Publish Advisories

GHSA-2jvx-3h5f-w2j7
GHSA-7f2q-q825-57p8
GHSA-3r8p-3x67-72v8
GHSA-23wq-qm4c-6497
GHSA-2g4v-8vvw-r8m9
GHSA-34x7-h5wm-79jf
GHSA-43wj-hwhg-9h4m
GHSA-4cqv-cv9m-26q8
GHSA-5rj5-w87x-2r8m
GHSA-8mgc-gvxr-fgch
GHSA-8wv3-qwhx-w2cj
GHSA-952j-g655-5gm9
GHSA-cvph-c7fw-4mjc
GHSA-grq4-g85p-x45c
GHSA-pcgg-6f95-wg8g
GHSA-qr63-7f35-4m2w
GHSA-v3rc-5q86-wwq8
GHSA-w54f-vq4c-7637
GHSA-xggx-88w4-2942
This commit is contained in:
advisory-database[bot]
2024-06-26 21:33:39 +00:00
parent 5b4f410bec
commit 10d86e38e7
19 changed files with 589 additions and 3 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2jvx-3h5f-w2j7",
"modified": "2023-11-15T21:35:08Z",
"modified": "2024-06-26T21:32:15Z",
"published": "2023-11-15T21:35:08Z",
"aliases": [
"CVE-2023-6105"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6105"
},
{
"type": "WEB",
"url": "https://www.manageengine.com/security/advisory/CVE/CVE-2023-6105.html"
},
{
"type": "WEB",
"url": "https://www.tenable.com/security/research/tra-2023-35"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7f2q-q825-57p8",
"modified": "2023-11-22T00:30:21Z",
"modified": "2024-06-26T21:32:15Z",
"published": "2023-11-22T00:30:21Z",
"aliases": [
"CVE-2023-49103"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3r8p-3x67-72v8",
"modified": "2023-12-05T18:30:23Z",
"modified": "2024-06-26T21:32:16Z",
"published": "2023-12-05T18:30:23Z",
"aliases": [
"CVE-2023-6448"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-23wq-qm4c-6497",
"modified": "2024-06-26T21:32:18Z",
"published": "2024-06-26T21:32:18Z",
"aliases": [
"CVE-2024-39242"
],
"details": "A cross-site scripting (XSS) vulnerability in skycaiji v2.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload using eval(String.fromCharCode()).",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39242"
},
{
"type": "WEB",
"url": "https://fushuling.com/index.php/2024/06/13/test2"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T20:15:16Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2g4v-8vvw-r8m9",
"modified": "2024-06-26T21:32:18Z",
"published": "2024-06-26T21:32:18Z",
"aliases": [
"CVE-2024-39243"
],
"details": "An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/admin/develop/editor_save.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39243"
},
{
"type": "WEB",
"url": "https://fushuling.com/index.php/2024/06/11/test"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T20:15:16Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-34x7-h5wm-79jf",
"modified": "2024-06-26T21:32:16Z",
"published": "2024-06-26T21:32:16Z",
"aliases": [
"CVE-2024-33327"
],
"details": "A cross-site scripting (XSS) vulnerability in the component UrlAccessibilityEvaluation.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the contentHtml parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33327"
},
{
"type": "WEB",
"url": "https://gist.github.com/rodnt/c53d4c95bb6966f0a2cf381ae5089c79"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T19:15:13Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-43wj-hwhg-9h4m",
"modified": "2024-06-26T21:32:18Z",
"published": "2024-06-26T21:32:18Z",
"aliases": [
"CVE-2024-1839"
],
"details": "Intrado 911 Emergency Gateway login form is vulnerable to an unauthenticated blind time-based SQL injection, which may allow an unauthenticated remote attacker to execute malicious code, exfiltrate data, or manipulate the database.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1839"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-163-04"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T21:15:12Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4cqv-cv9m-26q8",
"modified": "2024-06-26T21:32:18Z",
"published": "2024-06-26T21:32:18Z",
"aliases": [
"CVE-2024-23766"
],
"details": "An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes a web interface on port 80. An unauthenticated GET request to a specific URL triggers the reboot of the Anybus gateway (or at least most of its modules). An attacker can use this feature to carry out a denial of service attack by continuously sending GET requests to that URL.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23766"
},
{
"type": "WEB",
"url": "https://sensepost.com/blog/2024/targeting-an-industrial-protocol-gateway"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T21:15:12Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5rj5-w87x-2r8m",
"modified": "2024-06-26T21:32:19Z",
"published": "2024-06-26T21:32:19Z",
"aliases": [
"CVE-2024-6355"
],
"details": "A vulnerability was found in Genexis Tilgin Fiber Home Gateway HG1522 CSx000-01_09_01_12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /status/product_info/. The manipulation of the argument product_info leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269755. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6355"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.269755"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.269755"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.359289"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T21:15:13Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8mgc-gvxr-fgch",
"modified": "2024-06-26T21:32:16Z",
"published": "2024-06-26T21:32:16Z",
"aliases": [
"CVE-2024-33328"
],
