From 233497629f16e91da1923c48c82d67c4de95aed7 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 1 Aug 2024 06:32:06 +0000 Subject: [PATCH] Publish Advisories GHSA-27h7-6m3c-wghw GHSA-28v8-9mr3-438f GHSA-7f4q-mxmp-vrc9 GHSA-f8wm-p3c6-g898 GHSA-fgw8-wccj-749x GHSA-g4q4-8vjq-c7c8 GHSA-g4w3-q8cv-798h GHSA-p844-wjq6-m36r GHSA-r2cp-jr96-fmw7 GHSA-rr2m-vxfp-vgm4 GHSA-vcqx-95xm-6xh4 GHSA-vqgx-gpv3-58p3 GHSA-x6qr-qghp-2wfr GHSA-xhpw-qr8c-jfj2 --- .../GHSA-27h7-6m3c-wghw.json | 54 +++++++++++++++++++ .../GHSA-28v8-9mr3-438f.json | 42 +++++++++++++++ .../GHSA-7f4q-mxmp-vrc9.json | 42 +++++++++++++++ .../GHSA-f8wm-p3c6-g898.json | 35 ++++++++++++ .../GHSA-fgw8-wccj-749x.json | 35 ++++++++++++ .../GHSA-g4q4-8vjq-c7c8.json | 35 ++++++++++++ .../GHSA-g4w3-q8cv-798h.json | 42 +++++++++++++++ .../GHSA-p844-wjq6-m36r.json | 35 ++++++++++++ .../GHSA-r2cp-jr96-fmw7.json | 35 ++++++++++++ .../GHSA-rr2m-vxfp-vgm4.json | 54 +++++++++++++++++++ .../GHSA-vcqx-95xm-6xh4.json | 54 +++++++++++++++++++ .../GHSA-vqgx-gpv3-58p3.json | 35 ++++++++++++ .../GHSA-x6qr-qghp-2wfr.json | 54 +++++++++++++++++++ .../GHSA-xhpw-qr8c-jfj2.json | 35 ++++++++++++ 14 files changed, 587 insertions(+) create mode 100644 advisories/unreviewed/2024/08/GHSA-27h7-6m3c-wghw/GHSA-27h7-6m3c-wghw.json create mode 100644 advisories/unreviewed/2024/08/GHSA-28v8-9mr3-438f/GHSA-28v8-9mr3-438f.json create mode 100644 advisories/unreviewed/2024/08/GHSA-7f4q-mxmp-vrc9/GHSA-7f4q-mxmp-vrc9.json create mode 100644 advisories/unreviewed/2024/08/GHSA-f8wm-p3c6-g898/GHSA-f8wm-p3c6-g898.json create mode 100644 advisories/unreviewed/2024/08/GHSA-fgw8-wccj-749x/GHSA-fgw8-wccj-749x.json create mode 100644 advisories/unreviewed/2024/08/GHSA-g4q4-8vjq-c7c8/GHSA-g4q4-8vjq-c7c8.json create mode 100644 advisories/unreviewed/2024/08/GHSA-g4w3-q8cv-798h/GHSA-g4w3-q8cv-798h.json create mode 100644 advisories/unreviewed/2024/08/GHSA-p844-wjq6-m36r/GHSA-p844-wjq6-m36r.json create mode 100644 advisories/unreviewed/2024/08/GHSA-r2cp-jr96-fmw7/GHSA-r2cp-jr96-fmw7.json create mode 100644 advisories/unreviewed/2024/08/GHSA-rr2m-vxfp-vgm4/GHSA-rr2m-vxfp-vgm4.json create mode 100644 advisories/unreviewed/2024/08/GHSA-vcqx-95xm-6xh4/GHSA-vcqx-95xm-6xh4.json create mode 100644 advisories/unreviewed/2024/08/GHSA-vqgx-gpv3-58p3/GHSA-vqgx-gpv3-58p3.json create mode 100644 advisories/unreviewed/2024/08/GHSA-x6qr-qghp-2wfr/GHSA-x6qr-qghp-2wfr.json create mode 100644 advisories/unreviewed/2024/08/GHSA-xhpw-qr8c-jfj2/GHSA-xhpw-qr8c-jfj2.json diff --git a/advisories/unreviewed/2024/08/GHSA-27h7-6m3c-wghw/GHSA-27h7-6m3c-wghw.json b/advisories/unreviewed/2024/08/GHSA-27h7-6m3c-wghw/GHSA-27h7-6m3c-wghw.json new file mode 100644 index 00000000000..ad654f02c71 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-27h7-6m3c-wghw/GHSA-27h7-6m3c-wghw.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27h7-6m3c-wghw", + "modified": "2024-08-01T06:30:34Z", + "published": "2024-08-01T06:30:34Z", + "aliases": [ + "CVE-2024-7338" + ], + "details": "A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument week/sTime/eTime leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273261 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7338" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/TOTOLINK/EX1200/setParentalRules.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273261" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273261" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.379316" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T04:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-28v8-9mr3-438f/GHSA-28v8-9mr3-438f.json b/advisories/unreviewed/2024/08/GHSA-28v8-9mr3-438f/GHSA-28v8-9mr3-438f.json new file mode 100644 index 00000000000..6d872e5b38d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-28v8-9mr3-438f/GHSA-28v8-9mr3-438f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28v8-9mr3-438f", + "modified": "2024-08-01T06:30:34Z", + "published": "2024-08-01T06:30:34Z", + "aliases": [ + "CVE-2024-2090" + ], + "details": "The Remote Content Shortcode plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5 via the remote_content shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2090" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/remote-content-shortcode" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ec93f360-2eed-4858-b36f-8cc17f7b4ac1?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T05:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7f4q-mxmp-vrc9/GHSA-7f4q-mxmp-vrc9.json b/advisories/unreviewed/2024/08/GHSA-7f4q-mxmp-vrc9/GHSA-7f4q-mxmp-vrc9.json new file mode 100644 index 00000000000..a7f2ab82ee4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7f4q-mxmp-vrc9/GHSA-7f4q-mxmp-vrc9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f4q-mxmp-vrc9", + "modified": "2024-08-01T06:30:34Z", + "published": "2024-08-01T06:30:34Z", + "aliases": [ + "CVE-2024-6698" + ], + "details": "The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying user meta updated through the update_user_meta function. This makes it possible for authenticated attackers, with subscriber-level access and above, to update their user meta which can be leveraged to update their capabilities to gain administrator access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6698" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3128099%40wp-fundraising-donation%2Ftrunk&old=3072093%40wp-fundraising-donation%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2ec6cf42-291b-452d-ad14-80ae1cd5ec5c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T04:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f8wm-p3c6-g898/GHSA-f8wm-p3c6-g898.json b/advisories/unreviewed/2024/08/GHSA-f8wm-p3c6-g898/GHSA-f8wm-p3c6-g898.json new file mode 100644 index 00000000000..f32af1c6caf --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f8wm-p3c6-g898/GHSA-f8wm-p3c6-g898.