diff --git a/advisories/github-reviewed/2017/10/GHSA-5vx5-9q73-wgp4/GHSA-5vx5-9q73-wgp4.json b/advisories/github-reviewed/2017/10/GHSA-5vx5-9q73-wgp4/GHSA-5vx5-9q73-wgp4.json index e83d211cd19..21c40dbd809 100644 --- a/advisories/github-reviewed/2017/10/GHSA-5vx5-9q73-wgp4/GHSA-5vx5-9q73-wgp4.json +++ b/advisories/github-reviewed/2017/10/GHSA-5vx5-9q73-wgp4/GHSA-5vx5-9q73-wgp4.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-5vx5-9q73-wgp4", - "modified": "2023-01-26T20:24:55Z", + "modified": "2023-09-05T21:30:18Z", "published": "2017-10-24T18:33:35Z", "aliases": [ "CVE-2017-7540" ], - "summary": "safemode has Incomplete List of Disallowed Inputs", + "summary": "Safemode Gem Has Incomplete List of Disallowed Inputs", "details": "rubygem-safemode, as used in Foreman, versions 1.3.1 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax. This can lead to deletion of objects for which the user does not have delete permissions or possibly to privilege escalation.", "severity": [ { @@ -20,6 +20,11 @@ "ecosystem": "RubyGems", "name": "safemode" }, + "ecosystem_specific": { + "affected_functions": [ + "" + ] + }, "ranges": [ { "type": "ECOSYSTEM", diff --git a/advisories/unreviewed/2023/08/GHSA-4wfg-7c3p-cjr8/GHSA-4wfg-7c3p-cjr8.json b/advisories/unreviewed/2023/08/GHSA-4wfg-7c3p-cjr8/GHSA-4wfg-7c3p-cjr8.json index 8591b553d2a..72e52b1aa6a 100644 --- a/advisories/unreviewed/2023/08/GHSA-4wfg-7c3p-cjr8/GHSA-4wfg-7c3p-cjr8.json +++ b/advisories/unreviewed/2023/08/GHSA-4wfg-7c3p-cjr8/GHSA-4wfg-7c3p-cjr8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4wfg-7c3p-cjr8", - "modified": "2023-08-31T06:30:16Z", + "modified": "2023-09-05T21:30:20Z", "published": "2023-08-31T06:30:16Z", "aliases": [ "CVE-2023-2188" diff --git a/advisories/unreviewed/2023/08/GHSA-5ghx-2vfx-7347/GHSA-5ghx-2vfx-7347.json b/advisories/unreviewed/2023/08/GHSA-5ghx-2vfx-7347/GHSA-5ghx-2vfx-7347.json index 676393df6b3..d78899f1eb3 100644 --- a/advisories/unreviewed/2023/08/GHSA-5ghx-2vfx-7347/GHSA-5ghx-2vfx-7347.json +++ b/advisories/unreviewed/2023/08/GHSA-5ghx-2vfx-7347/GHSA-5ghx-2vfx-7347.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-306" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-9hqp-4cqc-x83x/GHSA-9hqp-4cqc-x83x.json b/advisories/unreviewed/2023/08/GHSA-9hqp-4cqc-x83x/GHSA-9hqp-4cqc-x83x.json index c5556d9053d..07f44aafd51 100644 --- a/advisories/unreviewed/2023/08/GHSA-9hqp-4cqc-x83x/GHSA-9hqp-4cqc-x83x.json +++ b/advisories/unreviewed/2023/08/GHSA-9hqp-4cqc-x83x/GHSA-9hqp-4cqc-x83x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9hqp-4cqc-x83x", - "modified": "2023-08-29T21:30:21Z", + "modified": "2023-09-05T21:30:20Z", "published": "2023-08-29T21:30:21Z", "aliases": [ "CVE-2021-3262" ], "details": "TripSpark VEO Transportation-2.2.x-XP_BB-20201123-184084 NovusEDU-2.2.x-XP_BB-20201123-184084 allows unsafe data inputs in POST body parameters from end users without sanitizing using server-side logic. It was possible to inject custom SQL commands into the \"Student Busing Information\" search queries.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-c7ff-rpgp-8q7p/GHSA-c7ff-rpgp-8q7p.json b/advisories/unreviewed/2023/08/GHSA-c7ff-rpgp-8q7p/GHSA-c7ff-rpgp-8q7p.json index ea8feffae1a..7dd416a976d 100644 --- a/advisories/unreviewed/2023/08/GHSA-c7ff-rpgp-8q7p/GHSA-c7ff-rpgp-8q7p.json +++ b/advisories/unreviewed/2023/08/GHSA-c7ff-rpgp-8q7p/GHSA-c7ff-rpgp-8q7p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c7ff-rpgp-8q7p", - "modified": "2023-08-30T15:30:18Z", + "modified": "2023-09-05T21:30:20Z", "published": "2023-08-30T15:30:18Z", "aliases": [ "CVE-2023-27426" diff --git a/advisories/unreviewed/2023/08/GHSA-fgpx-5352-x7c3/GHSA-fgpx-5352-x7c3.json b/advisories/unreviewed/2023/08/GHSA-fgpx-5352-x7c3/GHSA-fgpx-5352-x7c3.json index 6d536e61d4b..7acda217287 100644 --- a/advisories/unreviewed/2023/08/GHSA-fgpx-5352-x7c3/GHSA-fgpx-5352-x7c3.json +++ b/advisories/unreviewed/2023/08/GHSA-fgpx-5352-x7c3/GHSA-fgpx-5352-x7c3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fgpx-5352-x7c3", - "modified": "2023-08-31T00:30:17Z", + "modified": "2023-09-05T21:30:20Z", "published": "2023-08-31T00:30:17Z", "aliases": [ "CVE-2023-41163" ], "details": "A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the replace in results field while replacing the results under the tools drop down.