mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-4gpr-p634-922x GHSA-v24p-7p4j-qvvf GHSA-hmg4-wwm5-p999 GHSA-vqqr-fgmh-f626
This commit is contained in:
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4gpr-p634-922x",
|
||||
"modified": "2023-11-15T18:12:59Z",
|
||||
"modified": "2025-04-17T12:44:36Z",
|
||||
"published": "2023-07-25T17:19:10Z",
|
||||
"aliases": [
|
||||
"CVE-2023-36806"
|
||||
],
|
||||
"summary": "Cross site scripting via input unit widget",
|
||||
"details": "### Impact\n\nAuthenticated users can inject malicious code in widgets with units, which is then executed both in the element preview (back end) and on the website (front end).\n\n### Patches\n\nUpdate to Contao 4.9.42, 4.13.28 or 5.1.10. \n\n### Workarounds\n\nDisable login for all untrusted back end users.\n\n### References\n\nhttps://contao.org/en/security-advisories/cross-site-scripting-in-widgets-with-units\n\n### For more information\n\nIf you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose).\n\n### Credits\n\nThanks to Christian Pöschl and Fabian Brenner from usd AG for reporting this vulnerability.",
|
||||
"details": "### Impact\n\nAuthenticated users can inject malicious code in widgets with units, which is then executed both in the element preview (back end) and on the website (front end).\n\n### Patches\n\nUpdate to Contao 4.9.42, 4.13.28 or 5.1.10.\n\n### Workarounds\n\nDisable login for all untrusted back end users.\n\n### References\n\nhttps://contao.org/en/security-advisories/cross-site-scripting-in-widgets-with-units\n\n### For more information\n\nIf you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose).\n\n### Credits\n\nThanks to Christian Pöschl and Fabian Brenner from usd AG for reporting this vulnerability.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-v24p-7p4j-qvvf",
|
||||
"modified": "2024-04-09T18:52:47Z",
|
||||
"modified": "2025-04-17T12:44:31Z",
|
||||
"published": "2024-04-09T18:52:46Z",
|
||||
"aliases": [
|
||||
"CVE-2024-28190"
|
||||
|
||||
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-hmg4-wwm5-p999",
|
||||
"modified": "2025-02-20T22:51:41Z",
|
||||
"modified": "2025-04-17T12:43:18Z",
|
||||
"published": "2025-01-21T21:21:30Z",
|
||||
"aliases": [
|
||||
"CVE-2025-24011"
|
||||
],
|
||||
"summary": "Umbraco Allows User Enumeration Feasible Based On Management API Timing and Response Codes ",
|
||||
"details": "### Impact\n\nBased on an analysis of response codes and timing of Umbraco 14+ management API responses, it's possible to determine whether an account exists.\n\n### Patches\n\nWill be patched in 14.3.2 and 15.1.2.\n\n### Workarounds\n\nNone available.",
|
||||
"details": "### Impact\n\nBased on an analysis of response codes and timing of Umbraco 14+ management API responses, it's possible to determine whether an account exists.\n\n### Patches\n\nPatched in 14.3.2 and 15.1.2.\n\n### Workarounds\n\nNone available.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-vqqr-fgmh-f626",
|
||||
"modified": "2025-03-19T15:41:47Z",
|
||||
"modified": "2025-04-17T12:44:08Z",
|
||||
"published": "2025-03-18T21:07:17Z",
|
||||
"aliases": [
|
||||
"CVE-2025-29790"
|
||||
|
||||
Reference in New Issue
Block a user