diff --git a/advisories/github-reviewed/2023/07/GHSA-4gpr-p634-922x/GHSA-4gpr-p634-922x.json b/advisories/github-reviewed/2023/07/GHSA-4gpr-p634-922x/GHSA-4gpr-p634-922x.json index 959378803bd..09a6da429a9 100644 --- a/advisories/github-reviewed/2023/07/GHSA-4gpr-p634-922x/GHSA-4gpr-p634-922x.json +++ b/advisories/github-reviewed/2023/07/GHSA-4gpr-p634-922x/GHSA-4gpr-p634-922x.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-4gpr-p634-922x", - "modified": "2023-11-15T18:12:59Z", + "modified": "2025-04-17T12:44:36Z", "published": "2023-07-25T17:19:10Z", "aliases": [ "CVE-2023-36806" ], "summary": "Cross site scripting via input unit widget", - "details": "### Impact\n\nAuthenticated users can inject malicious code in widgets with units, which is then executed both in the element preview (back end) and on the website (front end).\n\n### Patches\n\nUpdate to Contao 4.9.42, 4.13.28 or 5.1.10. \n\n### Workarounds\n\nDisable login for all untrusted back end users.\n\n### References\n\nhttps://contao.org/en/security-advisories/cross-site-scripting-in-widgets-with-units\n\n### For more information\n\nIf you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose).\n\n### Credits\n\nThanks to Christian Pöschl and Fabian Brenner from usd AG for reporting this vulnerability.", + "details": "### Impact\n\nAuthenticated users can inject malicious code in widgets with units, which is then executed both in the element preview (back end) and on the website (front end).\n\n### Patches\n\nUpdate to Contao 4.9.42, 4.13.28 or 5.1.10.\n\n### Workarounds\n\nDisable login for all untrusted back end users.\n\n### References\n\nhttps://contao.org/en/security-advisories/cross-site-scripting-in-widgets-with-units\n\n### For more information\n\nIf you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose).\n\n### Credits\n\nThanks to Christian Pöschl and Fabian Brenner from usd AG for reporting this vulnerability.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/04/GHSA-v24p-7p4j-qvvf/GHSA-v24p-7p4j-qvvf.json b/advisories/github-reviewed/2024/04/GHSA-v24p-7p4j-qvvf/GHSA-v24p-7p4j-qvvf.json index a380b6a3ae8..f4c73272b2b 100644 --- a/advisories/github-reviewed/2024/04/GHSA-v24p-7p4j-qvvf/GHSA-v24p-7p4j-qvvf.json +++ b/advisories/github-reviewed/2024/04/GHSA-v24p-7p4j-qvvf/GHSA-v24p-7p4j-qvvf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v24p-7p4j-qvvf", - "modified": "2024-04-09T18:52:47Z", + "modified": "2025-04-17T12:44:31Z", "published": "2024-04-09T18:52:46Z", "aliases": [ "CVE-2024-28190" diff --git a/advisories/github-reviewed/2025/01/GHSA-hmg4-wwm5-p999/GHSA-hmg4-wwm5-p999.json b/advisories/github-reviewed/2025/01/GHSA-hmg4-wwm5-p999/GHSA-hmg4-wwm5-p999.json index 0bb6c7bfc6f..5ca451b05ac 100644 --- a/advisories/github-reviewed/2025/01/GHSA-hmg4-wwm5-p999/GHSA-hmg4-wwm5-p999.json +++ b/advisories/github-reviewed/2025/01/GHSA-hmg4-wwm5-p999/GHSA-hmg4-wwm5-p999.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-hmg4-wwm5-p999", - "modified": "2025-02-20T22:51:41Z", + "modified": "2025-04-17T12:43:18Z", "published": "2025-01-21T21:21:30Z", "aliases": [ "CVE-2025-24011" ], "summary": "Umbraco Allows User Enumeration Feasible Based On Management API Timing and Response Codes ", - "details": "### Impact\n\nBased on an analysis of response codes and timing of Umbraco 14+ management API responses, it's possible to determine whether an account exists.\n\n### Patches\n\nWill be patched in 14.3.2 and 15.1.2.\n\n### Workarounds\n\nNone available.", + "details": "### Impact\n\nBased on an analysis of response codes and timing of Umbraco 14+ management API responses, it's possible to determine whether an account exists.\n\n### Patches\n\nPatched in 14.3.2 and 15.1.2.\n\n### Workarounds\n\nNone available.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2025/03/GHSA-vqqr-fgmh-f626/GHSA-vqqr-fgmh-f626.json b/advisories/github-reviewed/2025/03/GHSA-vqqr-fgmh-f626/GHSA-vqqr-fgmh-f626.json index f23273f3ad1..46cb31b4260 100644 --- a/advisories/github-reviewed/2025/03/GHSA-vqqr-fgmh-f626/GHSA-vqqr-fgmh-f626.json +++ b/advisories/github-reviewed/2025/03/GHSA-vqqr-fgmh-f626/GHSA-vqqr-fgmh-f626.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vqqr-fgmh-f626", - "modified": "2025-03-19T15:41:47Z", + "modified": "2025-04-17T12:44:08Z", "published": "2025-03-18T21:07:17Z", "aliases": [ "CVE-2025-29790"