From 0e95084f1517acc256f2530c2905549d32dec43f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 3 Apr 2024 06:32:11 +0000 Subject: [PATCH] Publish Advisories GHSA-pjqv-pvfh-2w6m GHSA-2h64-rqxh-72wj GHSA-53x2-fcg3-m32m GHSA-6xrw-49j6-7f3m GHSA-7mxg-r76p-363g GHSA-9h58-5xgm-2682 GHSA-gcr2-pc9c-643g GHSA-p5p6-3j26-j8rh GHSA-rfj8-v7wf-3hfc GHSA-vrmm-rpmr-vmc8 GHSA-wjf7-jjrj-rw8w --- .../GHSA-pjqv-pvfh-2w6m.json | 6 ++- .../GHSA-2h64-rqxh-72wj.json | 35 ++++++++++++++++ .../GHSA-53x2-fcg3-m32m.json | 42 +++++++++++++++++++ .../GHSA-6xrw-49j6-7f3m.json | 35 ++++++++++++++++ .../GHSA-7mxg-r76p-363g.json | 39 +++++++++++++++++ .../GHSA-9h58-5xgm-2682.json | 35 ++++++++++++++++ .../GHSA-gcr2-pc9c-643g.json | 35 ++++++++++++++++ .../GHSA-p5p6-3j26-j8rh.json | 35 ++++++++++++++++ .../GHSA-rfj8-v7wf-3hfc.json | 35 ++++++++++++++++ .../GHSA-vrmm-rpmr-vmc8.json | 35 ++++++++++++++++ .../GHSA-wjf7-jjrj-rw8w.json | 35 ++++++++++++++++ 11 files changed, 366 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/04/GHSA-2h64-rqxh-72wj/GHSA-2h64-rqxh-72wj.json create mode 100644 advisories/unreviewed/2024/04/GHSA-53x2-fcg3-m32m/GHSA-53x2-fcg3-m32m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-6xrw-49j6-7f3m/GHSA-6xrw-49j6-7f3m.json create mode 100644 advisories/unreviewed/2024/04/GHSA-7mxg-r76p-363g/GHSA-7mxg-r76p-363g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-9h58-5xgm-2682/GHSA-9h58-5xgm-2682.json create mode 100644 advisories/unreviewed/2024/04/GHSA-gcr2-pc9c-643g/GHSA-gcr2-pc9c-643g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-p5p6-3j26-j8rh/GHSA-p5p6-3j26-j8rh.json create mode 100644 advisories/unreviewed/2024/04/GHSA-rfj8-v7wf-3hfc/GHSA-rfj8-v7wf-3hfc.json create mode 100644 advisories/unreviewed/2024/04/GHSA-vrmm-rpmr-vmc8/GHSA-vrmm-rpmr-vmc8.json create mode 100644 advisories/unreviewed/2024/04/GHSA-wjf7-jjrj-rw8w/GHSA-wjf7-jjrj-rw8w.json diff --git a/advisories/unreviewed/2024/03/GHSA-pjqv-pvfh-2w6m/GHSA-pjqv-pvfh-2w6m.json b/advisories/unreviewed/2024/03/GHSA-pjqv-pvfh-2w6m/GHSA-pjqv-pvfh-2w6m.json index c35fda29622..48b69584871 100644 --- a/advisories/unreviewed/2024/03/GHSA-pjqv-pvfh-2w6m/GHSA-pjqv-pvfh-2w6m.json +++ b/advisories/unreviewed/2024/03/GHSA-pjqv-pvfh-2w6m/GHSA-pjqv-pvfh-2w6m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pjqv-pvfh-2w6m", - "modified": "2024-04-02T03:30:43Z", + "modified": "2024-04-03T06:30:46Z", "published": "2024-03-27T15:30:37Z", "aliases": [ "CVE-2024-26651" @@ -54,6 +54,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/f546cc19f9b82975238d0ba413adc27714750774" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AXURWFKAKFEIUBN7RTCXI7GZYAHXNBX5" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SI2D7K2T6QCWALKLYEWZ22P4UXMEBCGB" diff --git a/advisories/unreviewed/2024/04/GHSA-2h64-rqxh-72wj/GHSA-2h64-rqxh-72wj.json b/advisories/unreviewed/2024/04/GHSA-2h64-rqxh-72wj/GHSA-2h64-rqxh-72wj.json new file mode 100644 index 00000000000..e760461930f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2h64-rqxh-72wj/GHSA-2h64-rqxh-72wj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2h64-rqxh-72wj", + "modified": "2024-04-03T06:30:47Z", + "published": "2024-04-03T06:30:47Z", + "aliases": [ + "CVE-2024-31013" + ], + "details": "Cross Site Scripting (XSS) vulnerability in emlog version Pro 2.3, allow remote attackers to execute arbitrary code via a crafted payload to the bottom of the homepage in footer_info parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31013" + }, + { + "type": "WEB", + "url": "https://github.com/emlog/emlog/issues/291" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T04:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-53x2-fcg3-m32m/GHSA-53x2-fcg3-m32m.json b/advisories/unreviewed/2024/04/GHSA-53x2-fcg3-m32m/GHSA-53x2-fcg3-m32m.json new file mode 100644 index 00000000000..cbfd755ece4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-53x2-fcg3-m32m/GHSA-53x2-fcg3-m32m.