Publish Advisories

GHSA-c2qq-2j48-5pr5
GHSA-c39f-gcvf-w4rp
GHSA-p2x9-xrxx-x6w7
GHSA-985v-7jg3-m7g3
GHSA-mqx6-fm3x-25wm
GHSA-3785-cv6x-mm3h
GHSA-38cx-x5rg-m9mx
GHSA-5vhj-65c8-9r9j
GHSA-77hm-gcrm-xcg8
GHSA-8w8w-88r2-6w5q
GHSA-94mp-gc2x-rqm6
GHSA-9c83-cg8h-x7rp
GHSA-9m5j-63r8-6hp8
GHSA-c7p7-p3jf-3wp4
GHSA-cwr4-4jj2-mpc2
GHSA-f3g2-9hcq-jr47
GHSA-f5mv-fx82-4m95
GHSA-gh6q-p7qv-wv6v
GHSA-hf47-p558-hhmv
GHSA-j5rc-gv5c-g3gv
GHSA-vhwq-33mx-jmx5
This commit is contained in:
advisory-database[bot]
2024-12-17 00:32:50 +00:00
parent b482d15e01
commit 1fa4631484
21 changed files with 622 additions and 13 deletions
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22",
"CWE-23"
],
"severity": "HIGH",
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c39f-gcvf-w4rp",
"modified": "2024-02-17T06:30:36Z",
"modified": "2024-12-17T00:31:16Z",
"published": "2024-02-17T06:30:36Z",
"aliases": [
"CVE-2024-25468"
],
"details": "An issue in TOTOLINK X5000R V.9.1.0u.6369_B20230113 allows a remote attacker to cause a denial of service via the host_time parameter of the NTPSyncWithHost component.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-78"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-17T06:15:54Z"
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-285"
"CWE-285",
"CWE-863"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-985v-7jg3-m7g3",
"modified": "2024-03-16T06:30:29Z",
"modified": "2024-12-17T00:31:17Z",
"published": "2024-03-16T06:30:29Z",
"aliases": [
"CVE-2024-28639"
],
"details": "Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022, allow remote attackers to execute arbitrary code and cause a denial of service (DoS) via the IP field.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-120"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-16T06:15:14Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mqx6-fm3x-25wm",
"modified": "2024-11-22T21:32:15Z",
"modified": "2024-12-17T00:31:17Z",
"published": "2024-11-22T21:32:15Z",
"aliases": [
"CVE-2024-52723"
],
"details": "In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-78"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-22T16:15:33Z"
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3785-cv6x-mm3h",
"modified": "2024-12-17T00:31:17Z",
"published": "2024-12-17T00:31:17Z",
"aliases": [
"CVE-2024-37776"
],
"details": "A cross-site scripting (XSS) vulnerability in Sunbird DCIM dcTrack v9.1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in some admin screens.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37776"
},
{
"type": "WEB",
"url": "https://s3.us-east-1.amazonaws.com/dcTrack.Docs/dcTrack_9.2.0_GA/dcTrack_9.2.0_Release_Notes.pdf"
},
{
"type": "WEB",
"url": "http://dctrack.com"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T22:15:06Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-38cx-x5rg-m9mx",
"modified": "2024-12-17T00:31:18Z",
"published": "2024-12-17T00:31:18Z",
"aliases": [
"CVE-2024-55085"
],
"details": "GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system, which can be used by an attacker to implement RCE.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55085"
},
{
"type": "WEB",
"url": "https://getsimple-ce.ovh"
},
{
"type": "WEB",
"url": "https://tasteful-stamp-da4.notion.site/CVE-2024-55085-15b1e0f227cb80a5aee6faeb820bf7e6"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T23:15:06Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5vhj-65c8-9r9j",
"modified": "2024-12-17T00:31:18Z",
"published": "2024-12-17T00:31:18Z",
"aliases": [
"CVE-2024-55452"
],
"details": "A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of new block / carousel items. This vulnerability allows authenticated attackers to redirect unprivileged users to an arbitrary, attacker-controlled webpage. When an authenticated user clicks on the malicious block item, they are redirected to the arbitrary untrusted domains, where sensitive tokens, such as JSON Web Tokens, can be stolen via a crafted webpage.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55452"
},
{
"type": "WEB",
"url": "https://github.com/cydtseng/Vulnerability-Research/blob/main/ujcms/OpenRedirect-BlockItemUpload.md"
},
{
"type": "WEB",
"url": "https://github.com/dromara/ujcms"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T23:15:06Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-77hm-gcrm-xcg8",
"modified": "2024-12-17T00:31:19Z",
"published": "2024-12-17T00:31:19Z",
"aliases": [
"CVE-2024-11906"
],
"details": "The TPG Get Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tpg_get_posts' shortcode in all versions up to, and including, 3.6.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11906"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/tpg-get-posts/trunk/inc/class-tpg-gp-process.php#L478"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/tpg-get-posts"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c22288e6-76f3-4c5a-bd7b-30681334bab7?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-17T00:15:06Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8w8w-88r2-6w5q",
"modified": "2024-12-17T00:31:18Z",
"published": "2024-12-17T00:31:18Z",
"aliases": [
"CVE-2024-56017"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in Tom Royal Stop Registration Spam allows Stored XSS.This issue affects Stop Registration Spam: from n/a through 1.23.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56017"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/stop-registration-spam/vulnerability/wordpress-stop-registration-spam-plugin-1-23-csrf-to-stored-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T23:15:06Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-94mp-gc2x-rqm6",
"modified": "2024-12-17T00:31:17Z",
"published": "2024-12-17T00:31:17Z",
"aliases": [
"CVE-2024-52949"
],
"details": "iptraf-ng 1.2.1 has a stack-based buffer overflow.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52949"
},
{
"type": "WEB",
"url": "https://github.com/iptraf-ng/iptraf-ng/releases/tag/v1.2.1"
},
{
"type": "WEB",
"url": "https://www.gruppotim.it/it/footer/red-team.html"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T22:15:06Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9c83-cg8h-x7rp",
