From 249e4213ac96aa07092481d6761ad5b8018c0fa6 Mon Sep 17 00:00:00 2001
From: "advisory-database[bot]"
<45398580+advisory-database[bot]@users.noreply.github.com>
Date: Wed, 21 Feb 2024 18:32:21 +0000
Subject: [PATCH] Advisory Database Sync
---
.../GHSA-34vm-c5cx-4485.json | 42 +++++++++++
.../GHSA-3qqg-26c5-xqh7.json | 31 ++++++++
.../GHSA-4847-mppj-fwhp.json | 35 ++++++++++
.../GHSA-4x7r-c6x9-qgv3.json | 46 ++++++++++++
.../GHSA-5c29-m8gg-59qv.json | 35 ++++++++++
.../GHSA-5g46-qxcm-rg25.json | 46 ++++++++++++
.../GHSA-65x5-26gm-j9pq.json | 38 ++++++++++
.../GHSA-6m3q-9vch-f5gh.json | 46 ++++++++++++
.../GHSA-6vjx-p68v-62qm.json | 46 ++++++++++++
.../GHSA-84jg-5x72-v4h5.json | 46 ++++++++++++
.../GHSA-84vv-q8q9-r9j3.json | 35 ++++++++++
.../GHSA-8vv7-j7w3-28ww.json | 50 +++++++++++++
.../GHSA-9hhq-2548-mw44.json | 35 ++++++++++
.../GHSA-cg3j-75xh-7fv3.json | 70 +++++++++++++++++++
.../GHSA-cjwx-wwmv-rqgc.json | 35 ++++++++++
.../GHSA-fcrq-rvcv-57cf.json | 38 ++++++++++
.../GHSA-g4fx-wxmx-fjq5.json | 35 ++++++++++
.../GHSA-g759-2x5w-f89c.json | 35 ++++++++++
.../GHSA-j38w-4mxv-xjj3.json | 35 ++++++++++
.../GHSA-m7jv-93jg-r5j8.json | 46 ++++++++++++
.../GHSA-m9x5-g73r-5mcj.json | 46 ++++++++++++
.../GHSA-mmq5-phxp-hrxq.json | 39 +++++++++++
.../GHSA-mv62-4r83-58qq.json | 39 +++++++++++
.../GHSA-p535-33vp-92fr.json | 35 ++++++++++
.../GHSA-q2p3-j458-f7vv.json | 43 ++++++++++++
.../GHSA-rmvf-wrpj-7c43.json | 43 ++++++++++++
.../GHSA-v222-j2c4-g82m.json | 35 ++++++++++
.../GHSA-w32h-6ffq-r68m.json | 35 ++++++++++
.../GHSA-x5qv-8w36-gxh4.json | 31 ++++++++
29 files changed, 1171 insertions(+)
create mode 100644 advisories/unreviewed/2024/02/GHSA-34vm-c5cx-4485/GHSA-34vm-c5cx-4485.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-3qqg-26c5-xqh7/GHSA-3qqg-26c5-xqh7.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-4847-mppj-fwhp/GHSA-4847-mppj-fwhp.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-4x7r-c6x9-qgv3/GHSA-4x7r-c6x9-qgv3.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-5c29-m8gg-59qv/GHSA-5c29-m8gg-59qv.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-5g46-qxcm-rg25/GHSA-5g46-qxcm-rg25.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-65x5-26gm-j9pq/GHSA-65x5-26gm-j9pq.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-6m3q-9vch-f5gh/GHSA-6m3q-9vch-f5gh.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-6vjx-p68v-62qm/GHSA-6vjx-p68v-62qm.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-84jg-5x72-v4h5/GHSA-84jg-5x72-v4h5.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-84vv-q8q9-r9j3/GHSA-84vv-q8q9-r9j3.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-8vv7-j7w3-28ww/GHSA-8vv7-j7w3-28ww.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-9hhq-2548-mw44/GHSA-9hhq-2548-mw44.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-cg3j-75xh-7fv3/GHSA-cg3j-75xh-7fv3.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-cjwx-wwmv-rqgc/GHSA-cjwx-wwmv-rqgc.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-fcrq-rvcv-57cf/GHSA-fcrq-rvcv-57cf.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-g4fx-wxmx-fjq5/GHSA-g4fx-wxmx-fjq5.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-g759-2x5w-f89c/GHSA-g759-2x5w-f89c.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-j38w-4mxv-xjj3/GHSA-j38w-4mxv-xjj3.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-m7jv-93jg-r5j8/GHSA-m7jv-93jg-r5j8.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-m9x5-g73r-5mcj/GHSA-m9x5-g73r-5mcj.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-mmq5-phxp-hrxq/GHSA-mmq5-phxp-hrxq.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-mv62-4r83-58qq/GHSA-mv62-4r83-58qq.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-p535-33vp-92fr/GHSA-p535-33vp-92fr.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-q2p3-j458-f7vv/GHSA-q2p3-j458-f7vv.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-rmvf-wrpj-7c43/GHSA-rmvf-wrpj-7c43.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-v222-j2c4-g82m/GHSA-v222-j2c4-g82m.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-w32h-6ffq-r68m/GHSA-w32h-6ffq-r68m.json
create mode 100644 advisories/unreviewed/2024/02/GHSA-x5qv-8w36-gxh4/GHSA-x5qv-8w36-gxh4.json
diff --git a/advisories/unreviewed/2024/02/GHSA-34vm-c5cx-4485/GHSA-34vm-c5cx-4485.json b/advisories/unreviewed/2024/02/GHSA-34vm-c5cx-4485/GHSA-34vm-c5cx-4485.json
new file mode 100644
index 00000000000..befaae0695f
--- /dev/null
+++ b/advisories/unreviewed/2024/02/GHSA-34vm-c5cx-4485/GHSA-34vm-c5cx-4485.json
@@ -0,0 +1,42 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-34vm-c5cx-4485",
+ "modified": "2024-02-21T18:31:00Z",
+ "published": "2024-02-21T18:31:00Z",
+ "aliases": [
