From 17beb28e4798a211b158c7dabf37e29e0aa7ebe0 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 26 Nov 2024 03:37:59 +0000 Subject: [PATCH] Publish Advisories GHSA-7f88-5hhx-67m2 GHSA-67c5-gg2x-j6wg GHSA-3qrf-2xj8-m9mv GHSA-6mg4-m676-rm67 GHSA-73gq-35g9-rpwr GHSA-7wfp-r36g-m8hf GHSA-9fhj-wr42-mmv6 GHSA-h8jw-v8m2-669r GHSA-j8p2-5922-rxpr GHSA-mpfv-w8fh-9hfv GHSA-mx67-gpgv-qm6w GHSA-pfqm-9375-7qwm GHSA-rwhw-2ccq-46p7 GHSA-rwvw-fh44-w2r2 --- .../GHSA-7f88-5hhx-67m2.json | 10 +++- .../GHSA-67c5-gg2x-j6wg.json | 6 +- .../GHSA-3qrf-2xj8-m9mv.json | 38 ++++++++++++ .../GHSA-6mg4-m676-rm67.json | 38 ++++++++++++ .../GHSA-73gq-35g9-rpwr.json | 38 ++++++++++++ .../GHSA-7wfp-r36g-m8hf.json | 38 ++++++++++++ .../GHSA-9fhj-wr42-mmv6.json | 42 ++++++++++++++ .../GHSA-h8jw-v8m2-669r.json | 58 +++++++++++++++++++ .../GHSA-j8p2-5922-rxpr.json | 58 +++++++++++++++++++ .../GHSA-mpfv-w8fh-9hfv.json | 3 +- .../GHSA-mx67-gpgv-qm6w.json | 58 +++++++++++++++++++ .../GHSA-pfqm-9375-7qwm.json | 3 +- .../GHSA-rwhw-2ccq-46p7.json | 3 +- .../GHSA-rwvw-fh44-w2r2.json | 58 +++++++++++++++++++ 14 files changed, 446 insertions(+), 5 deletions(-) create mode 100644 advisories/unreviewed/2024/11/GHSA-3qrf-2xj8-m9mv/GHSA-3qrf-2xj8-m9mv.json create mode 100644 advisories/unreviewed/2024/11/GHSA-6mg4-m676-rm67/GHSA-6mg4-m676-rm67.json create mode 100644 advisories/unreviewed/2024/11/GHSA-73gq-35g9-rpwr/GHSA-73gq-35g9-rpwr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-7wfp-r36g-m8hf/GHSA-7wfp-r36g-m8hf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-9fhj-wr42-mmv6/GHSA-9fhj-wr42-mmv6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-h8jw-v8m2-669r/GHSA-h8jw-v8m2-669r.json create mode 100644 advisories/unreviewed/2024/11/GHSA-j8p2-5922-rxpr/GHSA-j8p2-5922-rxpr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-mx67-gpgv-qm6w/GHSA-mx67-gpgv-qm6w.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rwvw-fh44-w2r2/GHSA-rwvw-fh44-w2r2.json diff --git a/advisories/github-reviewed/2024/03/GHSA-7f88-5hhx-67m2/GHSA-7f88-5hhx-67m2.json b/advisories/github-reviewed/2024/03/GHSA-7f88-5hhx-67m2/GHSA-7f88-5hhx-67m2.json index 8962f340c48..77fd26a64ca 100644 --- a/advisories/github-reviewed/2024/03/GHSA-7f88-5hhx-67m2/GHSA-7f88-5hhx-67m2.json +++ b/advisories/github-reviewed/2024/03/GHSA-7f88-5hhx-67m2/GHSA-7f88-5hhx-67m2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7f88-5hhx-67m2", - "modified": "2024-05-08T09:30:50Z", + "modified": "2024-11-26T03:36:37Z", "published": "2024-03-22T21:30:56Z", "aliases": [ "CVE-2023-5685" @@ -63,6 +63,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2023:7641" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:10207" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:10208" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:2707" diff --git a/advisories/unreviewed/2024/08/GHSA-67c5-gg2x-j6wg/GHSA-67c5-gg2x-j6wg.json b/advisories/unreviewed/2024/08/GHSA-67c5-gg2x-j6wg/GHSA-67c5-gg2x-j6wg.json index b36cf0096dc..433dd86f542 100644 --- a/advisories/unreviewed/2024/08/GHSA-67c5-gg2x-j6wg/GHSA-67c5-gg2x-j6wg.json +++ b/advisories/unreviewed/2024/08/GHSA-67c5-gg2x-j6wg/GHSA-67c5-gg2x-j6wg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-67c5-gg2x-j6wg", - "modified": "2024-08-21T18:31:28Z", + "modified": "2024-11-26T03:36:37Z", "published": "2024-08-21T18:31:28Z", "aliases": [ "CVE-2024-5725" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5725" }, + { + "type": "WEB", + "url": "https://thewatch.centreon.com/latest-security-bulletins-64/security-bulletin-for-centreon-web-3744" + }, { "type": "WEB", "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-597" diff --git a/advisories/unreviewed/2024/11/GHSA-3qrf-2xj8-m9mv/GHSA-3qrf-2xj8-m9mv.json b/advisories/unreviewed/2024/11/GHSA-3qrf-2xj8-m9mv/GHSA-3qrf-2xj8-m9mv.json new file mode 100644 index 00000000000..ae612415184 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-3qrf-2xj8-m9mv/GHSA-3qrf-2xj8-m9mv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qrf-2xj8-m9mv", + "modified": "2024-11-26T03:36:38Z", + "published": "2024-11-26T03:36:38Z", + "aliases": [ + "CVE-2024-52899" + ], + "details": "IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL parameters and execute code on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52899" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7177091" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T01:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6mg4-m676-rm67/GHSA-6mg4-m676-rm67.json b/advisories/unreviewed/2024/11/GHSA-6mg4-m676-rm67/GHSA-6mg4-m676-rm67.json new file mode 100644 index 00000000000..d64812861c3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6mg4-m676-rm67/GHSA-6mg4-m676-rm67.