"modified": "2024-12-17T00:31:17Z",
"published": "2024-12-17T00:31:17Z",
"aliases": [
"CVE-2024-37775"
],
"details": "Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location which bypasses an RBAC check.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37775"
},
{
"type": "WEB",
"url": "https://s3.us-east-1.amazonaws.com/dcTrack.Docs/dcTrack_9.2.0_GA/dcTrack_9.2.0_Release_Notes.pdf"
},
{
"type": "WEB",
"url": "http://dctrack.com"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T22:15:06Z"
}
}
@@ -0,0 +1,37 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9m5j-63r8-6hp8",
"modified": "2024-12-17T00:31:17Z",
"published": "2024-12-17T00:31:17Z",
"aliases": [
"CVE-2024-29671"
],
"details": "Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code via the POST request handler component.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29671"
},
{
"type": "WEB",
"url": "https://ez-net.co.kr/new_2012/customer/download_view.php?cid=&sid=&goods=&cate=&q=Ax1500&seq=228"
},
{
"type": "WEB",
"url": "https://gist.github.com/laskdjlaskdj12/4afc8b5d75640bd28eaf32de3ceda48a"
},
{
"type": "WEB",
"url": "https://github.com/laskdjlaskdj12/CVE-2024-29671-POC"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T22:15:05Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c7p7-p3jf-3wp4",
"modified": "2024-12-17T00:31:19Z",
"published": "2024-12-17T00:31:19Z",
"aliases": [
"CVE-2024-11905"
],
"details": "The Animated Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animatedcounte' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11905"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/animated-counters/trunk/animated-counters.php#L32"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/animated-counters"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/afd2f09c-4bd5-47a5-8d4f-7345aa8925f8?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-17T00:15:06Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cwr4-4jj2-mpc2",
"modified": "2024-12-17T00:31:17Z",
"published": "2024-12-17T00:31:17Z",
"aliases": [
"CVE-2024-37774"
],
"details": "A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37774"
},
{
"type": "WEB",
"url": "https://s3.us-east-1.amazonaws.com/dcTrack.Docs/dcTrack_9.2.0_GA/dcTrack_9.2.0_Release_Notes.pdf"
},
{
"type": "WEB",
"url": "http://dctrack.com"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T22:15:06Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f3g2-9hcq-jr47",
"modified": "2024-12-17T00:31:18Z",
"published": "2024-12-17T00:31:18Z",
"aliases": [
"CVE-2024-55451"
],
"details": "A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in UJCMS 9.6.3. The vulnerability arises from insufficient sanitization of embedded attributes in uploaded SVG files. When a maliciously crafted SVG file is viewed by other backend users, it allows authenticated attackers to execute arbitrary JavaScript in the context of other backend users' browsers, potentially leading to the theft of sensitive tokens.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55451"
},
{
"type": "WEB",
"url": "https://github.com/cydtseng/Vulnerability-Research/blob/main/ujcms/StoredXSS-SVGUpload.md"
},
{
"type": "WEB",
"url": "https://github.com/dromara/ujcms"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T23:15:06Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f5mv-fx82-4m95",
"modified": "2024-12-17T00:31:18Z",
"published": "2024-12-17T00:31:18Z",
"aliases": [
"CVE-2024-11900"
],
"details": "The Portfolio Filterable Masonry Portfolio Gallery for Professionals plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'portfolio-pro' shortcode in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11900"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/portfolio-pro/trunk/public/class-portfolio-pro-public.php#L358"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1989fe85-5c32-4671-bd20-f9d05cb5034c?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-17T00:15:04Z"
}
}
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gh6q-p7qv-wv6v",
"modified": "2024-12-17T00:31:18Z",
"published": "2024-12-17T00:31:18Z",
"aliases": [
"CVE-2024-12443"
],
"details": "The CRM Perks WordPress HelpDesk Integration Zendesk, Freshdesk, HelpScout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'crm-perks-tickets' shortcode in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12443"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/support-x/trunk/support-x.php#L210"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3207849/support-x/trunk/support-x.php"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/support-x"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a19e11e7-faa1-4e4d-87de-2454c4ad70f8?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T23:15:06Z"
}
}
@@ -0,0 +1,29 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hf47-p558-hhmv",
"modified": "2024-12-17T00:31:18Z",
"published": "2024-12-17T00:31:18Z",
"aliases": [
"CVE-2024-55554"
],
"details": "Intrexx Portal Server before 12.0.2 allows XSS via a user-defined portlet.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55554"
},
{
"type": "WEB",
"url": "https://security.intrexx.com/en/security-advisories/ixsa-20241204-01"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-16T22:15:07Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j5rc-gv5c-g3gv",
"modified": "2024-12-17T00:31:19Z",
"published": "2024-12-17T00:31:19Z",
"aliases": [
"CVE-2024-11902"
],
"details": "The Slope Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slope-reservations' shortcode in all versions up to, and including, 4.2.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11902"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/slope-widgets/trunk/slope-reservations.php#L298"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/slope-widgets"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7700f1f3-90e2-450d-9cfe-c922d0cc6a1e?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-17T00:15:05Z"
}
}

Some files were not shown because too many files have changed in this diff Show More