+ "CVE-2024-1474"
+ ],
+ "details": "In WS_FTP Server versions before 8.8.5, reflected cross-site scripting issues have been identified on various user supplied inputs on the WS_FTP Server administrative interface.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1474"
+ },
+ {
+ "type": "WEB",
+ "url": "https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-February-2024"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.progress.com/ws_ftp"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-02-21T16:15:49Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/02/GHSA-3qqg-26c5-xqh7/GHSA-3qqg-26c5-xqh7.json b/advisories/unreviewed/2024/02/GHSA-3qqg-26c5-xqh7/GHSA-3qqg-26c5-xqh7.json
new file mode 100644
index 00000000000..849e7c1f517
--- /dev/null
+++ b/advisories/unreviewed/2024/02/GHSA-3qqg-26c5-xqh7/GHSA-3qqg-26c5-xqh7.json
@@ -0,0 +1,31 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3qqg-26c5-xqh7",
+ "modified": "2024-02-21T18:31:01Z",
+ "published": "2024-02-21T18:31:01Z",
+ "aliases": [
+ "CVE-2024-27215"
+ ],
+ "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1709. Reason: This candidate is a duplicate of CVE-2024-1709. Notes: All CVE users should reference CVE-2024-1709 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27215"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-02-21T16:15:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/02/GHSA-4847-mppj-fwhp/GHSA-4847-mppj-fwhp.json b/advisories/unreviewed/2024/02/GHSA-4847-mppj-fwhp/GHSA-4847-mppj-fwhp.json
new file mode 100644
index 00000000000..08af5141c63
--- /dev/null
+++ b/advisories/unreviewed/2024/02/GHSA-4847-mppj-fwhp/GHSA-4847-mppj-fwhp.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4847-mppj-fwhp",
+ "modified": "2024-02-21T18:31:02Z",
+ "published": "2024-02-21T18:31:02Z",
+ "aliases": [
+ "CVE-2024-25892"
+ ],
+ "details": "ChurchCRM 5.5.0 ConfirmReport.php is vulnerable to Blind SQL Injection (Time-based) via the familyId GET parameter.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25892"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/ChurchCRM/CRM/issues/6858"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-02-21T18:15:51Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/02/GHSA-4x7r-c6x9-qgv3/GHSA-4x7r-c6x9-qgv3.json b/advisories/unreviewed/2024/02/GHSA-4x7r-c6x9-qgv3/GHSA-4x7r-c6x9-qgv3.json
new file mode 100644
index 00000000000..5a5e3fcace9
--- /dev/null
+++ b/advisories/unreviewed/2024/02/GHSA-4x7r-c6x9-qgv3/GHSA-4x7r-c6x9-qgv3.json
@@ -0,0 +1,46 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4x7r-c6x9-qgv3",
+ "modified": "2024-02-21T18:31:02Z",
+ "published": "2024-02-21T18:31:02Z",
+ "aliases": [
+ "CVE-2024-1704"
+ ],
+ "details": "A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been declared as critical. This vulnerability affects the function save/delete of the file /adminapi/system/crud. The manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254392. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1704"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/Echosssy/CVE/blob/main/%E4%BC%97%E9%82%A6%E7%A7%91%E6%8A%80CRMEB%20Mall%20business%20edition%20overrides%20any%20file.docx"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.254392"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.254392"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-22"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-02-21T18:15:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/02/GHSA-5c29-m8gg-59qv/GHSA-5c29-m8gg-59qv.json b/advisories/unreviewed/2024/02/GHSA-5c29-m8gg-59qv/GHSA-5c29-m8gg-59qv.json
new file mode 100644
index 00000000000..9a2506f6709
--- /dev/null
+++ b/advisories/unreviewed/2024/02/GHSA-5c29-m8gg-59qv/GHSA-5c29-m8gg-59qv.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5c29-m8gg-59qv",
+ "modified": "2024-02-21T18:31:02Z",
+ "published": "2024-02-21T18:31:02Z",
+ "aliases": [
+ "CVE-2024-25895"
+ ],
+ "details": "A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter of /EventAttendance.php",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25895"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/ChurchCRM/CRM/issues/6853"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-02-21T18:15:51Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/02/GHSA-5g46-qxcm-rg25/GHSA-5g46-qxcm-rg25.json b/advisories/unreviewed/2024/02/GHSA-5g46-qxcm-rg25/GHSA-5g46-qxcm-rg25.json
new file mode 100644
index 00000000000..eadef3822e3
--- /dev/null
+++ b/advisories/unreviewed/2024/02/GHSA-5g46-qxcm-rg25/GHSA-5g46-qxcm-rg25.json
@@ -0,0 +1,46 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5g46-qxcm-rg25",
+ "modified": "2024-02-21T18:31:02Z",
