Publish Advisories

GHSA-38pg-fhjw-6gv5
GHSA-67q5-5xj6-vp4m
GHSA-6xpq-789w-crhj
GHSA-9926-q94j-c3rc
GHSA-f3qm-vwjc-2pfv
GHSA-m336-3p9f-8r49
GHSA-p3xm-g7cx-5qfp
GHSA-r358-c7w3-46x5
GHSA-rw57-p6vv-42wg
GHSA-2xf9-j9jw-g7f7
GHSA-3x7w-vvg2-w6r8
GHSA-4v64-w7v7-ch7f
GHSA-7g9g-whvg-fhcj
GHSA-9c8q-55w7-h67h
GHSA-wf5c-q6vq-584r
GHSA-74q3-7j69-pcjv
GHSA-7qqw-h3cr-wwj4
GHSA-9v2g-7h8m-q5hc
GHSA-f97f-26jc-gffx
GHSA-mmj7-9q6x-r9fw
GHSA-pf8q-v3qp-47xw
GHSA-qh3h-ppj3-p38m
This commit is contained in:
advisory-database[bot]
2024-10-16 12:32:10 +00:00
parent 656e70bb88
commit 1a3582a3d1
22 changed files with 409 additions and 15 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-38pg-fhjw-6gv5",
"modified": "2022-03-20T00:00:33Z",
"modified": "2024-10-16T12:30:46Z",
"published": "2022-03-15T00:01:01Z",
"aliases": [
"CVE-2022-24387"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24387"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/CVE-2022-24387"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/DIVD-2021-00029"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-67q5-5xj6-vp4m",
"modified": "2023-01-11T03:30:18Z",
"modified": "2024-10-16T12:30:47Z",
"published": "2023-01-04T21:30:19Z",
"aliases": [
"CVE-2022-45052"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6xpq-789w-crhj",
"modified": "2024-04-04T04:43:03Z",
"modified": "2024-10-16T12:30:47Z",
"published": "2023-06-11T15:30:30Z",
"aliases": [
"CVE-2023-22584"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22584"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/CVE-2023-22584"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/DIVD-2023-00021"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9926-q94j-c3rc",
"modified": "2024-04-04T04:43:01Z",
"modified": "2024-10-16T12:30:47Z",
"published": "2023-06-11T15:30:30Z",
"aliases": [
"CVE-2023-22582"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22582"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/CVE-2023-22582"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/DIVD-2023-00021"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f3qm-vwjc-2pfv",
"modified": "2024-04-04T04:43:07Z",
"modified": "2024-10-16T12:30:47Z",
"published": "2023-06-11T15:30:30Z",
"aliases": [
"CVE-2023-22586"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22586"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/CVE-2023-22586"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/DIVD-2023-00021"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m336-3p9f-8r49",
"modified": "2024-04-04T04:43:05Z",
"modified": "2024-10-16T12:30:47Z",
"published": "2023-06-11T15:30:30Z",
"aliases": [
"CVE-2023-22585"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22585"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/CVE-2023-22585"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/DIVD-2023-00021"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p3xm-g7cx-5qfp",
"modified": "2024-04-04T04:43:09Z",
"modified": "2024-10-16T12:30:47Z",
"published": "2023-06-11T15:30:30Z",
"aliases": [
"CVE-2023-25912"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25912"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/CVE-2023-25912"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/DIVD-2023-00021"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r358-c7w3-46x5",
"modified": "2024-04-04T04:43:06Z",
"modified": "2024-10-16T12:30:47Z",
"published": "2023-06-11T15:30:30Z",
"aliases": [
"CVE-2023-25911"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25911"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/CVE-2023-25911"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/DIVD-2023-00021"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rw57-p6vv-42wg",
"modified": "2024-04-04T04:43:02Z",
"modified": "2024-10-16T12:30:47Z",
"published": "2023-06-11T15:30:30Z",
"aliases": [
"CVE-2023-22583"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22583"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/CVE-2023-22583"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/DIVD-2023-00021"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2xf9-j9jw-g7f7",
"modified": "2024-04-04T05:51:16Z",
"modified": "2024-10-16T12:30:47Z",
"published": "2023-07-10T18:30:47Z",
"aliases": [
"CVE-2021-4406"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://csirt.divd.nl/CVE-2021-4406"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/DIVD-2021-00020"
},
{
"type": "WEB",
"url": "https://www.divd.nl/DIVD-2021-00020"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3x7w-vvg2-w6r8",
"modified": "2024-04-04T05:51:15Z",
"modified": "2024-10-16T12:30:47Z",
"published": "2023-07-10T18:30:47Z",
"aliases": [
"CVE-2021-42082"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://csirt.divd.nl/CVE-2021-42082"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/DIVD-2021-00020"
},
{
"type": "WEB",
"url": "https://www.divd.nl/DIVD-2021-00020"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4v64-w7v7-ch7f",
