From 249e4213ac96aa07092481d6761ad5b8018c0fa6 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 21 Feb 2024 18:32:21 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-34vm-c5cx-4485.json | 42 +++++++++++ .../GHSA-3qqg-26c5-xqh7.json | 31 ++++++++ .../GHSA-4847-mppj-fwhp.json | 35 ++++++++++ .../GHSA-4x7r-c6x9-qgv3.json | 46 ++++++++++++ .../GHSA-5c29-m8gg-59qv.json | 35 ++++++++++ .../GHSA-5g46-qxcm-rg25.json | 46 ++++++++++++ .../GHSA-65x5-26gm-j9pq.json | 38 ++++++++++ .../GHSA-6m3q-9vch-f5gh.json | 46 ++++++++++++ .../GHSA-6vjx-p68v-62qm.json | 46 ++++++++++++ .../GHSA-84jg-5x72-v4h5.json | 46 ++++++++++++ .../GHSA-84vv-q8q9-r9j3.json | 35 ++++++++++ .../GHSA-8vv7-j7w3-28ww.json | 50 +++++++++++++ .../GHSA-9hhq-2548-mw44.json | 35 ++++++++++ .../GHSA-cg3j-75xh-7fv3.json | 70 +++++++++++++++++++ .../GHSA-cjwx-wwmv-rqgc.json | 35 ++++++++++ .../GHSA-fcrq-rvcv-57cf.json | 38 ++++++++++ .../GHSA-g4fx-wxmx-fjq5.json | 35 ++++++++++ .../GHSA-g759-2x5w-f89c.json | 35 ++++++++++ .../GHSA-j38w-4mxv-xjj3.json | 35 ++++++++++ .../GHSA-m7jv-93jg-r5j8.json | 46 ++++++++++++ .../GHSA-m9x5-g73r-5mcj.json | 46 ++++++++++++ .../GHSA-mmq5-phxp-hrxq.json | 39 +++++++++++ .../GHSA-mv62-4r83-58qq.json | 39 +++++++++++ .../GHSA-p535-33vp-92fr.json | 35 ++++++++++ .../GHSA-q2p3-j458-f7vv.json | 43 ++++++++++++ .../GHSA-rmvf-wrpj-7c43.json | 43 ++++++++++++ .../GHSA-v222-j2c4-g82m.json | 35 ++++++++++ .../GHSA-w32h-6ffq-r68m.json | 35 ++++++++++ .../GHSA-x5qv-8w36-gxh4.json | 31 ++++++++ 29 files changed, 1171 insertions(+) create mode 100644 advisories/unreviewed/2024/02/GHSA-34vm-c5cx-4485/GHSA-34vm-c5cx-4485.json create mode 100644 advisories/unreviewed/2024/02/GHSA-3qqg-26c5-xqh7/GHSA-3qqg-26c5-xqh7.json create mode 100644 advisories/unreviewed/2024/02/GHSA-4847-mppj-fwhp/GHSA-4847-mppj-fwhp.json create mode 100644 advisories/unreviewed/2024/02/GHSA-4x7r-c6x9-qgv3/GHSA-4x7r-c6x9-qgv3.json create mode 100644 advisories/unreviewed/2024/02/GHSA-5c29-m8gg-59qv/GHSA-5c29-m8gg-59qv.json create mode 100644 advisories/unreviewed/2024/02/GHSA-5g46-qxcm-rg25/GHSA-5g46-qxcm-rg25.json create mode 100644 advisories/unreviewed/2024/02/GHSA-65x5-26gm-j9pq/GHSA-65x5-26gm-j9pq.json create mode 100644 advisories/unreviewed/2024/02/GHSA-6m3q-9vch-f5gh/GHSA-6m3q-9vch-f5gh.json create mode 100644 advisories/unreviewed/2024/02/GHSA-6vjx-p68v-62qm/GHSA-6vjx-p68v-62qm.json create mode 100644 advisories/unreviewed/2024/02/GHSA-84jg-5x72-v4h5/GHSA-84jg-5x72-v4h5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-84vv-q8q9-r9j3/GHSA-84vv-q8q9-r9j3.json create mode 100644 advisories/unreviewed/2024/02/GHSA-8vv7-j7w3-28ww/GHSA-8vv7-j7w3-28ww.json create mode 100644 advisories/unreviewed/2024/02/GHSA-9hhq-2548-mw44/GHSA-9hhq-2548-mw44.json create mode 100644 advisories/unreviewed/2024/02/GHSA-cg3j-75xh-7fv3/GHSA-cg3j-75xh-7fv3.json create mode 100644 advisories/unreviewed/2024/02/GHSA-cjwx-wwmv-rqgc/GHSA-cjwx-wwmv-rqgc.json create mode 100644 advisories/unreviewed/2024/02/GHSA-fcrq-rvcv-57cf/GHSA-fcrq-rvcv-57cf.json create mode 100644 advisories/unreviewed/2024/02/GHSA-g4fx-wxmx-fjq5/GHSA-g4fx-wxmx-fjq5.json create mode 100644 advisories/unreviewed/2024/02/GHSA-g759-2x5w-f89c/GHSA-g759-2x5w-f89c.json create mode 100644 advisories/unreviewed/2024/02/GHSA-j38w-4mxv-xjj3/GHSA-j38w-4mxv-xjj3.json create mode 100644 advisories/unreviewed/2024/02/GHSA-m7jv-93jg-r5j8/GHSA-m7jv-93jg-r5j8.json create mode 100644 advisories/unreviewed/2024/02/GHSA-m9x5-g73r-5mcj/GHSA-m9x5-g73r-5mcj.json create mode 100644 advisories/unreviewed/2024/02/GHSA-mmq5-phxp-hrxq/GHSA-mmq5-phxp-hrxq.json create mode 100644 advisories/unreviewed/2024/02/GHSA-mv62-4r83-58qq/GHSA-mv62-4r83-58qq.json create mode 100644 advisories/unreviewed/2024/02/GHSA-p535-33vp-92fr/GHSA-p535-33vp-92fr.json create mode 100644 advisories/unreviewed/2024/02/GHSA-q2p3-j458-f7vv/GHSA-q2p3-j458-f7vv.json create mode 100644 advisories/unreviewed/2024/02/GHSA-rmvf-wrpj-7c43/GHSA-rmvf-wrpj-7c43.json create mode 100644 advisories/unreviewed/2024/02/GHSA-v222-j2c4-g82m/GHSA-v222-j2c4-g82m.json create mode 100644 advisories/unreviewed/2024/02/GHSA-w32h-6ffq-r68m/GHSA-w32h-6ffq-r68m.json create mode 100644 advisories/unreviewed/2024/02/GHSA-x5qv-8w36-gxh4/GHSA-x5qv-8w36-gxh4.json diff --git a/advisories/unreviewed/2024/02/GHSA-34vm-c5cx-4485/GHSA-34vm-c5cx-4485.json b/advisories/unreviewed/2024/02/GHSA-34vm-c5cx-4485/GHSA-34vm-c5cx-4485.json new file mode 100644 index 00000000000..befaae0695f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-34vm-c5cx-4485/GHSA-34vm-c5cx-4485.