Publish Advisories

GHSA-27h5-287x-qrg4
GHSA-6vmj-9xjc-fxmr
GHSA-7892-3f52-8277
GHSA-fp78-wr5r-r3fr
GHSA-gjpq-5jrr-h6wr
GHSA-mx7j-q788-jq8x
GHSA-wf7p-46h8-v74r
This commit is contained in:
advisory-database[bot]
2024-10-15 00:32:22 +00:00
parent 75ab5229f2
commit 206850ae56
7 changed files with 275 additions and 0 deletions
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-27h5-287x-qrg4",
"modified": "2024-10-15T00:30:58Z",
"published": "2024-10-15T00:30:58Z",
"aliases": [
"CVE-2024-9548"
],
"details": "The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping when logging visitor requests. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9548"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/wp-slimstat/tags/5.2.6"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/wp-slimstat/tags/5.2.6/admin/view/right-now.php#L196"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fa91912d-5794-4c96-8a13-bd54ce0f1deb?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-15T00:15:22Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6vmj-9xjc-fxmr",
"modified": "2024-10-15T00:30:57Z",
"published": "2024-10-15T00:30:57Z",
"aliases": [
"CVE-2024-35519"
],
"details": "Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap_mode parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35519"
},
{
"type": "WEB",
"url": "https://github.com/consrc/cves/blob/main/CVE-2024-35519.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-14T22:15:03Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7892-3f52-8277",
"modified": "2024-10-15T00:30:57Z",
"published": "2024-10-15T00:30:57Z",
"aliases": [
"CVE-2024-35520"
],
"details": "Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35520"
},
{
"type": "WEB",
"url": "https://kb.netgear.com/000066027/Security-Advisory-for-Post-Authentication-Command-Injection-on-the-R7000-PSV-2023-0154"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-14T22:15:03Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fp78-wr5r-r3fr",
"modified": "2024-10-15T00:30:57Z",
"published": "2024-10-15T00:30:57Z",
"aliases": [
"CVE-2024-30117"
],
"details": "A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30117"
},
{
"type": "WEB",
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0116659"
}
],
"database_specific": {
"cwe_ids": [
"CWE-427"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-14T23:15:11Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gjpq-5jrr-h6wr",
"modified": "2024-10-15T00:30:57Z",
"published": "2024-10-15T00:30:57Z",
"aliases": [
"CVE-2024-9953"
],
"details": "A Potential DOS Vulnerability exists in CERT VINCE software prior to version 3.0.8. An authenticated administrative user can inject an arbitrary pickle object as part of a user's profile. This can lead to a potential DoS on the server when the user's profile is accessed. Django server does restrict unpickling from crashing the server.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9953"
},
{
"type": "WEB",
"url": "https://github.com/CERTCC/VINCE/issues?q=label%3Asecurity"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-14T22:15:03Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mx7j-q788-jq8x",
"modified": "2024-10-15T00:30:57Z",
"published": "2024-10-15T00:30:57Z",
"aliases": [
"CVE-2024-35518"
],
"details": "Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35518"
},
{
"type": "WEB",
"url": "https://github.com/consrc/cves/blob/main/CVE-2024-35518.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-14T22:15:03Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wf7p-46h8-v74r",
"modified": "2024-10-15T00:30:58Z",
"published": "2024-10-15T00:30:58Z",
"aliases": [
"CVE-2024-9546"
],
"details": "The WPIDE File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.9. This is due to the plugin utilizing the PHP-Parser library, which outputs parser rebuild command execution results. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9546"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/wpide/tags/3.4.9/vendor/nikic/php-parser/grammar/rebuildParsers.php#L77"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e884af8b-c83f-4380-bfaf-f1419fce125c?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-15T00:15:21Z"
}
}