Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-01-29 21:31:22 +00:00
parent 9982374ecb
commit 1ca93f91a5
39 changed files with 929 additions and 48 deletions
@@ -65,6 +65,10 @@
"type": "WEB",
"url": "https://github.com/python-pillow/Pillow/releases"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/01/msg00019.html"
},
{
"type": "WEB",
"url": "https://pillow.readthedocs.io/en/stable/releasenotes/10.2.0.html#security"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fcqj-x222-4c7r",
"modified": "2023-05-11T12:30:14Z",
"modified": "2024-01-29T21:30:25Z",
"published": "2023-05-11T12:30:14Z",
"aliases": [
"CVE-2023-31445"
],
"details": "Cassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged -information disclosure vulnerability that allows read-only users have the ability to enumerate all other users and discover e-mail addresses, phone numbers, and privileges of all other users.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
@@ -18,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31445"
},
{
"type": "WEB",
"url": "https://blog.kscsc.online/cves/202331445/md.html"
},
{
"type": "WEB",
"url": "https://github.com/Dodge-MPTC/CVE-2023-31445-Unprivileged-Information-Disclosure"
@@ -25,13 +32,17 @@
{
"type": "WEB",
"url": "https://www.cassianetworks.com"
},
{
"type": "WEB",
"url": "https://www.swiruhack.online/cves/202331445/md.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-732"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-05-11T12:15:09Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qr34-fv3w-3x4j",
"modified": "2023-09-29T00:30:15Z",
"modified": "2024-01-29T21:30:25Z",
"published": "2023-09-27T15:30:34Z",
"aliases": [
"CVE-2023-35793"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35793"
},
{
"type": "WEB",
"url": "https://blog.kscsc.online/cves/202335793/md.html"
},
{
"type": "WEB",
"url": "https://github.com/Dodge-MPTC/CVE-2023-35793-CSRF-On-Web-SSH"
@@ -34,7 +38,7 @@
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-09-27T15:18:52Z"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35794"
},
{
"type": "WEB",
"url": "https://blog.kscsc.online/cves/202335794/md.html"
},
{
"type": "WEB",
"url": "https://github.com/Dodge-MPTC/CVE-2023-35794-WebSSH-Hijacking"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2x33-pfvq-675c",
"modified": "2024-01-29T21:30:27Z",
"published": "2024-01-29T21:30:27Z",
"aliases": [
"CVE-2024-24136"
],
"details": "The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cross-Site Scripting (XSS) attacks.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24136"
},
{
"type": "WEB",
"url": "https://github.com/BurakSevben/2024_Math_Game_XSS"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-29T20:15:15Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-39g9-xc8h-ffgp",
"modified": "2024-01-29T21:30:27Z",
"published": "2024-01-29T21:30:27Z",
"aliases": [
"CVE-2024-24134"
],
"details": "Sourcecodester Online Food Menu 1.0 is vulnerable to Cross Site Scripting (XSS) via the 'Menu Name' and 'Description' fields in the Update Menu section.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24134"
},
{
"type": "WEB",
"url": "https://github.com/BurakSevben/2024_Online_Food_Menu_XSS/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-29T19:15:08Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3crw-hq66-3456",
"modified": "2024-01-23T21:30:20Z",
"modified": "2024-01-29T21:30:27Z",
"published": "2024-01-23T21:30:20Z",
"aliases": [
"CVE-2023-51210"
],
"details": "SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id_product parameters in the UpdateProductQuantity function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-23T19:15:08Z"
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-555g-cg2q-wmc3",
"modified": "2024-01-29T21:30:27Z",
"published": "2024-01-29T21:30:27Z",
"aliases": [
"CVE-2023-51840"
],
"details": "DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51840"
},
{
"type": "WEB",
"url": "https://github.com/doramart/DoraCMS/issues/262"
},
{
"type": "WEB",
"url": "https://github.com/doramart/DoraCMS"
},
{
"type": "WEB",
"url": "https://github.com/tianjk99/Cryptographic-Misuses/blob/main/CVE-2023-51840.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-29T20:15:15Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6m95-c675-56r5",
"modified": "2024-01-29T21:30:27Z",
"published": "2024-01-29T21:30:27Z",
"aliases": [
"CVE-2024-1018"
],
"details": "A vulnerability classified as problematic has been found in PbootCMS 3.2.5-20230421. Affected is an unknown function of the file /admin.php?p=/Area/index#tab=t2. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252288.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1018"
},
{
"type": "WEB",
"url": "https://github.com/1MurasaKi/PboostCMS_XSS/blob/main/README.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.252288"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.252288"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-29T20:15:15Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6xwv-xr2m-rj2h",
"modified": "2024-01-23T21:30:21Z",
"modified": "2024-01-29T21:30:27Z",
"published": "2024-01-23T21:30:21Z",
"aliases": [
"CVE-2023-47201"
],
"details": "A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThis vulnerability is similar to, but not identical to, CVE-2023-47200.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-23T21:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7258-xmq8-x5x7",