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34vm-c5cx-4485", + "modified": "2024-02-21T18:31:00Z", + "published": "2024-02-21T18:31:00Z", + "aliases": [ + "CVE-2024-1474" + ], + "details": "In WS_FTP Server versions before 8.8.5, reflected cross-site scripting issues have been identified on various user supplied inputs on the WS_FTP Server administrative interface.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1474" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-February-2024" + }, + { + "type": "WEB", + "url": "https://www.progress.com/ws_ftp" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-3qqg-26c5-xqh7/GHSA-3qqg-26c5-xqh7.json b/advisories/unreviewed/2024/02/GHSA-3qqg-26c5-xqh7/GHSA-3qqg-26c5-xqh7.json new file mode 100644 index 00000000000..849e7c1f517 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-3qqg-26c5-xqh7/GHSA-3qqg-26c5-xqh7.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qqg-26c5-xqh7", + "modified": "2024-02-21T18:31:01Z", + "published": "2024-02-21T18:31:01Z", + "aliases": [ + "CVE-2024-27215" + ], + "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1709. Reason: This candidate is a duplicate of CVE-2024-1709. Notes: All CVE users should reference CVE-2024-1709 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27215" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4847-mppj-fwhp/GHSA-4847-mppj-fwhp.json b/advisories/unreviewed/2024/02/GHSA-4847-mppj-fwhp/GHSA-4847-mppj-fwhp.json new file mode 100644 index 00000000000..08af5141c63 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4847-mppj-fwhp/GHSA-4847-mppj-fwhp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4847-mppj-fwhp", + "modified": "2024-02-21T18:31:02Z", + "published": "2024-02-21T18:31:02Z", + "aliases": [ + "CVE-2024-25892" + ], + "details": "ChurchCRM 5.5.0 ConfirmReport.php is vulnerable to Blind SQL Injection (Time-based) via the familyId GET parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25892" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/issues/6858" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-4x7r-c6x9-qgv3/GHSA-4x7r-c6x9-qgv3.json b/advisories/unreviewed/2024/02/GHSA-4x7r-c6x9-qgv3/GHSA-4x7r-c6x9-qgv3.json new file mode 100644 index 00000000000..5a5e3fcace9 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-4x7r-c6x9-qgv3/GHSA-4x7r-c6x9-qgv3.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x7r-c6x9-qgv3", + "modified": "2024-02-21T18:31:02Z", + "published": "2024-02-21T18:31:02Z", + "aliases": [ + "CVE-2024-1704" + ], + "details": "A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been declared as critical. This vulnerability affects the function save/delete of the file /adminapi/system/crud. The manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254392. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1704" + }, + { + "type": "WEB", + "url": "https://github.com/Echosssy/CVE/blob/main/%E4%BC%97%E9%82%A6%E7%A7%91%E6%8A%80CRMEB%20Mall%20business%20edition%20overrides%20any%20file.docx" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254392" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254392" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-5c29-m8gg-59qv/GHSA-5c29-m8gg-59qv.json b/advisories/unreviewed/2024/02/GHSA-5c29-m8gg-59qv/GHSA-5c29-m8gg-59qv.json new file mode 100644 index 00000000000..9a2506f6709 