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8wm-p3c6-g898", + "modified": "2024-08-01T06:30:34Z", + "published": "2024-08-01T06:30:34Z", + "aliases": [ + "CVE-2024-3983" + ], + "details": "The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting customers via CSRF attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3983" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/e4059d66-07b9-4f1a-a461-d6e8f0e98eec" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T06:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fgw8-wccj-749x/GHSA-fgw8-wccj-749x.json b/advisories/unreviewed/2024/08/GHSA-fgw8-wccj-749x/GHSA-fgw8-wccj-749x.json new file mode 100644 index 00000000000..516f8018720 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fgw8-wccj-749x/GHSA-fgw8-wccj-749x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgw8-wccj-749x", + "modified": "2024-08-01T06:30:34Z", + "published": "2024-08-01T06:30:34Z", + "aliases": [ + "CVE-2024-4090" + ], + "details": "The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4090" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/aedcb986-0f2b-4852-baf1-6cb61e83e109" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T06:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g4q4-8vjq-c7c8/GHSA-g4q4-8vjq-c7c8.json b/advisories/unreviewed/2024/08/GHSA-g4q4-8vjq-c7c8/GHSA-g4q4-8vjq-c7c8.json new file mode 100644 index 00000000000..77739badede --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g4q4-8vjq-c7c8/GHSA-g4q4-8vjq-c7c8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4q4-8vjq-c7c8", + "modified": "2024-08-01T06:30:35Z", + "published": "2024-08-01T06:30:35Z", + "aliases": [ + "CVE-2024-6529" + ], + "details": "The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6529" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/1a346c9a-cc1a-46b1-b27a-a77a38449933" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T06:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g4w3-q8cv-798h/GHSA-g4w3-q8cv-798h.json b/advisories/unreviewed/2024/08/GHSA-g4w3-q8cv-798h/GHSA-g4w3-q8cv-798h.json new file mode 100644 index 00000000000..c70ae4ceb74 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-g4w3-q8cv-798h/GHSA-g4w3-q8cv-798h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4w3-q8cv-798h", + "modified": "2024-08-01T06:30:34Z", + "published": "2024-08-01T06:30:34Z", + "aliases": [ + "CVE-2024-1715" + ], + "details": "The AdFoxly – Ad Manager, AdSense Ads & Ads.txt plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the adfoxly_ad_status() function in all versions up to, and including, 1.8.5. This makes it possible for unauthenticated attackers to enable and disable ads.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1715" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/adfoxly/trunk/includes/class-adfoxly-ajax.php#L80" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/84792202-d089-4dca-b950-16aea968c58e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T04:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-p844-wjq6-m36r/GHSA-p844-wjq6-m36r.json b/advisories/unreviewed/2024/08/GHSA-p844-wjq6-m36r/GHSA-p844-wjq6-m36r.json new file mode 100644 index 00000000000..1967ac9058d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-p844-wjq6-m36r/GHSA-p844-wjq6-m36r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p844-wjq6-m36r", + "modified": "2024-08-01T06:30:34Z", + "published": "2024-08-01T06:30:34Z", + "aliases": [ + "CVE-2024-2872" + ], + "details": "The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2872" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/15d3150c-673c-4c36-ac5e-85767d78b9eb" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T06:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-r2cp-jr96-fmw7/GHSA-r2cp-jr96-fmw7.json b/advisories/unreviewed/2024/08/GHSA-r2cp-jr96-fmw7/GHSA-r2cp-jr96-fmw7.json new file mode 100644 index 00000000000..ff6fb6ec292 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-r2cp-jr96-fmw7/GHSA-r2cp-jr96-fmw7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2cp-jr96-fmw7", + "modified": "2024-08-01T06:30:35Z", + "published": "2024-08-01T06:30:34Z", + "aliases": [ + "CVE-2024-6496" + ], + "details": "The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks when deleting polls, which could allow attackers to make logged in users perform such action via a CSRF attack", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6496" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d598eabd-a87a-4e3e-be46-a5c5cc3f130e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T06:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rr2m-vxfp-vgm4/GHSA-rr2m-vxfp-vgm4.json b/advisories/unreviewed/2024/08/GHSA-rr2m-vxfp-vgm4/GHSA-rr2m-vxfp-vgm4.json new file mode 100644 index 00000000000..4c28bd4d276 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rr2m-vxfp-vgm4/GHSA-rr2m-vxfp-vgm4.