"modified": "2024-01-23T03:31:07Z",
"modified": "2024-01-29T21:30:26Z",
"published": "2024-01-23T03:31:07Z",
"aliases": [
"CVE-2023-42915"
],
"details": "Multiple issues were addressed by updating to curl version 8.4.0. This issue is fixed in macOS Ventura 13.6.4, macOS Sonoma 14.2, macOS Monterey 12.7.3, iOS 16.7.5 and iPadOS 16.7.5. Multiple issues in curl.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -55,7 +58,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-23T01:15:10Z"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7m9h-xc4x-cg98",
"modified": "2024-01-29T21:30:27Z",
"published": "2024-01-29T21:30:27Z",
"aliases": [
"CVE-2023-4551"
],
"details": "Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows OS Command Injection.\n\nThe AppBuilder's Scheduler functionality that facilitates creation of scheduled tasks is vulnerable to command injection. This allows authenticated users to inject arbitrary operating system commands into the executing process.\n\n\nThis issue affects AppBuilder: from 21.2 before 23.2.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4551"
},
{
"type": "WEB",
"url": "https://support.opentext.com/csm?id=ot_kb_search&kb_category=61648712db61781068cfd6c4e296197b"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-29T21:15:08Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7xm8-wjq7-88r5",
"modified": "2024-01-29T21:30:27Z",
"published": "2024-01-29T21:30:27Z",
"aliases": [
"CVE-2023-51839"
],
"details": "DeviceFarmer stf v3.6.6 suffers from Use of a Broken or Risky Cryptographic Algorithm.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51839"
},
{
"type": "WEB",
"url": "https://github.com/DeviceFarmer/stf/issues/736"
},
{
"type": "WEB",
"url": "https://github.com/DeviceFarmer/stf"
},
{
"type": "WEB",
"url": "https://github.com/tianjk99/Cryptographic-Misuses/blob/main/CVE-2023-51839.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-29T20:15:15Z"
}
}
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31446"
},
{
"type": "WEB",
"url": "https://blog.kscsc.online/cves/202331446/md.html"
},
{
"type": "WEB",
"url": "https://github.com/Dodge-MPTC/CVE-2023-31446-Remote-Code-Execution"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8c2v-657f-h9r7",
"modified": "2024-01-29T21:30:27Z",
"published": "2024-01-29T21:30:27Z",
"aliases": [
"CVE-2024-24139"
],
"details": "Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24139"
},
{
"type": "WEB",
"url": "https://github.com/BurakSevben/Login_System_with_Email_Verification_SQL_Injection/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-29T20:15:15Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8mxm-prp8-gc3w",
"modified": "2024-01-29T21:30:27Z",
"published": "2024-01-29T21:30:27Z",
"aliases": [
"CVE-2024-24141"
],
"details": "Sourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24141"
},
{
"type": "WEB",
"url": "https://github.com/BurakSevben/School-Task-Manager-System-SQLi-1"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-29T20:15:15Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8p2h-w6cv-wr2w",
"modified": "2024-01-29T21:30:27Z",
"published": "2024-01-29T21:30:27Z",
"aliases": [
"CVE-2023-4553"
],
"details": "Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files.\n\n\nAppBuilder configuration files are viewable by unauthenticated users.\n\n\nThis issue affects AppBuilder: from 21.2 before 23.2.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4553"
},
{
"type": "WEB",
"url": "https://support.opentext.com/csm?id=ot_kb_search&kb_category=61648712db61781068cfd6c4e296197b"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-29T21:15:09Z"
}
}
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://advisory.abay.sh/cve-2023-6524"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3015598%40mappress-google-maps-for-wordpress%2Ftrunk&old=3001436%40mappress-google-maps-for-wordpress%2Ftrunk&sfp_email=&sfph_mail="
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3001436%40mappress-google-maps-for-wordpress%2Ftags%2F2.88.13&new=3015598%40mappress-google-maps-for-wordpress%2Ftags%2F2.88.14#file31"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9933-5g23-6jq2",
"modified": "2024-01-23T21:30:21Z",
"modified": "2024-01-29T21:30:27Z",
"published": "2024-01-23T21:30:21Z",
"aliases": [
"CVE-2023-52092"
],
"details": "A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations.\n\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-59"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-23T21:15:09Z"
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9fpx-vc83-vhpf",
"modified": "2024-01-29T21:30:27Z",
"published": "2024-01-29T21:30:27Z",
"aliases": [
"CVE-2024-23940"
],
"details": "Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, which if exploited could allow an attacker to impersonate and modify a library to execute code on the system and ultimately escalate privileges on an affected system.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23940"
},
{
"type": "WEB",
"url": "https://helpcenter.trendmicro.com/en-us/article/tmka-12134"
},
{
"type": "WEB",
"url": "https://helpcenter.trendmicro.com/ja-jp/article/tmka-12132"
},
{
"type": "WEB",
"url": "https://medium.com/@s1kr10s/av-when-a-friend-becomes-an-enemy-55f41aba42b1"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-29T19:15:08Z"
}
}

Some files were not shown because too many files have changed in this diff Show More