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-5c29-m8gg-59qv/GHSA-5c29-m8gg-59qv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c29-m8gg-59qv", + "modified": "2024-02-21T18:31:02Z", + "published": "2024-02-21T18:31:02Z", + "aliases": [ + "CVE-2024-25895" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter of /EventAttendance.php", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25895" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/issues/6853" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-5g46-qxcm-rg25/GHSA-5g46-qxcm-rg25.json b/advisories/unreviewed/2024/02/GHSA-5g46-qxcm-rg25/GHSA-5g46-qxcm-rg25.json new file mode 100644 index 00000000000..eadef3822e3 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-5g46-qxcm-rg25/GHSA-5g46-qxcm-rg25.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g46-qxcm-rg25", + "modified": "2024-02-21T18:31:02Z", + "published": "2024-02-21T18:31:02Z", + "aliases": [ + "CVE-2024-1705" + ], + "details": "A vulnerability was found in Shopwind up to 4.6. It has been rated as critical. This issue affects the function actionCreate of the file /public/install/controllers/DefaultController.php of the component Installation. The manipulation leads to code injection. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-254393 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1705" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/QHdXavkw5eDm" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254393" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254393" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-65x5-26gm-j9pq/GHSA-65x5-26gm-j9pq.json b/advisories/unreviewed/2024/02/GHSA-65x5-26gm-j9pq/GHSA-65x5-26gm-j9pq.json new file mode 100644 index 00000000000..bf46631d0e4 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-65x5-26gm-j9pq/GHSA-65x5-26gm-j9pq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65x5-26gm-j9pq", + "modified": "2024-02-21T18:31:01Z", + "published": "2024-02-21T18:31:01Z", + "aliases": [ + "CVE-2024-1708" + ], + "details": "ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker \n\nthe ability to execute remote code or directly impact confidential data or critical systems.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1708" + }, + { + "type": "WEB", + "url": "https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-6m3q-9vch-f5gh/GHSA-6m3q-9vch-f5gh.json b/advisories/unreviewed/2024/02/GHSA-6m3q-9vch-f5gh/GHSA-6m3q-9vch-f5gh.json new file mode 100644 index 00000000000..aa2947993b8 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-6m3q-9vch-f5gh/GHSA-6m3q-9vch-f5gh.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m3q-9vch-f5gh", + "modified": "2024-02-21T18:31:00Z", + "published": "2024-02-21T18:31:00Z", + "aliases": [ + "CVE-2024-1700" + ], + "details": "A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected is an unknown function of the file /signup.php. The manipulation of the argument username with the input leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254388. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1700" + }, + { + "type": "WEB", + "url": "https://github.com/omarexala/PHP-MYSQL-User-Login-System---Stored-XSS" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254388" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254388" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-6vjx-p68v-62qm/GHSA-6vjx-p68v-62qm.json b/advisories/unreviewed/2024/02/GHSA-6vjx-p68v-62qm/GHSA-6vjx-p68v-62qm.json new file mode 100644 index 00000000000..ea19802be0b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-6vjx-p68v-62qm/GHSA-6vjx-p68v-62qm.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vjx-p68v-62qm", + "modified": "2024-02-21T18:31:00Z", + "published": "2024-02-21T18:31:00Z", + "aliases": [ + "CVE-2024-1701" + ], + "details": "A vulnerability has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edit.php. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-254389 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1701" + }, + { + "type": "WEB", + "url": "https://github.com/omarexala/PHP-MYSQL-User-Login-System---Broken-Access-Control" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254389" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254389" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-84jg-5x72-v4h5/GHSA-84jg-5x72-v4h5.json b/advisories/unreviewed/2024/02/GHSA-84jg-5x72-v4h5/GHSA-84jg-5x72-v4h5.json new file mode 100644 index 00000000000..b82d73e8f7c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-84jg-5x72-v4h5/GHSA-84jg-5x72-v4h5.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84jg-5x72-v4h5", + "modified": "2024-02-21T18:31:02Z", + "published": "2024-02-21T18:31:02Z", + "aliases": [ + "CVE-2024-1706" + ], + "details": "A vulnerability, which was classified as problematic, has been found in ZKTeco ZKBio Access IVS up to 3.3.2. Affected by this issue is some unknown functionality of the component Department Name Search Bar. The manipulation with the input hi leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254396. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1706" + }, + { + "type": "WEB", + "url": "https://gist.githubusercontent.com/whiteman007/8d3a09991de4ef336937ba91c07b7856/raw/adc00538d7a8c3c54bde4797a10d9b6af393711d/gistfile1.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254396" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254396" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-84vv-q8q9-r9j3/GHSA-84vv-q8q9-r9j3.json b/advisories/unreviewed/2024/02/GHSA-84vv-q8q9-r9j3/GHSA-84vv-q8q9-r9j3.json new file mode 100644 index 00000000000..307dd41eaab --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-84vv-q8q9-r9j3/GHSA-84vv-q8q9-r9j3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84vv-q8q9-r9j3", + "modified": "2024-02-21T18:31:02Z", + "published": "2024-02-21T18:31:02Z", + "aliases": [ + "CVE-2024-25897" + ], + "details": "ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25897" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/issues/6856" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-8vv7-j7w3-28ww/GHSA-8vv7-j7w3-28ww.json b/advisories/unreviewed/2024/02/GHSA-8vv7-j7w3-28ww/GHSA-8vv7-j7w3-28ww.json new file mode 100644 index 00000000000..b9d267d231d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-8vv7-j7w3-28ww/GHSA-8vv7-j7w3-28ww.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vv7-j7w3-28ww", + "modified": "2024-02-21T18:31:02Z", + "published": "2024-02-21T18:31:02Z", + "aliases": [ + "CVE-2024-1212" + ], + "details": "Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1212" + }, + { + "type": "WEB", + "url": "https://freeloadbalancer.com" + }, + { + "type": "WEB", + "url": "https://kemptechnologies.com" + }, + { + "type": "WEB", + "url": "https://support.kemptechnologies.com/hc/en-us/articles/23878931058445-LoadMaster-Security-Vulnerability-CVE-2024-1212" + }, + { + "type": "WEB", + "url": "https://support.kemptechnologies.com/hc/en-us/articles/24325072850573-Release-Notice-LMOS-7-2-59-2-7-2-54-8-7-2-48-10-CVE-2024-1212" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T18:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-9hhq-2548-mw44/GHSA-9hhq-2548-mw44.json b/advisories/unreviewed/2024/02/GHSA-9hhq-2548-mw44/GHSA-9hhq-2548-mw44.json new file mode 100644 index 00000000000..0f581c2e227 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-9hhq-2548-mw44/GHSA-9hhq-2548-mw44.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hhq-2548-mw44", + "modified": "2024-02-21T18:31:02Z", + "published": "2024-02-21T18:31:02Z", + "aliases": [ + "CVE-2024-25891" + ], + "details": "ChurchCRM 5.5.0 FRBidSheets.