+ "published": "2024-02-21T18:31:02Z",
+ "aliases": [
+ "CVE-2024-1705"
+ ],
+ "details": "A vulnerability was found in Shopwind up to 4.6. It has been rated as critical. This issue affects the function actionCreate of the file /public/install/controllers/DefaultController.php of the component Installation. The manipulation leads to code injection. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-254393 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1705"
+ },
+ {
+ "type": "WEB",
+ "url": "https://note.zhaoj.in/share/QHdXavkw5eDm"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.254393"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.254393"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-94"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-02-21T18:15:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/02/GHSA-65x5-26gm-j9pq/GHSA-65x5-26gm-j9pq.json b/advisories/unreviewed/2024/02/GHSA-65x5-26gm-j9pq/GHSA-65x5-26gm-j9pq.json
new file mode 100644
index 00000000000..bf46631d0e4
--- /dev/null
+++ b/advisories/unreviewed/2024/02/GHSA-65x5-26gm-j9pq/GHSA-65x5-26gm-j9pq.json
@@ -0,0 +1,38 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-65x5-26gm-j9pq",
+ "modified": "2024-02-21T18:31:01Z",
+ "published": "2024-02-21T18:31:01Z",
+ "aliases": [
+ "CVE-2024-1708"
+ ],
+ "details": "ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker \n\nthe ability to execute remote code or directly impact confidential data or critical systems.\n\n",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1708"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-22"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-02-21T16:15:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/02/GHSA-6m3q-9vch-f5gh/GHSA-6m3q-9vch-f5gh.json b/advisories/unreviewed/2024/02/GHSA-6m3q-9vch-f5gh/GHSA-6m3q-9vch-f5gh.json
new file mode 100644
index 00000000000..aa2947993b8
--- /dev/null
+++ b/advisories/unreviewed/2024/02/GHSA-6m3q-9vch-f5gh/GHSA-6m3q-9vch-f5gh.json
@@ -0,0 +1,46 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6m3q-9vch-f5gh",
+ "modified": "2024-02-21T18:31:00Z",
+ "published": "2024-02-21T18:31:00Z",
+ "aliases": [
+ "CVE-2024-1700"
+ ],
+ "details": "A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected is an unknown function of the file /signup.php. The manipulation of the argument username with the input leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254388. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1700"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/omarexala/PHP-MYSQL-User-Login-System---Stored-XSS"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.254388"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.254388"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-02-21T16:15:49Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/02/GHSA-6vjx-p68v-62qm/GHSA-6vjx-p68v-62qm.json b/advisories/unreviewed/2024/02/GHSA-6vjx-p68v-62qm/GHSA-6vjx-p68v-62qm.json
new file mode 100644
index 00000000000..ea19802be0b
--- /dev/null
+++ b/advisories/unreviewed/2024/02/GHSA-6vjx-p68v-62qm/GHSA-6vjx-p68v-62qm.json
@@ -0,0 +1,46 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6vjx-p68v-62qm",
+ "modified": "2024-02-21T18:31:00Z",
+ "published": "2024-02-21T18:31:00Z",
+ "aliases": [
+ "CVE-2024-1701"
+ ],
+ "details": "A vulnerability has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edit.php. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-254389 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1701"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/omarexala/PHP-MYSQL-User-Login-System---Broken-Access-Control"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.254389"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.254389"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-284"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-02-21T16:15:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/02/GHSA-84jg-5x72-v4h5/GHSA-84jg-5x72-v4h5.json b/advisories/unreviewed/2024/02/GHSA-84jg-5x72-v4h5/GHSA-84jg-5x72-v4h5.json
new file mode 100644
index 00000000000..b82d73e8f7c
--- /dev/null
+++ b/advisories/unreviewed/2024/02/GHSA-84jg-5x72-v4h5/GHSA-84jg-5x72-v4h5.json
@@ -0,0 +1,46 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-84jg-5x72-v4h5",
+ "modified": "2024-02-21T18:31:02Z",
+ "published": "2024-02-21T18:31:02Z",
+ "aliases": [
+ "CVE-2024-1706"
+ ],
+ "details": "A vulnerability, which was classified as problematic, has been found in ZKTeco ZKBio Access IVS up to 3.3.2. Affected by this issue is some unknown functionality of the component Department Name Search Bar. The manipulation with the input