From 1048a18e84d2f3c8d95c4eef910939034271e6aa Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 29 Mar 2023 09:31:52 +0000 Subject: [PATCH] Publish Advisories GHSA-28xp-c478-9qjp GHSA-3223-r5rv-jq9r GHSA-32pp-2qph-whhh GHSA-5mhh-jgxp-w9p8 GHSA-848g-h6v9-26j6 GHSA-859g-44xh-72pq GHSA-fp5w-594q-2cg5 GHSA-gjq7-hxqp-x7cf GHSA-gq7r-qxw5-w38c GHSA-h5g5-ch4q-387c GHSA-j685-gggh-9f7v GHSA-pfr6-hwpr-j396 GHSA-q98q-v2pg-cgx3 GHSA-rqvx-rx9q-529r GHSA-vmw8-9495-f948 GHSA-vvv3-7crr-pxrc GHSA-x8cp-27fq-25p8 --- .../GHSA-28xp-c478-9qjp.json | 43 +++++++++++++++++++ .../GHSA-3223-r5rv-jq9r.json | 9 ++-- .../GHSA-32pp-2qph-whhh.json | 11 +++-- .../GHSA-5mhh-jgxp-w9p8.json | 11 +++-- .../GHSA-848g-h6v9-26j6.json | 9 ++-- .../GHSA-859g-44xh-72pq.json | 9 ++-- .../GHSA-fp5w-594q-2cg5.json | 11 +++-- .../GHSA-gjq7-hxqp-x7cf.json | 35 +++++++++++++++ .../GHSA-gq7r-qxw5-w38c.json | 35 +++++++++++++++ .../GHSA-h5g5-ch4q-387c.json | 11 +++-- .../GHSA-j685-gggh-9f7v.json | 39 +++++++++++++++++ .../GHSA-pfr6-hwpr-j396.json | 9 ++-- .../GHSA-q98q-v2pg-cgx3.json | 9 ++-- .../GHSA-rqvx-rx9q-529r.json | 11 +++-- .../GHSA-vmw8-9495-f948.json | 39 +++++++++++++++++ .../GHSA-vvv3-7crr-pxrc.json | 11 +++-- .../GHSA-x8cp-27fq-25p8.json | 9 ++-- 17 files changed, 269 insertions(+), 42 deletions(-) create mode 100644 advisories/unreviewed/2023/03/GHSA-28xp-c478-9qjp/GHSA-28xp-c478-9qjp.json create mode 100644 advisories/unreviewed/2023/03/GHSA-gjq7-hxqp-x7cf/GHSA-gjq7-hxqp-x7cf.json create mode 100644 advisories/unreviewed/2023/03/GHSA-gq7r-qxw5-w38c/GHSA-gq7r-qxw5-w38c.json create mode 100644 advisories/unreviewed/2023/03/GHSA-j685-gggh-9f7v/GHSA-j685-gggh-9f7v.json create mode 100644 advisories/unreviewed/2023/03/GHSA-vmw8-9495-f948/GHSA-vmw8-9495-f948.json diff --git a/advisories/unreviewed/2023/03/GHSA-28xp-c478-9qjp/GHSA-28xp-c478-9qjp.json b/advisories/unreviewed/2023/03/GHSA-28xp-c478-9qjp/GHSA-28xp-c478-9qjp.json new file mode 100644 index 00000000000..133d3d0be99 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-28xp-c478-9qjp/GHSA-28xp-c478-9qjp.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28xp-c478-9qjp", + "modified": "2023-03-29T09:30:32Z", + "published": "2023-03-29T09:30:32Z", + "aliases": [ + "CVE-2023-1686" + ], + "details": "A vulnerability was found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file bsenordering/admin/category/index.php of the component GET Parameter Handler. The manipulation of the argument view with the input leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224243.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1686" + }, + { + "type": "WEB", + "url": "https://github.com/Apeng96/bug_report/blob/main/XSS-1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.224243" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.224243" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T07:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-3223-r5rv-jq9r/GHSA-3223-r5rv-jq9r.json b/advisories/unreviewed/2023/03/GHSA-3223-r5rv-jq9r/GHSA-3223-r5rv-jq9r.json index 4d1be0d56a8..efd7278a48f 100644 --- a/advisories/unreviewed/2023/03/GHSA-3223-r5rv-jq9r/GHSA-3223-r5rv-jq9r.json +++ b/advisories/unreviewed/2023/03/GHSA-3223-r5rv-jq9r/GHSA-3223-r5rv-jq9r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3223-r5rv-jq9r", - "modified": "2023-03-24T21:30:50Z", + "modified": "2023-03-29T09:30:32Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20953" ], "details": "In onPrimaryClipChanged of ClipboardListener.java, there is a possible way to bypass factory reset protection due to incorrect UI being shown prior to setup completion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251778420", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-32pp-2qph-whhh/GHSA-32pp-2qph-whhh.json b/advisories/unreviewed/2023/03/GHSA-32pp-2qph-whhh/GHSA-32pp-2qph-whhh.json index 113f84ce425..15b7699fdd3 100644 --- a/advisories/unreviewed/2023/03/GHSA-32pp-2qph-whhh/GHSA-32pp-2qph-whhh.json +++ b/advisories/unreviewed/2023/03/GHSA-32pp-2qph-whhh/GHSA-32pp-2qph-whhh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-32pp-2qph-whhh", - "modified": "2023-03-23T21:30:20Z", + "modified": "2023-03-29T09:30:31Z", "published": "2023-03-23T21:30:20Z", "aliases": [ "CVE-2023-1607" ], "details": "A vulnerability was found in novel-plus 3.6.2. It has been classified as critical. This affects an unknown part of the file /common/sysFile/list. The manipulation of the argument sort leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223737 was assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-23T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-5mhh-jgxp-w9p8/GHSA-5mhh-jgxp-w9p8.json b/advisories/unreviewed/2023/03/GHSA-5mhh-jgxp-w9p8/GHSA-5mhh-jgxp-w9p8.json index db920763705..5e19db37955 100644 --- a/advisories/unreviewed/2023/03/GHSA-5mhh-jgxp-w9p8/GHSA-5mhh-jgxp-w9p8.json +++ b/advisories/unreviewed/2023/03/GHSA-5mhh-jgxp-w9p8/GHSA-5mhh-jgxp-w9p8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5mhh-jgxp-w9p8", - "modified": "2023-03-24T21:30:49Z", + "modified": "2023-03-29T09:30:31Z", "published": "2023-03-24T21:30:49Z", "aliases": [ "CVE-2023-20936" ], "details": "In bta_av_rc_disc_done of bta_av_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-226927612", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-848g-h6v9-26j6/GHSA-848g-h6v9-26j6.json b/advisories/unreviewed/2023/03/GHSA-848g-h6v9-26j6/GHSA-848g-h6v9-26j6.json index e7bebf42d2f..44df0bc9552 100644 --- a/advisories/unreviewed/2023/03/GHSA-848g-h6v9-26j6/GHSA-848g-h6v9-26j6.json +++ b/advisories/unreviewed/2023/03/GHSA-848g-h6v9-26j6/GHSA-848g-h6v9-26j6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-848g-h6v9-26j6", - "modified": "2023-03-24T21:30:50Z", + "modified": "2023-03-29T09:30:31Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20929" ], "details": "In sendHalfSheetCancelBroadcast of HalfSheetActivity.java, there is a possible way to learn nearby BT MAC addresses due to an unrestricted broadcast intent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-234442700", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-859g-44xh-72pq/GHSA-859g-44xh-72pq.json b/advisories/unreviewed/2023/03/GHSA-859g-44xh-72pq/GHSA-859g-44xh-72pq.json index 6c4dffd1aa9..cc534e5edcd 100644 --- a/advisories/unreviewed/2023/03/GHSA-859g-44xh-72pq/GHSA-859g-44xh-72pq.json +++ b/advisories/unreviewed/2023/03/GHSA-859g-44xh-72pq/GHSA-859g-44xh-72pq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-859g-44xh-72pq", - "modified": "2023-03-24T21:30:50Z", + "modified": "2023-03-29T09:30:31Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20947" ], "details": "In getGroupState of GrantPermissionsViewModel.kt, there is a possible way to keep a one-time permission granted due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-237405974", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-fp5w-594q-2cg5/GHSA-fp5w-594q-2cg5.json b/advisories/unreviewed/2023/03/GHSA-fp5w-594q-2cg5/GHSA-fp5w-594q-2cg5.json index d156a715276..d9a552d95ba 100644 --- a/advisories/unreviewed/2023/03/GHSA-fp5w-594q-2cg5/GHSA-fp5w-594q-2cg5.json +++ b/advisories/unreviewed/2023/03/GHSA-fp5w-594q-2cg5/GHSA-fp5w-594q-2cg5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fp5w-594q-2cg5", - "modified": "2023-03-23T21:30:20Z", + "modified": "2023-03-29T09:30:31Z", "published": "2023-03-23T21:30:20Z", "aliases": [ "CVE-2023-1609" ], "details": "A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. It has been rated as problematic. This issue affects the function save of the file /api/admin/store/product/save. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223739.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-23T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-gjq7-hxqp-x7cf/GHSA-gjq7-hxqp-x7cf.json b/advisories/unreviewed/2023/03/GHSA-gjq7-hxqp-x7cf/GHSA-gjq7-hxqp-x7cf.json new file mode 100644 index 00000000000..5ca24a39231 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-gjq7-hxqp-x7cf/GHSA-gjq7-hxqp-x7cf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjq7-hxqp-x7cf", + "modified": "2023-03-29T09:30:32Z", + "published": "2023-03-29T09:30:32Z", + "aliases": [ + "CVE-2022-27598" + ], + "details": "A vulnerability have been reported to affect multiple QNAP operating systems. If exploited, the vulnerability allow remote authenticated users to get secret values. The vulnerabilities affect