"modified": "2024-04-04T05:51:11Z",
"modified": "2024-10-16T12:30:47Z",
"published": "2023-07-10T18:30:47Z",
"aliases": [
"CVE-2021-42079"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-42079"
},
{
"type": "WEB",
"url": "https://cisrt.divd.nl/DIVD-2021-00020"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/CVE-2021-42079"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7g9g-whvg-fhcj",
"modified": "2024-04-04T05:51:13Z",
"modified": "2024-10-16T12:30:47Z",
"published": "2023-07-10T18:30:47Z",
"aliases": [
"CVE-2021-42081"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://csirt.divd.nl/CVE-2021-42081"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/DIVD-2021-00020"
},
{
"type": "WEB",
"url": "https://www.divd.nl/DIVD-2021-00020"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9c8q-55w7-h67h",
"modified": "2024-01-02T21:30:23Z",
"modified": "2024-10-16T12:30:47Z",
"published": "2023-07-10T18:30:47Z",
"aliases": [
"CVE-2021-42083"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://csirt.divd.nl/CVE-2021-42083"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/DIVD-2021-00020"
},
{
"type": "WEB",
"url": "https://www.divd.nl/DIVD-2021-00020"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wf5c-q6vq-584r",
"modified": "2024-04-04T05:51:12Z",
"modified": "2024-10-16T12:30:47Z",
"published": "2023-07-10T18:30:47Z",
"aliases": [
"CVE-2021-42080"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://csirt.divd.nl/CVE-2021-42080"
},
{
"type": "WEB",
"url": "https://csirt.divd.nl/DIVD-2021-00020"
},
{
"type": "WEB",
"url": "https://www.divd.nl/DIVD-2021-00020"
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-74q3-7j69-pcjv",
"modified": "2024-10-16T12:30:48Z",
"published": "2024-10-16T12:30:47Z",
"aliases": [
"CVE-2024-10022"
],
"details": "A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an unknown part of the file /php/manage_supplier.php?action=search. The manipulation of the argument text leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10022"
},
{
"type": "WEB",
"url": "https://code-projects.org"
},
{
"type": "WEB",
"url": "https://gist.github.com/higordiego/2bd0a94e480906a60ce83b8a4ec26957"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.280557"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.280557"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.424337"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-16T12:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7qqw-h3cr-wwj4",
"modified": "2024-10-16T12:30:47Z",
"published": "2024-10-16T12:30:47Z",
"aliases": [
"CVE-2024-6380"
],
"details": "A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6380"
},
{
"type": "WEB",
"url": "https://www.3ds.com/vulnerability/advisories"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-16T12:15:08Z"
}
}
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9v2g-7h8m-q5hc",
"modified": "2024-10-16T12:30:47Z",
"published": "2024-10-16T12:30:47Z",
"aliases": [
"CVE-2024-8921"
],
"details": "The Zita Elementor Site Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8921"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/zita-site-library/trunk/importer/wxr-importer.php#L160"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/zita-site-library/trunk/inc/importer.php#L148"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3168327"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/zita-site-library/#developers"
},
{
"type": "WEB",
"url": "https://wpzita.com/changelog"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cc1c76ee-078d-4c9a-a4d3-063d9147d7e8?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-16T11:15:13Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f97f-26jc-gffx",
"modified": "2024-10-16T12:30:47Z",
"published": "2024-10-16T12:30:47Z",
"aliases": [
"CVE-2023-32190"
],
"details": "mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32190"
},
{
"type": "WEB",
"url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-32190"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-16T12:15:07Z"
}
}
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mmj7-9q6x-r9fw",
"modified": "2024-10-16T12:30:48Z",
"published": "2024-10-16T12:30:48Z",
"aliases": [
"CVE-2024-10021"
],
"details": "A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /php/manage_purchase.php?action=search&tag=VOUCHER_NUMBER. The manipulation of the argument text leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10021"
},
{
"type": "WEB",
"url": "https://code-projects.org"
},
{
"type": "WEB",
"url": "https://gist.github.com/higordiego/439f2af836c2c7d6075ba9de2e1169da"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.280556"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.280556"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.424334"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-16T12:15:07Z"
}
}

Some files were not shown because too many files have changed in this diff Show More