From 2482b0956f4ebade83854960356e3cf49b74a6dc Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sun, 28 Apr 2024 00:31:53 +0000 Subject: [PATCH] Publish Advisories GHSA-2239-pmp7-cm44 GHSA-3494-cfwf-56hw GHSA-5473-w6gq-5r5g GHSA-frhh-phxr-hpp9 GHSA-h9vv-8q8m-v6m6 GHSA-xh76-hgvx-8pp6 --- .../GHSA-2239-pmp7-cm44.json | 50 +++++++++++++++++++ .../GHSA-3494-cfwf-56hw.json | 35 +++++++++++++ .../GHSA-5473-w6gq-5r5g.json | 35 +++++++++++++ .../GHSA-frhh-phxr-hpp9.json | 50 +++++++++++++++++++ .../GHSA-h9vv-8q8m-v6m6.json | 38 ++++++++++++++ .../GHSA-xh76-hgvx-8pp6.json | 38 ++++++++++++++ 6 files changed, 246 insertions(+) create mode 100644 advisories/unreviewed/2024/04/GHSA-2239-pmp7-cm44/GHSA-2239-pmp7-cm44.json create mode 100644 advisories/unreviewed/2024/04/GHSA-3494-cfwf-56hw/GHSA-3494-cfwf-56hw.json create mode 100644 advisories/unreviewed/2024/04/GHSA-5473-w6gq-5r5g/GHSA-5473-w6gq-5r5g.json create mode 100644 advisories/unreviewed/2024/04/GHSA-frhh-phxr-hpp9/GHSA-frhh-phxr-hpp9.json create mode 100644 advisories/unreviewed/2024/04/GHSA-h9vv-8q8m-v6m6/GHSA-h9vv-8q8m-v6m6.json create mode 100644 advisories/unreviewed/2024/04/GHSA-xh76-hgvx-8pp6/GHSA-xh76-hgvx-8pp6.json diff --git a/advisories/unreviewed/2024/04/GHSA-2239-pmp7-cm44/GHSA-2239-pmp7-cm44.json b/advisories/unreviewed/2024/04/GHSA-2239-pmp7-cm44/GHSA-2239-pmp7-cm44.json new file mode 100644 index 00000000000..2900261f4af --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2239-pmp7-cm44/GHSA-2239-pmp7-cm44.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2239-pmp7-cm44", + "modified": "2024-04-28T00:30:23Z", + "published": "2024-04-28T00:30:23Z", + "aliases": [ + "CVE-2024-4294" + ], + "details": "A vulnerability, which was classified as critical, has been found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this issue is some unknown functionality of the file /doctor/view-appointment-detail.php. The manipulation of the argument editid leads to improper control of resource identifiers. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-262226 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4294" + }, + { + "type": "WEB", + "url": "https://github.com/Sospiro014/zday1/blob/main/doctor_appointment_management_system_idor.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.262226" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.262226" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.323597" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-99" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-27T23:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3494-cfwf-56hw/GHSA-3494-cfwf-56hw.json b/advisories/unreviewed/2024/04/GHSA-3494-cfwf-56hw/GHSA-3494-cfwf-56hw.json new file mode 100644 index 00000000000..a4900e7f1a4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3494-cfwf-56hw/GHSA-3494-cfwf-56hw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3494-cfwf-56hw", + "modified": "2024-04-28T00:30:22Z", + "published": "2024-04-28T00:30:22Z", + "aliases": [ + "CVE-2024-33851" + ], + "details": "phpecc, as used in paragonie/phpecc before 2.0.1, has a branch-based timing leak in Point addition. (This is related to phpecc/phpecc on GitHub, and the Matyas Danter ECC library.)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33851" + }, + { + "type": "WEB", + "url": "https://github.com/paragonie/phpecc/releases/tag/v2.0.1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-27T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5473-w6gq-5r5g/GHSA-5473-w6gq-5r5g.json b/advisories/unreviewed/2024/04/GHSA-5473-w6gq-5r5g/GHSA-5473-w6gq-5r5g.json new file mode 100644 index 00000000000..51be7574326 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5473-w6gq-5r5g/GHSA-5473-w6gq-5r5g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5473-w6gq-5r5g", + "modified": "2024-04-28T00:30:23Z", + "published": "2024-04-28T00:30:23Z", + "aliases": [ + "CVE-2023-52722" + ], + "details": "An issue was discovered in Artifex Ghostscript through 10.01.0. psi/zmisc1.c, when SAFER mode is used, allows eexec seeds other than the Type 1 standard.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52722" + }, + { + "type": "WEB", + "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=afd7188f74918cb51b5fb89f52b54eb16e8acfd1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-28T00:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-frhh-phxr-hpp9/GHSA-frhh-phxr-hpp9.json b/advisories/unreviewed/2024/04/GHSA-frhh-phxr-hpp9/GHSA-frhh-phxr-hpp9.json new file mode 100644 index 00000000000..9dfe433151d --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-frhh-phxr-hpp9/GHSA-frhh-phxr-hpp9.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frhh-phxr-hpp9", + "modified": "2024-04-28T00:30:23Z", + "published": "2024-04-28T00:30:23Z", + "aliases": [ + "CVE-2024-4293" + ], + "details": "A vulnerability classified as problematic was found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file appointment-bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-262225 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4293" + }, + { + "type": "WEB", + "url": "https://github.com/Sospiro014/zday1/blob/main/doctor_appointment_management_system_xss.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.262225" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.262225" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.323586" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-27T22:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-h9vv-8q8m-v6m6/GHSA-h9vv-8q8m-v6m6.json b/advisories/unreviewed/2024/04/GHSA-h9vv-8q8m-v6m6/GHSA-h9vv-8q8m-v6m6.json new file mode 100644 index 00000000000..7c7e30c2168 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h9vv-8q8m-v6m6/GHSA-h9vv-8q8m-v6m6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9vv-8q8m-v6m6", + "modified": "2024-04-28T00:30:23Z", + "published": "2024-04-28T00:30:23Z", + "aliases": [ + "CVE-2022-48684" + ], + "details": "An issue was discovered in Logpoint before 7.1.1. Template injection was seen in the search template. The search template uses jinja templating for generating dynamic data. This could be abused to achieve code execution. Any user with access to create a search template can leverage this to execute code as the loginspect user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48684" + }, + { + "type": "WEB", + "url": "https://servicedesk.logpoint.com/hc/en-us/articles/7201134201885-Template-injection-in-Search-Template" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-27T23:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xh76-hgvx-8pp6/GHSA-xh76-hgvx-8pp6.json b/advisories/unreviewed/2024/04/GHSA-xh76-hgvx-8pp6/GHSA-xh76-hgvx-8pp6.json new file mode 100644 index 00000000000..0adbece1b29 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xh76-hgvx-8pp6/GHSA-xh76-hgvx-8pp6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh76-hgvx-8pp6", + "modified": "2024-04-28T00:30:23Z", + "published": "2024-04-28T00:30:23Z", + "aliases": [ + "CVE-2022-48685" + ], + "details": "An issue was discovered in Logpoint 7.1 before 7.1.2. The daily executed cron file clean_secbi_old_logs is writable by all users and is executed as root, leading to privilege escalation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48685" + }, + { + "type": "WEB", + "url": "https://servicedesk.logpoint.com/hc/en-us/articles/7997112373277-Privilege-Escalation-Through-Cronjob" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-27T23:15:06Z" + } +} \ No newline at end of file