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25891" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/issues/6856" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-cg3j-75xh-7fv3/GHSA-cg3j-75xh-7fv3.json b/advisories/unreviewed/2024/02/GHSA-cg3j-75xh-7fv3/GHSA-cg3j-75xh-7fv3.json new file mode 100644 index 00000000000..739623c1963 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-cg3j-75xh-7fv3/GHSA-cg3j-75xh-7fv3.json @@ -0,0 +1,70 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg3j-75xh-7fv3", + "modified": "2024-02-21T18:31:01Z", + "published": "2024-02-21T18:31:01Z", + "aliases": [ + "CVE-2024-1709" + ], + "details": "ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel\n\n vulnerability, which may allow an attacker direct access to confidential information or \n\ncritical systems.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1709" + }, + { + "type": "WEB", + "url": "https://github.com/rapid7/metasploit-framework/pull/18870" + }, + { + "type": "WEB", + "url": "https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc" + }, + { + "type": "WEB", + "url": "https://techcrunch.com/2024/02/21/researchers-warn-high-risk-connectwise-flaw-under-attack-is-embarrassingly-easy-to-exploit" + }, + { + "type": "WEB", + "url": "https://www.bleepingcomputer.com/news/security/connectwise-urges-screenconnect-admins-to-patch-critical-rce-flaw" + }, + { + "type": "WEB", + "url": "https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8" + }, + { + "type": "WEB", + "url": "https://www.horizon3.ai/attack-research/red-team/connectwise-screenconnect-auth-bypass-deep-dive" + }, + { + "type": "WEB", + "url": "https://www.huntress.com/blog/detection-guidance-for-connectwise-cwe-288-2" + }, + { + "type": "WEB", + "url": "https://www.huntress.com/blog/vulnerability-reproduced-immediately-patch-screenconnect-23-9-8" + }, + { + "type": "WEB", + "url": "https://www.securityweek.com/connectwise-confirms-screenconnect-flaw-under-active-exploitation" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-cjwx-wwmv-rqgc/GHSA-cjwx-wwmv-rqgc.json b/advisories/unreviewed/2024/02/GHSA-cjwx-wwmv-rqgc/GHSA-cjwx-wwmv-rqgc.json new file mode 100644 index 00000000000..dceb5116614 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-cjwx-wwmv-rqgc/GHSA-cjwx-wwmv-rqgc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjwx-wwmv-rqgc", + "modified": "2024-02-21T18:31:00Z", + "published": "2024-02-21T18:31:00Z", + "aliases": [ + "CVE-2022-45169" + ], + "details": "An issue was discovered in LIVEBOX Collaboration vDesk through v031. A URL Redirection to an Untrusted Site (Open Redirect) can occur under the /api/v1/notification/createnotification endpoint, allowing an authenticated user to send an arbitrary push notification to any other user of the system. This push notification can include an (invisible) clickable link.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45169" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-fcrq-rvcv-57cf/GHSA-fcrq-rvcv-57cf.json b/advisories/unreviewed/2024/02/GHSA-fcrq-rvcv-57cf/GHSA-fcrq-rvcv-57cf.json new file mode 100644 index 00000000000..53a84300914 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-fcrq-rvcv-57cf/GHSA-fcrq-rvcv-57cf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcrq-rvcv-57cf", + "modified": "2024-02-21T18:31:02Z", + "published": "2024-02-21T18:31:02Z", + "aliases": [ + "CVE-2024-20325" + ], + "details": "A vulnerability in the Live Data server of Cisco Unified Intelligence Center could allow an unauthenticated, local attacker to read and modify data in a repository that belongs to an internal service on an affected device.\n\n This vulnerability is due to insufficient access control implementations on cluster configuration CLI requests. An attacker could exploit this vulnerability by sending a cluster configuration CLI request to specific directories on an affected device. A successful exploit could allow the attacker to read and modify data that is handled by an internal service on the affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20325" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cuic-access-control-jJsZQMjj" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-g4fx-wxmx-fjq5/GHSA-g4fx-wxmx-fjq5.json b/advisories/unreviewed/2024/02/GHSA-g4fx-wxmx-fjq5/GHSA-g4fx-wxmx-fjq5.json new file mode 100644 index 00000000000..1da3c9a80e2 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-g4fx-wxmx-fjq5/GHSA-g4fx-wxmx-fjq5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4fx-wxmx-fjq5", + "modified": "2024-02-21T18:31:02Z", + "published": "2024-02-21T18:31:02Z", + "aliases": [ + "CVE-2024-25893" + ], + "details": "ChurchCRM 5.5.0 FRCertificates.