From 24db43b8642c60aae89d9fe8165da66793d73edd Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 19 Nov 2024 06:32:15 +0000 Subject: [PATCH] Publish Advisories GHSA-9v3g-gwx4-px97 GHSA-v87w-5qjf-xwc5 --- .../GHSA-9v3g-gwx4-px97.json | 42 +++++++++++++++++++ .../GHSA-v87w-5qjf-xwc5.json | 35 ++++++++++++++++ 2 files changed, 77 insertions(+) create mode 100644 advisories/unreviewed/2024/11/GHSA-9v3g-gwx4-px97/GHSA-9v3g-gwx4-px97.json create mode 100644 advisories/unreviewed/2024/11/GHSA-v87w-5qjf-xwc5/GHSA-v87w-5qjf-xwc5.json diff --git a/advisories/unreviewed/2024/11/GHSA-9v3g-gwx4-px97/GHSA-9v3g-gwx4-px97.json b/advisories/unreviewed/2024/11/GHSA-9v3g-gwx4-px97/GHSA-9v3g-gwx4-px97.json new file mode 100644 index 00000000000..10ef29d8c6f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9v3g-gwx4-px97/GHSA-9v3g-gwx4-px97.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v3g-gwx4-px97", + "modified": "2024-11-19T06:30:40Z", + "published": "2024-11-19T06:30:40Z", + "aliases": [ + "CVE-2024-8403" + ], + "details": "Improper Validation of Specified Type of Input vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET versions 1.100 and later and FX5-ENET/IP versions 1.100 to 1.104 allows a remote attacker to cause a Denial of Service condition in Ethernet communication of the products by sending specially crafted SLMP packets.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8403" + }, + { + "type": "WEB", + "url": "https://jvn.jp/vu/JVNVU97790713" + }, + { + "type": "WEB", + "url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-009_en.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T06:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v87w-5qjf-xwc5/GHSA-v87w-5qjf-xwc5.json b/advisories/unreviewed/2024/11/GHSA-v87w-5qjf-xwc5/GHSA-v87w-5qjf-xwc5.json new file mode 100644 index 00000000000..2ff8963c85f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v87w-5qjf-xwc5/GHSA-v87w-5qjf-xwc5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v87w-5qjf-xwc5", + "modified": "2024-11-19T06:30:40Z", + "published": "2024-11-19T06:30:40Z", + "aliases": [ + "CVE-2024-10103" + ], + "details": "In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10103" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/89660883-5f34-426a-ad06-741c0c213ecc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-19T06:15:17Z" + } +} \ No newline at end of file