Publish Advisories

GHSA-vgrx-vhjf-p7wv
GHSA-393j-fpg3-h6c9
GHSA-fxgj-cfm7-w8hw
GHSA-h2w6-c2hx-7jcf
GHSA-jc9g-7x7r-c8w7
GHSA-mvh5-v533-3v55
GHSA-q8jx-8wr3-gv52
GHSA-x748-g8vm-gmhw
GHSA-657j-69g5-mr77
GHSA-jhvx-96xq-qggm
GHSA-659h-jrcq-w3wg
GHSA-6pc8-5263-hvgq
GHSA-7xmw-644w-wp3m
GHSA-mjhr-3845-j2r5
This commit is contained in:
advisory-database[bot]
2025-02-27 00:31:51 +00:00
parent 8a2736e9bd
commit 10ce279920
14 changed files with 156 additions and 15 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vgrx-vhjf-p7wv",
"modified": "2023-03-21T21:30:19Z",
"modified": "2025-02-27T00:30:24Z",
"published": "2023-03-15T21:30:25Z",
"aliases": [
"CVE-2023-28450"
@@ -23,6 +23,14 @@
"type": "WEB",
"url": "https://capec.mitre.org/data/definitions/495.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6UQ6LKDTLSSD64TBIZ3XEKBM2SWC63VV"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OU2ZT4ITSEOOR2CFBAHK4Z67KXJIEWQA"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6UQ6LKDTLSSD64TBIZ3XEKBM2SWC63VV"
@@ -35,6 +43,14 @@
"type": "WEB",
"url": "https://thekelleys.org.uk/dnsmasq/doc.html"
},
{
"type": "WEB",
"url": "https://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=blob%3Bf=CHANGELOG"
},
{
"type": "WEB",
"url": "https://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commit%3Bh=eb92fb32b746f2104b0f370b5b295bb8dd4bd5e5"
},
{
"type": "WEB",
"url": "https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=blob;f=CHANGELOG"
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-393j-fpg3-h6c9",
"modified": "2023-11-10T06:30:18Z",
"modified": "2025-02-27T00:30:25Z",
"published": "2023-11-06T09:30:15Z",
"aliases": [
"CVE-2023-45074"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter Most Wanted Analytics Plugin for WordPress allows SQL Injection.This issue affects Advanced Page Visit Counter Most Wanted Analytics Plugin for WordPress: from n/a through 7.1.1.\n\n",
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter Most Wanted Analytics Plugin for WordPress allows SQL Injection.This issue affects Advanced Page Visit Counter Most Wanted Analytics Plugin for WordPress: from n/a through 7.1.1.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fxgj-cfm7-w8hw",
"modified": "2024-10-10T18:31:07Z",
"modified": "2025-02-27T00:30:26Z",
"published": "2023-11-09T15:30:30Z",
"aliases": [
"CVE-2023-4612"
],
"details": "Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the vendor does not treat it as a vulnerability.\n\n\n\n\n\n\n\n\n",
"details": "Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the vendor does not treat it as a vulnerability.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h2w6-c2hx-7jcf",
"modified": "2023-11-10T06:30:18Z",
"modified": "2025-02-27T00:30:25Z",
"published": "2023-11-06T09:30:15Z",
"aliases": [
"CVE-2023-45069"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Video Gallery by Total-Soft Video Gallery Best WordPress YouTube Gallery Plugin allows SQL Injection.This issue affects Video Gallery Best WordPress YouTube Gallery Plugin: from n/a through 2.1.3.\n\n",
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Video Gallery by Total-Soft Video Gallery Best WordPress YouTube Gallery Plugin allows SQL Injection.This issue affects Video Gallery Best WordPress YouTube Gallery Plugin: from n/a through 2.1.3.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jc9g-7x7r-c8w7",
"modified": "2023-11-14T18:30:22Z",
"modified": "2025-02-27T00:30:25Z",
"published": "2023-11-06T12:30:24Z",
"aliases": [
"CVE-2023-46823"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum ImageLinks Interactive Image Builder for WordPress allows SQL Injection.This issue affects ImageLinks Interactive Image Builder for WordPress: from n/a through 1.5.4.\n\n",
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum ImageLinks Interactive Image Builder for WordPress allows SQL Injection.This issue affects ImageLinks Interactive Image Builder for WordPress: from n/a through 1.5.4.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mvh5-v533-3v55",
"modified": "2023-11-10T06:30:18Z",
"modified": "2025-02-27T00:30:25Z",