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25893" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/issues/6856" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-g759-2x5w-f89c/GHSA-g759-2x5w-f89c.json b/advisories/unreviewed/2024/02/GHSA-g759-2x5w-f89c/GHSA-g759-2x5w-f89c.json new file mode 100644 index 00000000000..db9165a5aff --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-g759-2x5w-f89c/GHSA-g759-2x5w-f89c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g759-2x5w-f89c", + "modified": "2024-02-21T18:31:00Z", + "published": "2024-02-21T18:31:00Z", + "aliases": [ + "CVE-2022-45177" + ], + "details": "An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and the /login endpoint. The web application provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45177" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-j38w-4mxv-xjj3/GHSA-j38w-4mxv-xjj3.json b/advisories/unreviewed/2024/02/GHSA-j38w-4mxv-xjj3/GHSA-j38w-4mxv-xjj3.json new file mode 100644 index 00000000000..9e8304c0438 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-j38w-4mxv-xjj3/GHSA-j38w-4mxv-xjj3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j38w-4mxv-xjj3", + "modified": "2024-02-21T18:31:02Z", + "published": "2024-02-21T18:31:02Z", + "aliases": [ + "CVE-2024-25894" + ], + "details": "ChurchCRM 5.5.0 /EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EventCount POST parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25894" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/issues/6849" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-m7jv-93jg-r5j8/GHSA-m7jv-93jg-r5j8.json b/advisories/unreviewed/2024/02/GHSA-m7jv-93jg-r5j8/GHSA-m7jv-93jg-r5j8.json new file mode 100644 index 00000000000..e59377178a6 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-m7jv-93jg-r5j8/GHSA-m7jv-93jg-r5j8.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7jv-93jg-r5j8", + "modified": "2024-02-21T18:31:01Z", + "published": "2024-02-21T18:31:01Z", + "aliases": [ + "CVE-2024-1702" + ], + "details": "A vulnerability was found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /edit.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-254390 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1702" + }, + { + "type": "WEB", + "url": "https://github.com/omarexala/PHP-MYSQL-User-Login-System---SQL-Injection" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254390" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254390" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-m9x5-g73r-5mcj/GHSA-m9x5-g73r-5mcj.json b/advisories/unreviewed/2024/02/GHSA-m9x5-g73r-5mcj/GHSA-m9x5-g73r-5mcj.json new file mode 100644 index 00000000000..9b9d0d0d48f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-m9x5-g73r-5mcj/GHSA-m9x5-g73r-5mcj.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9x5-g73r-5mcj", + "modified": "2024-02-21T18:31:02Z", + "published": "2024-02-21T18:31:01Z", + "aliases": [ + "CVE-2024-1703" + ], + "details": "A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been classified as problematic. This affects the function openfile of the file /adminapi/system/file/openfile. The manipulation leads to absolute path traversal. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254391. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1703" + }, + { + "type": "WEB", + "url": "https://github.com/Echosssy/-CRMEB-Mall-commercial-version-of-any-file-read-vulnerability/blob/main/README.