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-q4c3-fmw8-m6gp/GHSA-q4c3-fmw8-m6gp.json b/advisories/unreviewed/2023/08/GHSA-q4c3-fmw8-m6gp/GHSA-q4c3-fmw8-m6gp.json index f18b1713773..b8037c6d15c 100644 --- a/advisories/unreviewed/2023/08/GHSA-q4c3-fmw8-m6gp/GHSA-q4c3-fmw8-m6gp.json +++ b/advisories/unreviewed/2023/08/GHSA-q4c3-fmw8-m6gp/GHSA-q4c3-fmw8-m6gp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q4c3-fmw8-m6gp", - "modified": "2023-08-29T18:31:53Z", + "modified": "2023-09-05T21:30:19Z", "published": "2023-08-29T18:31:53Z", "aliases": [ "CVE-2023-41376" ], "details": "Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update-fault-tolerance is not enabled, mishandle BGP path attributes.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/09/GHSA-3w23-96r5-5vc2/GHSA-3w23-96r5-5vc2.json b/advisories/unreviewed/2023/09/GHSA-3w23-96r5-5vc2/GHSA-3w23-96r5-5vc2.json new file mode 100644 index 00000000000..9b2ca09b0cf --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-3w23-96r5-5vc2/GHSA-3w23-96r5-5vc2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w23-96r5-5vc2", + "modified": "2023-09-05T21:30:20Z", + "published": "2023-09-05T21:30:20Z", + "aliases": [ + "CVE-2023-4178" + ], + "details": "Authentication Bypass by Spoofing vulnerability in Neutron Neutron Smart VMS allows Authentication Bypass.This issue affects Neutron Smart VMS: before b1130.1.0.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4178" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-23-0496" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-7q7j-jq8x-xcjh/GHSA-7q7j-jq8x-xcjh.json b/advisories/unreviewed/2023/09/GHSA-7q7j-jq8x-xcjh/GHSA-7q7j-jq8x-xcjh.json new file mode 100644 index 00000000000..e48eca9b3dd --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-7q7j-jq8x-xcjh/GHSA-7q7j-jq8x-xcjh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q7j-jq8x-xcjh", + "modified": "2023-09-05T21:30:21Z", + "published": "2023-09-05T21:30:21Z", + "aliases": [ + "CVE-2023-4310" + ], + "details": "BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of this vulnerability can allow an unauthenticated remote attacker to execute underlying operating system commands within the context of the site user. This issue is fixed in version 23.2.3.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4310" + }, + { + "type": "WEB", + "url": "https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sysparm_article=KB0020207" + }, + { + "type": "WEB", + "url": "https://www.beyondtrust.com/blog/entry/security-update-for-remote-support-and-privileged-remote-access" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-8hxx-8cjf-cxvg/GHSA-8hxx-8cjf-cxvg.json b/advisories/unreviewed/2023/09/GHSA-8hxx-8cjf-cxvg/GHSA-8hxx-8cjf-cxvg.json new file mode 100644 index 00000000000..c269b73be02 --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-8hxx-8cjf-cxvg/GHSA-8hxx-8cjf-cxvg.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hxx-8cjf-cxvg", + "modified": "2023-09-05T21:30:20Z", + "published": "2023-09-05T21:30:20Z", + "aliases": [ + "CVE-2020-35593" + ], + "details": "BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -host.