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53x2-fcg3-m32m", + "modified": "2024-04-03T06:30:46Z", + "published": "2024-04-03T06:30:46Z", + "aliases": [ + "CVE-2024-2879" + ], + "details": "The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.11 and 7.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2879" + }, + { + "type": "WEB", + "url": "https://layerslider.com/release-log" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3fddf96e-029c-4753-ba82-043ca64b78d3?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T04:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6xrw-49j6-7f3m/GHSA-6xrw-49j6-7f3m.json b/advisories/unreviewed/2024/04/GHSA-6xrw-49j6-7f3m/GHSA-6xrw-49j6-7f3m.json new file mode 100644 index 00000000000..04deaba31fb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6xrw-49j6-7f3m/GHSA-6xrw-49j6-7f3m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xrw-49j6-7f3m", + "modified": "2024-04-03T06:30:48Z", + "published": "2024-04-03T06:30:48Z", + "aliases": [ + "CVE-2024-31011" + ], + "details": "Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path that was not isolated and the suffix was not verified in admin_template.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31011" + }, + { + "type": "WEB", + "url": "https://github.com/ss122-0ss/beescms/blob/main/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T05:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7mxg-r76p-363g/GHSA-7mxg-r76p-363g.json b/advisories/unreviewed/2024/04/GHSA-7mxg-r76p-363g/GHSA-7mxg-r76p-363g.json new file mode 100644 index 00000000000..128dc633139 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7mxg-r76p-363g/GHSA-7mxg-r76p-363g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mxg-r76p-363g", + "modified": "2024-04-03T06:30:48Z", + "published": "2024-04-03T06:30:48Z", + "aliases": [ + "CVE-2021-27312" + ], + "details": "Server Side Request Forgery (SSRF) vulnerability in Gleez Cms 1.2.0, allows remote attackers to execute arbitrary code and obtain sensitive information via modules/gleez/classes/request.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-27312" + }, + { + "type": "WEB", + "url": "https://github.com/gleez/cms/issues/805" + }, + { + "type": "WEB", + "url": "https://gist.github.com/LioTree/8d10d123d31f50db05a25586e62a87ba" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9h58-5xgm-2682/GHSA-9h58-5xgm-2682.json b/advisories/unreviewed/2024/04/GHSA-9h58-5xgm-2682/GHSA-9h58-5xgm-2682.json new file mode 100644 index 00000000000..953db905cb7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9h58-5xgm-2682/GHSA-9h58-5xgm-2682.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9h58-5xgm-2682", + "modified": "2024-04-03T06:30:47Z", + "published": "2024-04-03T06:30:47Z", + "aliases": [ + "CVE-2024-31010" + ], + "details": "SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Banner.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31010" + }, + { + "type": "WEB", + "url": "https://github.com/ss122-0ss/semcms/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T04:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-gcr2-pc9c-643g/GHSA-gcr2-pc9c-643g.json b/advisories/unreviewed/2024/04/GHSA-gcr2-pc9c-643g/GHSA-gcr2-pc9c-643g.json new file mode 100644 index 00000000000..8d7a8ac20a7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-gcr2-pc9c-643g/GHSA-gcr2-pc9c-643g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcr2-pc9c-643g", + "modified": "2024-04-03T06:30:48Z", + "published": "2024-04-03T06:30:48Z", + "aliases": [ + "CVE-2024-30998" + ], + "details": "SQL Injection vulnerability in PHPGurukul Men Salon Management System v.2.0, allows remote attackers to execute arbitrary code and obtain sensitive information via the email parameter in the index.