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.254391" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.254391" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mmq5-phxp-hrxq/GHSA-mmq5-phxp-hrxq.json b/advisories/unreviewed/2024/02/GHSA-mmq5-phxp-hrxq/GHSA-mmq5-phxp-hrxq.json new file mode 100644 index 00000000000..b3dcab3d88b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mmq5-phxp-hrxq/GHSA-mmq5-phxp-hrxq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmq5-phxp-hrxq", + "modified": "2024-02-21T18:31:01Z", + "published": "2024-02-21T18:31:01Z", + "aliases": [ + "CVE-2024-22220" + ], + "details": "An issue was discovered in Terminalfour 7.4 through 7.4.0004 QP3 and 8 through 8.3.19, and Formbank through 2.1.10-FINAL. Unauthenticated Stored Cross-Site Scripting can occur, with resultant Admin Session Hijacking. The attack vectors are Form Builder and Form Preview.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22220" + }, + { + "type": "WEB", + "url": "https://docs.terminalfour.com/articles/release-notes-highlights" + }, + { + "type": "WEB", + "url": "https://docs.terminalfour.com/release-notes/security-notices/cve-2024-22220" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T16:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mv62-4r83-58qq/GHSA-mv62-4r83-58qq.json b/advisories/unreviewed/2024/02/GHSA-mv62-4r83-58qq/GHSA-mv62-4r83-58qq.json new file mode 100644 index 00000000000..553f56bf376 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mv62-4r83-58qq/GHSA-mv62-4r83-58qq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv62-4r83-58qq", + "modified": "2024-02-21T18:31:02Z", + "published": "2024-02-21T18:31:02Z", + "aliases": [ + "CVE-2024-25288" + ], + "details": "SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25288" + }, + { + "type": "WEB", + "url": "https://github.com/slims/slims9_bulian/issues/229" + }, + { + "type": "WEB", + "url": "https://github.com/Vuln0wned/slims_owned/blob/main/slims/slims9-bulian-9.6.1-SQLI-pop_scope_vocabolary.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p535-33vp-92fr/GHSA-p535-33vp-92fr.json b/advisories/unreviewed/2024/02/GHSA-p535-33vp-92fr/GHSA-p535-33vp-92fr.json new file mode 100644 index 00000000000..ff5d6750f55 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-p535-33vp-92fr/GHSA-p535-33vp-92fr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p535-33vp-92fr", + "modified": "2024-02-21T18:31:02Z", + "published": "2024-02-21T18:31:02Z", + "aliases": [ + "CVE-2024-25898" + ], + "details": "A XSS vulnerability was found in the ChurchCRM v.5.5.0 functionality, edit your event, where malicious JS or HTML code can be inserted in the Event Sermon field in EventEditor.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25898" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/issues/6851" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-q2p3-j458-f7vv/GHSA-q2p3-j458-f7vv.json b/advisories/unreviewed/2024/02/GHSA-q2p3-j458-f7vv/GHSA-q2p3-j458-f7vv.json new file mode 100644 index 00000000000..a71339eb051 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-q2p3-j458-f7vv/GHSA-q2p3-j458-f7vv.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2p3-j458-f7vv", + "modified": "2024-02-21T18:31:02Z", + "published": "2024-02-21T18:31:02Z", + "aliases": [ + "CVE-2024-24478" + ], + "details": "An issue in Wireshark team Wireshark before v.4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24478" + }, + { + "type": "WEB", + "url": "https://github.com/wireshark/wireshark/commit/80a4dc55f4d2fa33c2b36a99406500726d3faaef" + }, + { + "type": "WEB", + "url": "https://gist.github.com/1047524396/e82c55147cd3cb62ef20cbdb0ec83694" + }, + { + "type": "WEB", + "url": "https://gitlab.com/wireshark/wireshark/-/issues/19347" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-rmvf-wrpj-7c43/GHSA-rmvf-wrpj-7c43.json b/advisories/unreviewed/2024/02/GHSA-rmvf-wrpj-7c43/GHSA-rmvf-wrpj-7c43.json new file mode 100644 index 00000000000..841b7f09aa7 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-rmvf-wrpj-7c43/GHSA-rmvf-wrpj-7c43.