the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) We have already fixed the vulnerabilities in the following operating system versions: QTS 5.0.1.2346 build 20230322 and later QuTS hero h5.0.1.2348 build 20230324 and later", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27598" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T07:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-gq7r-qxw5-w38c/GHSA-gq7r-qxw5-w38c.json b/advisories/unreviewed/2023/03/GHSA-gq7r-qxw5-w38c/GHSA-gq7r-qxw5-w38c.json new file mode 100644 index 00000000000..7b17931de5f --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-gq7r-qxw5-w38c/GHSA-gq7r-qxw5-w38c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq7r-qxw5-w38c", + "modified": "2023-03-29T09:30:32Z", + "published": "2023-03-29T09:30:32Z", + "aliases": [ + "CVE-2022-27597" + ], + "details": "A vulnerability have been reported to affect multiple QNAP operating systems. If exploited, the vulnerability allow remote authenticated users to get secret values. The vulnerabilities affect the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) We have already fixed the vulnerabilities in the following operating system versions: QTS 5.0.1.2346 build 20230322 and later QuTS hero h5.0.1.2348 build 20230324 and later", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-27597" + }, + { + "type": "WEB", + "url": "https://www.qnap.com/en/security-advisory/qsa-23-06" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T07:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-h5g5-ch4q-387c/GHSA-h5g5-ch4q-387c.json b/advisories/unreviewed/2023/03/GHSA-h5g5-ch4q-387c/GHSA-h5g5-ch4q-387c.json index fedb2c6f1ed..3cbef593e6d 100644 --- a/advisories/unreviewed/2023/03/GHSA-h5g5-ch4q-387c/GHSA-h5g5-ch4q-387c.json +++ b/advisories/unreviewed/2023/03/GHSA-h5g5-ch4q-387c/GHSA-h5g5-ch4q-387c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h5g5-ch4q-387c", - "modified": "2023-03-24T12:30:16Z", + "modified": "2023-03-29T09:30:31Z", "published": "2023-03-24T12:30:16Z", "aliases": [ "CVE-2023-27242" ], "details": "SourceCodester Loan Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Type parameter under the Edit Loan Types module.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T12:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-j685-gggh-9f7v/GHSA-j685-gggh-9f7v.json b/advisories/unreviewed/2023/03/GHSA-j685-gggh-9f7v/GHSA-j685-gggh-9f7v.json new file mode 100644 index 00000000000..a36e7591ed9 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-j685-gggh-9f7v/GHSA-j685-gggh-9f7v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j685-gggh-9f7v", + "modified": "2023-03-29T09:30:31Z", + "published": "2023-03-29T09:30:31Z", + "aliases": [ + "CVE-2023-1687" + ], + "details": "A vulnerability classified as problematic has been found in SourceCodester Simple Task Allocation System 1.0. Affected is an unknown function of the file LoginRegistration.php?a=register_user. The manipulation of the argument Fullname leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-224244.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1687" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.224244" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.224244" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T08:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-pfr6-hwpr-j396/GHSA-pfr6-hwpr-j396.json b/advisories/unreviewed/2023/03/GHSA-pfr6-hwpr-j396/GHSA-pfr6-hwpr-j396.json index 00a4bc62460..d0016052cc4 100644 --- a/advisories/unreviewed/2023/03/GHSA-pfr6-hwpr-j396/GHSA-pfr6-hwpr-j396.json +++ b/advisories/unreviewed/2023/03/GHSA-pfr6-hwpr-j396/GHSA-pfr6-hwpr-j396.