"details": "A cross-site scripting (XSS) vulnerability in the component main.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the pageId parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33328"
},
{
"type": "WEB",
"url": "https://gist.github.com/rodnt/cf2946b0f6136cd03ee4737aa72ae95b"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T19:15:13Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8wv3-qwhx-w2cj",
"modified": "2024-06-26T21:32:18Z",
"published": "2024-06-26T21:32:18Z",
"aliases": [
"CVE-2024-23765"
],
"details": "An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes an unidentified service on port 7412 on the network. All the network services of the gateway become unresponsive after sending 85 requests to this port. The content and length of the frame does not matter. The device needs to be restarted to resume operations.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23765"
},
{
"type": "WEB",
"url": "https://sensepost.com/blog/2024/targeting-an-industrial-protocol-gateway"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T21:15:12Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-952j-g655-5gm9",
"modified": "2024-06-26T21:32:17Z",
"published": "2024-06-26T21:32:17Z",
"aliases": [
"CVE-2024-39241"
],
"details": "Cross Site Scripting (XSS) vulnerability in skycaiji 2.8 allows attackers to run arbitrary code via /admin/tool/preview.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39241"
},
{
"type": "WEB",
"url": "https://fushuling.com/index.php/2024/06/19/test3"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T20:15:16Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cvph-c7fw-4mjc",
"modified": "2024-06-26T21:32:17Z",
"published": "2024-06-26T21:32:17Z",
"aliases": [
"CVE-2024-38950"
],
"details": "Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38950"
},
{
"type": "WEB",
"url": "https://github.com/strukturag/libde265/issues/460"
},
{
"type": "WEB",
"url": "https://github.com/zhangteng0526/CVE-information/blob/main/CVE-2024-38950"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T20:15:16Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-grq4-g85p-x45c",
"modified": "2024-06-26T21:32:18Z",
"published": "2024-06-26T21:32:18Z",
"aliases": [
"CVE-2024-36829"
],
"details": "Incorrect access control in Teldat M1 v11.00.05.50.01 allows attackers to obtain sensitive information via a crafted query string.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36829"
},
{
"type": "WEB",
"url": "https://gist.github.com/MILPDS/96843ccf7369ec1da643b7d6e22d428d"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T21:15:13Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pcgg-6f95-wg8g",
"modified": "2024-06-26T21:32:18Z",
"published": "2024-06-26T21:32:18Z",
"aliases": [
"CVE-2024-23767"
],
"details": "An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated changes to a device's network configurations.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23767"
},
{
"type": "WEB",
"url": "https://sensepost.com/blog/2024/targeting-an-industrial-protocol-gateway"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T21:15:13Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qr63-7f35-4m2w",
"modified": "2024-06-26T21:32:16Z",
"published": "2024-06-26T21:32:16Z",
"aliases": [
"CVE-2024-33326"
],
"details": "A cross-site scripting (XSS) vulnerability in the component XsltResultControllerHtml.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the lumPageID parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33326"
},
{
"type": "WEB",
"url": "https://gist.github.com/rodnt/51ae2897abfff1bdcedccf72edbf3d24"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T19:15:13Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v3rc-5q86-wwq8",
"modified": "2024-06-26T21:32:16Z",
"published": "2024-06-26T21:32:16Z",
"aliases": [
"CVE-2024-33329"
],
"details": "A hardcoded privileged ID within Lumisxp v15.0.x to v16.1.x allows attackers to bypass authentication and access internal pages and other sensitive information.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33329"
},
{
"type": "WEB",
"url": "https://gist.github.com/rodnt/f6b3a2ac875b8f13656063eefbfd9812"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T19:15:13Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w54f-vq4c-7637",
"modified": "2024-06-26T21:32:17Z",
"published": "2024-06-26T21:32:17Z",
"aliases": [
"CVE-2024-38949"
],
"details": "Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38949"
},
{
"type": "WEB",
"url": "https://github.com/strukturag/libde265/issues/460"
},
{
"type": "WEB",
"url": "https://github.com/zhangteng0526/CVE-information/blob/main/CVE-2024-38949"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T20:15:16Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xggx-88w4-2942",
"modified": "2024-06-26T21:32:16Z",
"published": "2024-06-26T21:32:16Z",
"aliases": [
"CVE-2023-26877"
],
"details": "File upload vulnerability found in Softexpert Excellence Suite v.2.1 allows attackers to execute arbitrary code via a .php file upload to the form/efms_exec_html/file_upload_parser.php endpoint.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26877"
},
{
"type": "WEB",
"url": "https://gist.github.com/rodnt/90ac26fdf891e602f6f090d6aebce32d"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-26T20:15:14Z"
}
}