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mg4-m676-rm67", + "modified": "2024-11-26T03:36:39Z", + "published": "2024-11-26T03:36:39Z", + "aliases": [ + "CVE-2024-49597" + ], + "details": "Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Attempts vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49597" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000244453/dsa-2024-440" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-73gq-35g9-rpwr/GHSA-73gq-35g9-rpwr.json b/advisories/unreviewed/2024/11/GHSA-73gq-35g9-rpwr/GHSA-73gq-35g9-rpwr.json new file mode 100644 index 00000000000..e7734163b7c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-73gq-35g9-rpwr/GHSA-73gq-35g9-rpwr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73gq-35g9-rpwr", + "modified": "2024-11-26T03:36:38Z", + "published": "2024-11-26T03:36:38Z", + "aliases": [ + "CVE-2024-49596" + ], + "details": "Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and arbitrary file deletion", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49596" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000244453/dsa-2024-440" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-7wfp-r36g-m8hf/GHSA-7wfp-r36g-m8hf.json b/advisories/unreviewed/2024/11/GHSA-7wfp-r36g-m8hf/GHSA-7wfp-r36g-m8hf.json new file mode 100644 index 00000000000..ba70f12d9d1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7wfp-r36g-m8hf/GHSA-7wfp-r36g-m8hf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wfp-r36g-m8hf", + "modified": "2024-11-26T03:36:38Z", + "published": "2024-11-26T03:36:38Z", + "aliases": [ + "CVE-2024-49595" + ], + "details": "Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49595" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000244453/dsa-2024-440" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-294" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T03:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9fhj-wr42-mmv6/GHSA-9fhj-wr42-mmv6.json b/advisories/unreviewed/2024/11/GHSA-9fhj-wr42-mmv6/GHSA-9fhj-wr42-mmv6.json new file mode 100644 index 00000000000..36335040993 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9fhj-wr42-mmv6/GHSA-9fhj-wr42-mmv6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fhj-wr42-mmv6", + "modified": "2024-11-26T03:36:38Z", + "published": "2024-11-26T03:36:38Z", + "aliases": [ + "CVE-2024-10729" + ], + "details": "The Booking & Appointment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_google_calendar_data' function in versions up to, and including, 6.9.0. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update the site options arbitrarily.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10729" + }, + { + "type": "WEB", + "url": "https://www.tychesoftwares.com/docs/docs/booking-appointment-plugin-for-woocommerce-new/changelog" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6ed215da-10c5-469b-bab2-923808feebd4?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T02:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-h8jw-v8m2-669r/GHSA-h8jw-v8m2-669r.json b/advisories/unreviewed/2024/11/GHSA-h8jw-v8m2-669r/GHSA-h8jw-v8m2-669r.json new file mode 100644 index 00000000000..f91a0c950f2 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h8jw-v8m2-669r/GHSA-h8jw-v8m2-669r.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8jw-v8m2-669r", + "modified": "2024-11-26T03:36:38Z", + "published": "2024-11-26T03:36:38Z", + "aliases": [ + "CVE-2024-11676" + ], + "details": "A vulnerability was found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /backend/admin/his_admin_add_lab_equipment.php of the component Add Laboratory Equipment Page. The manipulation of the argument eqp_code/eqp_name/eqp_vendor/eqp_desc/eqp_dept/eqp_status/eqp_qty leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11676" + }, + { + "type": "WEB", + "url": "https://codeastro.com" + }, + { + "type": "WEB", + "url": "https://github.com/EmilGallajov/zero-day/blob/main/codeastro_hms_stored_xss.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.286016" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.286016" + }, + { + "type": "WEB", + "url": "https://www.youtube.com/watch?v=UsScmd8Xzuw" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T01:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j8p2-5922-rxpr/GHSA-j8p2-5922-rxpr.json b/advisories/unreviewed/2024/11/GHSA-j8p2-5922-rxpr/GHSA-j8p2-5922-rxpr.json new file mode 100644 index 00000000000..aa2214a96c1 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j8p2-5922-rxpr/GHSA-j8p2-5922-rxpr.