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35593" + }, + { + "type": "WEB", + "url": "https://community.bmc.com/s/article/SECURITY-Patrol-Agent-Local-Privilege-Escalation-in-BMC-PATROL-Agent-CVE-2020-35593" + }, + { + "type": "WEB", + "url": "https://webapps.bmc.com/support/faces/az/prodallversions.jsp?seqid=304517" + }, + { + "type": "WEB", + "url": "https://www.securifera.com/advisories/" + }, + { + "type": "WEB", + "url": "https://www.securifera.com/blog/2021/03/08/bmc-patrol-agent-domain-user-to-domain-admin-part-2/" + }, + { + "type": "WEB", + "url": "http://web.archive.org/web/20210106175128/https://community.bmc.com/s/article/SECURITY-Patrol-Agent-Local-Privilege-Escalation-in-BMC-PATROL-Agent-CVE-2020-35593" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-8p84-86q8-2m7m/GHSA-8p84-86q8-2m7m.json b/advisories/unreviewed/2023/09/GHSA-8p84-86q8-2m7m/GHSA-8p84-86q8-2m7m.json new file mode 100644 index 00000000000..28180ccf069 --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-8p84-86q8-2m7m/GHSA-8p84-86q8-2m7m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p84-86q8-2m7m", + "modified": "2023-09-05T21:30:20Z", + "published": "2023-09-05T21:30:20Z", + "aliases": [ + "CVE-2023-4531" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestav Software E-commerce Software allows SQL Injection.This issue affects E-commerce Software: before 20230901 .\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4531" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-23-0495" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-8wpj-m327-rr2w/GHSA-8wpj-m327-rr2w.json b/advisories/unreviewed/2023/09/GHSA-8wpj-m327-rr2w/GHSA-8wpj-m327-rr2w.json new file mode 100644 index 00000000000..fee48ac4456 --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-8wpj-m327-rr2w/GHSA-8wpj-m327-rr2w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wpj-m327-rr2w", + "modified": "2023-09-05T21:30:20Z", + "published": "2023-09-05T21:30:20Z", + "aliases": [ + "CVE-2023-39654" + ], + "details": "abupy up to v0.4.0 was discovered to contain a SQL injection vulnerability via the component abupy.MarketBu.ABuSymbol.search_to_symbol_dict.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39654" + }, + { + "type": "WEB", + "url": "https://github.com/Leeyangee/leeya_bug/blob/main/%5BWarning%5DSQL%20Injection%20in%20abupy%20%3C=%20v0.4.0.md" + }, + { + "type": "WEB", + "url": "https://github.com/bbfamily/abu" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-ffxx-53hq-vq75/GHSA-ffxx-53hq-vq75.json b/advisories/unreviewed/2023/09/GHSA-ffxx-53hq-vq75/GHSA-ffxx-53hq-vq75.json new file mode 100644 index 00000000000..d70a875cadc --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-ffxx-53hq-vq75/GHSA-ffxx-53hq-vq75.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffxx-53hq-vq75", + "modified": "2023-09-05T21:30:21Z", + "published": "2023-09-05T21:30:21Z", + "aliases": [ + "CVE-2023-41508" + ], + "details": "A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41508" + }, + { + "type": "WEB", + "url": "https://github.com/redblueteam/CVE-2023-41508/" + }, + { + "type": "WEB", + "url": "https://superstorefinder.net/support/forums/topic/super-store-finder-patch-notes/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-h9w3-rpx7-pwpc/GHSA-h9w3-rpx7-pwpc.json b/advisories/unreviewed/2023/09/GHSA-h9w3-rpx7-pwpc/GHSA-h9w3-rpx7-pwpc.json new file mode 100644 index 00000000000..d9064e81929 --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-h9w3-rpx7-pwpc/GHSA-h9w3-rpx7-pwpc.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9w3-rpx7-pwpc", + "modified": "2023-09-05T21:30:20Z", + "published": "2023-09-05T21:30:20Z", + "aliases": [ + "CVE-2023-41009" + ], + "details": "File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted script to the authorization field in the header.