"published": "2023-11-06T09:30:15Z",
"aliases": [
"CVE-2023-35911"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Creative Solutions Contact Form Generator : Creative form builder for WordPress allows SQL Injection.This issue affects Contact Form Generator : Creative form builder for WordPress: from n/a through 2.6.0.\n\n",
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Creative Solutions Contact Form Generator : Creative form builder for WordPress allows SQL Injection.This issue affects Contact Form Generator : Creative form builder for WordPress: from n/a through 2.6.0.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q8jx-8wr3-gv52",
"modified": "2024-11-13T00:30:47Z",
"modified": "2025-02-27T00:30:25Z",
"published": "2023-11-06T06:30:26Z",
"aliases": [
"CVE-2023-4699"
],
"details": "Insufficient Verification of Data Authenticity vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules and MELSEC iQ-F Series CPU modules allows a remote unauthenticated attacker to reset the memory of the products to factory default state and cause denial-of-service (DoS) condition on the products by sending specific packets.\n\n\n\n\n\n\n",
"details": "Insufficient Verification of Data Authenticity vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules and MELSEC iQ-F Series CPU modules allows a remote unauthenticated attacker to reset the memory of the products to factory default state and cause denial-of-service (DoS) condition on the products by sending specific packets.",
"severity": [
{
"type": "CVSS_V3",
@@ -27,6 +27,7 @@
"database_specific": {
"cwe_ids": [
"CWE-284",
"CWE-683",
"CWE-863"
],
"severity": "MODERATE",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-657j-69g5-mr77",
"modified": "2024-05-23T06:30:45Z",
"modified": "2025-02-27T00:30:26Z",
"published": "2024-05-23T06:30:45Z",
"aliases": [
"CVE-2024-5235"
@@ -11,6 +11,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jhvx-96xq-qggm",
"modified": "2024-05-23T06:30:45Z",
"modified": "2025-02-27T00:30:26Z",
"published": "2024-05-23T06:30:45Z",
"aliases": [
"CVE-2024-5236"
@@ -11,6 +11,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
@@ -0,0 +1,25 @@
{
"schema_version": "1.4.0",
"id": "GHSA-659h-jrcq-w3wg",
"modified": "2025-02-27T00:30:27Z",
"published": "2025-02-27T00:30:27Z",
"aliases": [
"CVE-2025-1460"
],
"details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1460"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-26T23:15:10Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6pc8-5263-hvgq",
"modified": "2025-02-27T00:30:27Z",
"published": "2025-02-27T00:30:26Z",
"aliases": [
"CVE-2024-55581"
],
"details": "When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55581"
},
{
"type": "WEB",
"url": "https://docs.adacore.com/corp/security-advisories/SEC.AWS-0056-v1.pdf"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-26T22:15:14Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7xmw-644w-wp3m",
"modified": "2025-02-27T00:30:27Z",
"published": "2025-02-27T00:30:27Z",
"aliases": [
"CVE-2024-53573"
],
"details": "Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints intended exclusively for administrative use. This issue specifically affects teacher/edit/{id}.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53573"
},
{
"type": "WEB",
"url": "https://drive.google.com/file/d/14Or6QIpOeLEqdFm1mwxdE_NNCOwMmcFc/view"
},
{
"type": "WEB",
"url": "https://www.getastra.com/blog/vulnerability/improper-access-control-in-school-management-system-unifiedtransform"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-26T22:15:14Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mjhr-3845-j2r5",
"modified": "2025-02-27T00:30:27Z",
"published": "2025-02-27T00:30:27Z",
"aliases": [
"CVE-2024-57040"
],
"details": "TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded password for the root account which can be obtained via a brute force attack.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57040"
},
{
"type": "WEB",
"url": "https://security.iiita.ac.in/iot/hashed_password.pdf"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-26T22:15:14Z"
}
}