pg8j/GHSA-5qx6-4rcv-pg8j.json create mode 100644 advisories/unreviewed/2024/05/GHSA-gggr-w4c4-8w8h/GHSA-gggr-w4c4-8w8h.json create mode 100644 advisories/unreviewed/2024/05/GHSA-mfv3-73vg-4vjg/GHSA-mfv3-73vg-4vjg.json create mode 100644 advisories/unreviewed/2024/05/GHSA-pwh7-phvx-rxgv/GHSA-pwh7-phvx-rxgv.json create mode 100644 advisories/unreviewed/2024/05/GHSA-qfp7-gc56-5hcj/GHSA-qfp7-gc56-5hcj.json diff --git a/advisories/unreviewed/2024/05/GHSA-5qx6-4rcv-pg8j/GHSA-5qx6-4rcv-pg8j.json b/advisories/unreviewed/2024/05/GHSA-5qx6-4rcv-pg8j/GHSA-5qx6-4rcv-pg8j.json new file mode 100644 index 00000000000..99205fba9c5 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-5qx6-4rcv-pg8j/GHSA-5qx6-4rcv-pg8j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qx6-4rcv-pg8j", + "modified": "2024-05-31T09:31:30Z", + "published": "2024-05-31T09:31:29Z", + "aliases": [ + "CVE-2024-5436" + ], + "details": "Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88. We recommend upgrading to version 12.88 or above.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5436" + }, + { + "type": "WEB", + "url": "https://hackerone.com/snapchat" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-704" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-31T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-gggr-w4c4-8w8h/GHSA-gggr-w4c4-8w8h.json b/advisories/unreviewed/2024/05/GHSA-gggr-w4c4-8w8h/GHSA-gggr-w4c4-8w8h.json new file mode 100644 index 00000000000..c79b8ddb2d9 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-gggr-w4c4-8w8h/GHSA-gggr-w4c4-8w8h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gggr-w4c4-8w8h", + "modified": "2024-05-31T09:31:30Z", + "published": "2024-05-31T09:31:29Z", + "aliases": [ + "CVE-2024-5525" + ], + "details": "Improper privilege management vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows a local user to access the application as an administrator without any provided credentials, allowing the attacker to perform administrative actions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5525" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-astrotalks" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-31T08:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-mfv3-73vg-4vjg/GHSA-mfv3-73vg-4vjg.json b/advisories/unreviewed/2024/05/GHSA-mfv3-73vg-4vjg/GHSA-mfv3-73vg-4vjg.json new file mode 100644 index 00000000000..adb2ece9e5d --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-mfv3-73vg-4vjg/GHSA-mfv3-73vg-4vjg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfv3-73vg-4vjg", + "modified": "2024-05-31T09:31:29Z", + "published": "2024-05-31T09:31:29Z", + "aliases": [ + "CVE-2024-5524" + ], + "details": "Information exposure vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows unregistered users to access all internal links of the application without providing any credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5524" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-astrotalks" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-31T08:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-pwh7-phvx-rxgv/GHSA-pwh7-phvx-rxgv.json b/advisories/unreviewed/2024/05/GHSA-pwh7-phvx-rxgv/GHSA-pwh7-phvx-rxgv.json new file mode 100644 index 00000000000..65ca8585cb7 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-pwh7-phvx-rxgv/GHSA-pwh7-phvx-rxgv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwh7-phvx-rxgv", + "modified": "2024-05-31T09:31:29Z", + "published": "2024-05-31T09:31:29Z", + "aliases": [ + "CVE-2024-5523" + ], + "details": "SQL injection vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability could allow an authenticated local user to send a specially crafted SQL query to the 'searchString' parameter and retrieve all information stored in the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5523" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-astrotalks" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-31T08:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-qfp7-gc56-5hcj/GHSA-qfp7-gc56-5hcj.json b/advisories/unreviewed/2024/05/GHSA-qfp7-gc56-5hcj/GHSA-qfp7-gc56-5hcj.json new file mode 100644 index 00000000000..eb34199eb08 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-qfp7-gc56-5hcj/GHSA-qfp7-gc56-5hcj.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfp7-gc56-5hcj", + "modified": "2024-05-31T09:31:29Z", + "published": "2024-05-31T09:31:29Z", + "aliases": [ + "CVE-2024-5427" + ], + "details": "The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Reservation Form shortcode in all versions up to, and including, 2.2.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5427" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-cafe/trunk/core/shortcodes/views/reservation/reservation-form-template.php#L22" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3095135/#file8" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wp-cafe/#description" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/336e2429-97ab-4948-9d21-f0121216d2d1?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-31T07:15:10Z" + } +} \ No newline at end of file