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41009" + }, + { + "type": "WEB", + "url": "https://github.com/Rabb1tQ/HillstoneCVEs/blob/main/CVE-2023-41009/CVE-2023-41009.md" + }, + { + "type": "WEB", + "url": "https://github.com/adlered/bolo-solo" + }, + { + "type": "WEB", + "url": "http://adlered.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-hvfg-rr99-vxgg/GHSA-hvfg-rr99-vxgg.json b/advisories/unreviewed/2023/09/GHSA-hvfg-rr99-vxgg/GHSA-hvfg-rr99-vxgg.json new file mode 100644 index 00000000000..b4082309940 --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-hvfg-rr99-vxgg/GHSA-hvfg-rr99-vxgg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvfg-rr99-vxgg", + "modified": "2023-09-05T21:30:20Z", + "published": "2023-09-05T21:30:20Z", + "aliases": [ + "CVE-2023-4781" + ], + "details": "Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4781" + }, + { + "type": "WEB", + "url": "https://github.com/vim/vim/commit/f6d28fe2c95c678cc3202cc5dc825a3fcc709e93" + }, + { + "type": "WEB", + "url": "https://huntr.dev/bounties/c867eb0a-aa8b-4946-a621-510350673883" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-mf93-hqq3-h8xg/GHSA-mf93-hqq3-h8xg.json b/advisories/unreviewed/2023/09/GHSA-mf93-hqq3-h8xg/GHSA-mf93-hqq3-h8xg.json new file mode 100644 index 00000000000..73dcedc86bd --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-mf93-hqq3-h8xg/GHSA-mf93-hqq3-h8xg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf93-hqq3-h8xg", + "modified": "2023-09-05T21:30:20Z", + "published": "2023-09-05T21:30:20Z", + "aliases": [ + "CVE-2021-40546" + ], + "details": "Tenda AC6 US_AC6V4.0RTL_V02.03.01.26_cn.bin allows attackers (who have the administrator password) to cause a denial of service (device crash) via a long string in the wifiPwd_5G parameter to /goform/setWifi.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-40546" + }, + { + "type": "WEB", + "url": "https://github.com/doudoudedi/buffer_overflow/blob/main/Tenda%20AC6%20V4.0-Denial%20of%20Service%20Vulnerability.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-pgw9-9vq7-fw2c/GHSA-pgw9-9vq7-fw2c.json b/advisories/unreviewed/2023/09/GHSA-pgw9-9vq7-fw2c/GHSA-pgw9-9vq7-fw2c.json new file mode 100644 index 00000000000..df12388e2b1 --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-pgw9-9vq7-fw2c/GHSA-pgw9-9vq7-fw2c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgw9-9vq7-fw2c", + "modified": "2023-09-05T21:30:20Z", + "published": "2023-09-05T21:30:20Z", + "aliases": [ + "CVE-2020-10128" + ], + "details": "SearchBlox product with version before 9.2.1 is vulnerable to stored cross-site scripting at multiple user input parameters. In SearchBlox products multiple parameters are not sanitized/validate properly which allows an attacker to inject malicious JavaScript.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-10128" + }, + { + "type": "WEB", + "url": "https://developer.searchblox.com/v9.2/changelog/version-921" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/09/GHSA-xhhw-26mm-7pmg/GHSA-xhhw-26mm-7pmg.json b/advisories/unreviewed/2023/09/GHSA-xhhw-26mm-7pmg/GHSA-xhhw-26mm-7pmg.json new file mode 100644 index 00000000000..0e6867a0699 --- /dev/null +++ b/advisories/unreviewed/2023/09/GHSA-xhhw-26mm-7pmg/GHSA-xhhw-26mm-7pmg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhhw-26mm-7pmg", + "modified": "2023-09-05T21:30:20Z", + "published": "2023-09-05T21:30:20Z", + "aliases": [ + "CVE-2023-4034" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digita Information Technology Smartrise Document Management System allows SQL Injection.This issue affects Smartrise Document Management System: before Hvl-2.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4034" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-23-0494" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file