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pfr6-hwpr-j396", - "modified": "2023-03-24T21:30:49Z", + "modified": "2023-03-29T09:30:31Z", "published": "2023-03-24T21:30:49Z", "aliases": [ "CVE-2023-20917" ], "details": "In onTargetSelected of ResolverActivity.java, there is a possible way to share a wrong file due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-242605257", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-q98q-v2pg-cgx3/GHSA-q98q-v2pg-cgx3.json b/advisories/unreviewed/2023/03/GHSA-q98q-v2pg-cgx3/GHSA-q98q-v2pg-cgx3.json index 235e21e9718..8403f61f7a3 100644 --- a/advisories/unreviewed/2023/03/GHSA-q98q-v2pg-cgx3/GHSA-q98q-v2pg-cgx3.json +++ b/advisories/unreviewed/2023/03/GHSA-q98q-v2pg-cgx3/GHSA-q98q-v2pg-cgx3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q98q-v2pg-cgx3", - "modified": "2023-03-14T06:30:16Z", + "modified": "2023-03-29T09:30:32Z", "published": "2023-03-14T06:30:16Z", "aliases": [ "CVE-2023-27893" ], "details": "An attacker authenticated as a user with a non-administrative role and a common remote execution authorization in SAP Solution Manager and ABAP managed systems (ST-PI) - versions 2088_1_700, 2008_1_710, 740, can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can read or modify any user or application data and can make the application unavailable.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-14T06:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-rqvx-rx9q-529r/GHSA-rqvx-rx9q-529r.json b/advisories/unreviewed/2023/03/GHSA-rqvx-rx9q-529r/GHSA-rqvx-rx9q-529r.json index 5065db4fbe9..8ba603718c6 100644 --- a/advisories/unreviewed/2023/03/GHSA-rqvx-rx9q-529r/GHSA-rqvx-rx9q-529r.json +++ b/advisories/unreviewed/2023/03/GHSA-rqvx-rx9q-529r/GHSA-rqvx-rx9q-529r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rqvx-rx9q-529r", - "modified": "2023-03-24T21:30:50Z", + "modified": "2023-03-29T09:30:32Z", "published": "2023-03-24T21:30:50Z", "aliases": [ "CVE-2023-20951" ], "details": "In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-258652631", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-vmw8-9495-f948/GHSA-vmw8-9495-f948.json b/advisories/unreviewed/2023/03/GHSA-vmw8-9495-f948/GHSA-vmw8-9495-f948.json new file mode 100644 index 00000000000..50ba54c50b9 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-vmw8-9495-f948/GHSA-vmw8-9495-f948.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmw8-9495-f948", + "modified": "2023-03-29T09:30:31Z", + "published": "2023-03-29T09:30:31Z", + "aliases": [ + "CVE-2023-1688" + ], + "details": "A vulnerability classified as problematic has been found in SourceCodester Earnings and Expense Tracker App 1.0. This affects an unknown part of the file Master.php?a=save_expense. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-224307.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1688" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.224307" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.224307" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T09:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-vvv3-7crr-pxrc/GHSA-vvv3-7crr-pxrc.json b/advisories/unreviewed/2023/03/GHSA-vvv3-7crr-pxrc/GHSA-vvv3-7crr-pxrc.json index 55df605ddbe..6205cd99f4f 100644 --- a/advisories/unreviewed/2023/03/GHSA-vvv3-7crr-pxrc/GHSA-vvv3-7crr-pxrc.json +++ b/advisories/unreviewed/2023/03/GHSA-vvv3-7crr-pxrc/GHSA-vvv3-7crr-pxrc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vvv3-7crr-pxrc", - "modified": "2023-03-23T18:30:19Z", + "modified": "2023-03-29T09:30:32Z", "published": "2023-03-23T18:30:19Z", "aliases": [ "CVE-2022-28496" ], "details": "TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswordCfg function via the adminuser and adminpassparameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-23T17:15:00Z" diff --git a/advisories/unreviewed/2023/03/GHSA-x8cp-27fq-25p8/GHSA-x8cp-27fq-25p8.json b/advisories/unreviewed/2023/03/GHSA-x8cp-27fq-25p8/GHSA-x8cp-27fq-25p8.json index 22d9e035c37..bbccafffcb4 100644 --- a/advisories/unreviewed/2023/03/GHSA-x8cp-27fq-25p8/GHSA-x8cp-27fq-25p8.json +++ b/advisories/unreviewed/2023/03/GHSA-x8cp-27fq-25p8/GHSA-x8cp-27fq-25p8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x8cp-27fq-25p8", - "modified": "2023-03-24T21:30:49Z", + "modified": "2023-03-29T09:30:32Z", "published": "2023-03-24T21:30:49Z", "aliases": [ "CVE-2023-20906" ], "details": "In onPackageAddedInternal of PermissionManagerService.java, there is a possible way to silently grant a permission after a Target SDK update due to a permissions bypass. This could lead to local escalation of privilege after updating an app to a higher Target SDK with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-221040577", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-03-24T20:15:00Z"