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30998" + }, + { + "type": "WEB", + "url": "https://github.com/efekaanakkar/CVEs/blob/main/PHPGurukul-Men-Salon-Management-System-2.0.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T06:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p5p6-3j26-j8rh/GHSA-p5p6-3j26-j8rh.json b/advisories/unreviewed/2024/04/GHSA-p5p6-3j26-j8rh/GHSA-p5p6-3j26-j8rh.json new file mode 100644 index 00000000000..b659a36770b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p5p6-3j26-j8rh/GHSA-p5p6-3j26-j8rh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5p6-3j26-j8rh", + "modified": "2024-04-03T06:30:47Z", + "published": "2024-04-03T06:30:47Z", + "aliases": [ + "CVE-2024-31012" + ], + "details": "An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the upload.php file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31012" + }, + { + "type": "WEB", + "url": "https://github.com/ss122-0ss/semcmsv4.8/blob/main/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T04:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rfj8-v7wf-3hfc/GHSA-rfj8-v7wf-3hfc.json b/advisories/unreviewed/2024/04/GHSA-rfj8-v7wf-3hfc/GHSA-rfj8-v7wf-3hfc.json new file mode 100644 index 00000000000..af3368ceff5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rfj8-v7wf-3hfc/GHSA-rfj8-v7wf-3hfc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfj8-v7wf-3hfc", + "modified": "2024-04-03T06:30:48Z", + "published": "2024-04-03T06:30:48Z", + "aliases": [ + "CVE-2024-2322" + ], + "details": "The WooCommerce Cart Abandonment Recovery WordPress plugin before 1.2.27 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admins delete arbitrary email templates as well as delete and unsubscribe users from abandoned orders via CSRF attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2322" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c740ed3b-d6b8-4afc-8c6b-a1ec37597055" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T05:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vrmm-rpmr-vmc8/GHSA-vrmm-rpmr-vmc8.json b/advisories/unreviewed/2024/04/GHSA-vrmm-rpmr-vmc8/GHSA-vrmm-rpmr-vmc8.json new file mode 100644 index 00000000000..b1537b2de74 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vrmm-rpmr-vmc8/GHSA-vrmm-rpmr-vmc8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrmm-rpmr-vmc8", + "modified": "2024-04-03T06:30:47Z", + "published": "2024-04-03T06:30:47Z", + "aliases": [ + "CVE-2024-31009" + ], + "details": "SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via lgid parameter in Banner.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31009" + }, + { + "type": "WEB", + "url": "https://github.com/ss122-0ss/semcms/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T04:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wjf7-jjrj-rw8w/GHSA-wjf7-jjrj-rw8w.json b/advisories/unreviewed/2024/04/GHSA-wjf7-jjrj-rw8w/GHSA-wjf7-jjrj-rw8w.json new file mode 100644 index 00000000000..a8abb49278b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wjf7-jjrj-rw8w/GHSA-wjf7-jjrj-rw8w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjf7-jjrj-rw8w", + "modified": "2024-04-03T06:30:48Z", + "published": "2024-04-03T06:30:48Z", + "aliases": [ + "CVE-2024-31008" + ], + "details": "An issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive information via the index.php file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31008" + }, + { + "type": "WEB", + "url": "https://github.com/majic-banana/vulnerability/blob/main/POC/WUZHICMS4.1.0-Captcha%20bypass%20%28logic%20vulnerability%29.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T06:15:07Z" + } +} \ No newline at end of file