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8p2-5922-rxpr", + "modified": "2024-11-26T03:36:38Z", + "published": "2024-11-26T03:36:38Z", + "aliases": [ + "CVE-2024-11678" + ], + "details": "A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /backend/doc/his_doc_register_patient.php. The manipulation of the argument pat_fname/pat_ailment/pat_lname/pat_age/pat_dob/pat_number/pat_phone/pat_type/pat_addr leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11678" + }, + { + "type": "WEB", + "url": "https://codeastro.com" + }, + { + "type": "WEB", + "url": "https://github.com/EmilGallajov/zero-day/blob/main/codeastro_hms_stored_xss.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.286018" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.286018" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.448789" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T02:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mpfv-w8fh-9hfv/GHSA-mpfv-w8fh-9hfv.json b/advisories/unreviewed/2024/11/GHSA-mpfv-w8fh-9hfv/GHSA-mpfv-w8fh-9hfv.json index 5de72ff0bf3..77deaba1cc8 100644 --- a/advisories/unreviewed/2024/11/GHSA-mpfv-w8fh-9hfv/GHSA-mpfv-w8fh-9hfv.json +++ b/advisories/unreviewed/2024/11/GHSA-mpfv-w8fh-9hfv/GHSA-mpfv-w8fh-9hfv.json @@ -52,7 +52,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-mx67-gpgv-qm6w/GHSA-mx67-gpgv-qm6w.json b/advisories/unreviewed/2024/11/GHSA-mx67-gpgv-qm6w/GHSA-mx67-gpgv-qm6w.json new file mode 100644 index 00000000000..564eeb8fdc0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mx67-gpgv-qm6w/GHSA-mx67-gpgv-qm6w.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx67-gpgv-qm6w", + "modified": "2024-11-26T03:36:38Z", + "published": "2024-11-26T03:36:38Z", + "aliases": [ + "CVE-2024-11677" + ], + "details": "A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /backend/admin/his_admin_add_vendor.php of the component Add Vendor Details Page. The manipulation of the argument v_name/v_adr/v_number/v_email/v_phone/v_desc leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11677" + }, + { + "type": "WEB", + "url": "https://codeastro.com" + }, + { + "type": "WEB", + "url": "https://github.com/EmilGallajov/zero-day/blob/main/codeastro_hms_stored_xss.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.286017" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.286017" + }, + { + "type": "WEB", + "url": "https://www.youtube.com/watch?v=UsScmd8Xzuw" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T02:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pfqm-9375-7qwm/GHSA-pfqm-9375-7qwm.json b/advisories/unreviewed/2024/11/GHSA-pfqm-9375-7qwm/GHSA-pfqm-9375-7qwm.json index 3fb9d0d0b86..6d4d1155dcb 100644 --- a/advisories/unreviewed/2024/11/GHSA-pfqm-9375-7qwm/GHSA-pfqm-9375-7qwm.json +++ b/advisories/unreviewed/2024/11/GHSA-pfqm-9375-7qwm/GHSA-pfqm-9375-7qwm.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-rwhw-2ccq-46p7/GHSA-rwhw-2ccq-46p7.json b/advisories/unreviewed/2024/11/GHSA-rwhw-2ccq-46p7/GHSA-rwhw-2ccq-46p7.json index 473513f1123..b7564abf34e 100644 --- a/advisories/unreviewed/2024/11/GHSA-rwhw-2ccq-46p7/GHSA-rwhw-2ccq-46p7.json +++ b/advisories/unreviewed/2024/11/GHSA-rwhw-2ccq-46p7/GHSA-rwhw-2ccq-46p7.json @@ -48,7 +48,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-rwvw-fh44-w2r2/GHSA-rwvw-fh44-w2r2.json b/advisories/unreviewed/2024/11/GHSA-rwvw-fh44-w2r2/GHSA-rwvw-fh44-w2r2.json new file mode 100644 index 00000000000..bf3e247b7f0 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rwvw-fh44-w2r2/GHSA-rwvw-fh44-w2r2.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwvw-fh44-w2r2", + "modified": "2024-11-26T03:36:38Z", + "published": "2024-11-26T03:36:38Z", + "aliases": [ + "CVE-2024-11675" + ], + "details": "A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /backend/admin/his_admin_register_patient.php of the component Add Patient Details Page. The manipulation of the argument pat_fname/pat_ailment/pat_lname/pat_age/pat_dob/pat_number/pat_phone/pat_type/pat_addr leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11675" + }, + { + "type": "WEB", + "url": "https://codeastro.com" + }, + { + "type": "WEB", + "url": "https://github.com/EmilGallajov/zero-day/blob/main/codeastro_hms_stored_xss.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.286015" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.286015" + }, + { + "type": "WEB", + "url": "https://www.youtube.com/watch?v=UsScmd8Xzuw" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T01:15:04Z" + } +} \ No newline at end of file