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmvf-wrpj-7c43", + "modified": "2024-02-21T18:31:00Z", + "published": "2024-02-21T18:31:00Z", + "aliases": [ + "CVE-2023-49100" + ], + "details": "Trusted Firmware-A (TF-A) before 2.10 has a potential read out-of-bounds in the SDEI service. The input parameter passed in register x1 is not validated well enough in the function sdei_interrupt_bind. The parameter is passed to a call to plat_ic_get_interrupt_type. It can be any arbitrary value passing checks in the function plat_ic_is_sgi. A compromised Normal World (Linux kernel) can enable a root-privileged attacker to issue arbitrary SMC calls. Using this primitive, he can control the content of registers x0 through x6, which are used to send parameters to TF-A. Out-of-bounds addresses can be read in the context of TF-A (EL3). Because the read value is never returned to non-secure memory or in registers, no leak is possible. An attacker can still crash TF-A, however.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49100" + }, + { + "type": "WEB", + "url": "https://github.com/ARM-software/arm-trusted-firmware/blob/a05414bedc9b1cc35cf0795ce641b6b4db5bc97e/services/std_svc/sdei/sdei_main.c#L708" + }, + { + "type": "WEB", + "url": "https://github.com/ARM-software/arm-trusted-firmware/blob/a05414bedc9b1cc35cf0795ce641b6b4db5bc97e/services/std_svc/sdei/sdei_main.c#L714" + }, + { + "type": "WEB", + "url": "https://trustedfirmware-a.readthedocs.io/en/latest/security_advisories/security-advisory-tfv-11.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v222-j2c4-g82m/GHSA-v222-j2c4-g82m.json b/advisories/unreviewed/2024/02/GHSA-v222-j2c4-g82m/GHSA-v222-j2c4-g82m.json new file mode 100644 index 00000000000..091d8b9c48c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-v222-j2c4-g82m/GHSA-v222-j2c4-g82m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v222-j2c4-g82m", + "modified": "2024-02-21T18:31:02Z", + "published": "2024-02-21T18:31:02Z", + "aliases": [ + "CVE-2024-25896" + ], + "details": "ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25896" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/issues/6854" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T18:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-w32h-6ffq-r68m/GHSA-w32h-6ffq-r68m.json b/advisories/unreviewed/2024/02/GHSA-w32h-6ffq-r68m/GHSA-w32h-6ffq-r68m.json new file mode 100644 index 00000000000..31eefabaabe --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-w32h-6ffq-r68m/GHSA-w32h-6ffq-r68m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w32h-6ffq-r68m", + "modified": "2024-02-21T18:31:00Z", + "published": "2024-02-21T18:31:00Z", + "aliases": [ + "CVE-2022-45179" + ], + "details": "An issue was discovered in LIVEBOX Collaboration vDesk through v031. A basic XSS vulnerability exists under the /api/v1/vdeskintegration/todo/createorupdate endpoint via the title parameter and /dashboard/reminders. A remote user (authenticated to the product) can store arbitrary HTML code in the reminder section title in order to corrupt the web page (for example, by creating phishing sections to exfiltrate victims' credentials).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45179" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T16:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-x5qv-8w36-gxh4/GHSA-x5qv-8w36-gxh4.json b/advisories/unreviewed/2024/02/GHSA-x5qv-8w36-gxh4/GHSA-x5qv-8w36-gxh4.json new file mode 100644 index 00000000000..04e39cc1b12 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-x5qv-8w36-gxh4/GHSA-x5qv-8w36-gxh4.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5qv-8w36-gxh4", + "modified": "2024-02-21T18:31:02Z", + "published": "2024-02-21T18:31:02Z", + "aliases": [ + "CVE-2024-1714" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1714" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-21T17:15:09Z" + } +} \ No newline at end of file