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr2m-vxfp-vgm4", + "modified": "2024-08-01T06:30:34Z", + "published": "2024-08-01T06:30:34Z", + "aliases": [ + "CVE-2024-7342" + ], + "details": "A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part of the file /ueditor/php/controller.php?action=uploadfile&encode=utf-8. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273273 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7342" + }, + { + "type": "WEB", + "url": "https://github.com/Hebing123/cve/issues/62" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273273" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273273" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.380092" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T05:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vcqx-95xm-6xh4/GHSA-vcqx-95xm-6xh4.json b/advisories/unreviewed/2024/08/GHSA-vcqx-95xm-6xh4/GHSA-vcqx-95xm-6xh4.json new file mode 100644 index 00000000000..d814ea33207 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vcqx-95xm-6xh4/GHSA-vcqx-95xm-6xh4.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcqx-95xm-6xh4", + "modified": "2024-08-01T06:30:34Z", + "published": "2024-08-01T06:30:34Z", + "aliases": [ + "CVE-2024-7339" + ], + "details": "A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION DVR AV108T and classified as problematic. This vulnerability affects unknown code of the file /queryDevInfo. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273262 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7339" + }, + { + "type": "WEB", + "url": "https://netsecfish.notion.site/Sensitive-Device-Information-Disclosure-in-TVT-DVR-fad1cce703d946969be5130bf3aaac0d?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273262" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273262" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.379373" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T04:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vqgx-gpv3-58p3/GHSA-vqgx-gpv3-58p3.json b/advisories/unreviewed/2024/08/GHSA-vqgx-gpv3-58p3/GHSA-vqgx-gpv3-58p3.json new file mode 100644 index 00000000000..ee0910a9d9d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vqgx-gpv3-58p3/GHSA-vqgx-gpv3-58p3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqgx-gpv3-58p3", + "modified": "2024-08-01T06:30:34Z", + "published": "2024-08-01T06:30:34Z", + "aliases": [ + "CVE-2024-1747" + ], + "details": "The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX actions, allowing any authenticated users, such as subscriber, to call them and update/delete/create customer metadata, also leading to Stored Cross-Site Scripting due to the lack of escaping of said metadata values.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1747" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/17e45d4d-0ee1-4863-a8a4-df8587f448ec" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T06:15:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x6qr-qghp-2wfr/GHSA-x6qr-qghp-2wfr.json b/advisories/unreviewed/2024/08/GHSA-x6qr-qghp-2wfr/GHSA-x6qr-qghp-2wfr.json new file mode 100644 index 00000000000..dcc38259bf0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x6qr-qghp-2wfr/GHSA-x6qr-qghp-2wfr.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6qr-qghp-2wfr", + "modified": "2024-08-01T06:30:34Z", + "published": "2024-08-01T06:30:34Z", + "aliases": [ + "CVE-2024-7343" + ], + "details": "A vulnerability was found in Baidu UEditor 1.4.2. It has been declared as problematic. This vulnerability affects unknown code of the file /ueditor142/php/controller.php?action=catchimage. The manipulation of the argument source[] leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273274 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7343" + }, + { + "type": "WEB", + "url": "https://github.com/Hebing123/cve/issues/63" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273274" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273274" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.380151" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T05:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xhpw-qr8c-jfj2/GHSA-xhpw-qr8c-jfj2.json b/advisories/unreviewed/2024/08/GHSA-xhpw-qr8c-jfj2/GHSA-xhpw-qr8c-jfj2.json new file mode 100644 index 00000000000..98a1b043984 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xhpw-qr8c-jfj2/GHSA-xhpw-qr8c-jfj2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhpw-qr8c-jfj2", + "modified": "2024-08-01T06:30:34Z", + "published": "2024-08-01T06:30:34Z", + "aliases": [ + "CVE-2024-2843" + ], + "details": "The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin users delete users via CSRF attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2843" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/fec4e077-4c4e-4618-bfe8-61fdba59b696" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-01T06:15:02Z" + } +} \ No newline at end of file