diff --git a/advisories/unreviewed/2023/07/GHSA-26p5-j42v-vp3h/GHSA-26p5-j42v-vp3h.json b/advisories/unreviewed/2023/07/GHSA-26p5-j42v-vp3h/GHSA-26p5-j42v-vp3h.json new file mode 100644 index 00000000000..ac5e7cedd33 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-26p5-j42v-vp3h/GHSA-26p5-j42v-vp3h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26p5-j42v-vp3h", + "modified": "2023-07-15T03:30:27Z", + "published": "2023-07-15T03:30:27Z", + "aliases": [ + "CVE-2023-35802" + ], + "details": "IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be exploited to obtain elevated privileges to conduct remote code execution. Access to the internal management interface/subnet is required to conduct the exploit.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35802" + }, + { + "type": "WEB", + "url": "https://extremeportal.force.com/ExtrArticleDetail?an=000112741" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-99c6-mjfj-w86j/GHSA-99c6-mjfj-w86j.json b/advisories/unreviewed/2023/07/GHSA-99c6-mjfj-w86j/GHSA-99c6-mjfj-w86j.json new file mode 100644 index 00000000000..dafa01572f5 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-99c6-mjfj-w86j/GHSA-99c6-mjfj-w86j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99c6-mjfj-w86j", + "modified": "2023-07-15T03:30:28Z", + "published": "2023-07-15T03:30:28Z", + "aliases": [ + "CVE-2023-38350" + ], + "details": "PNP4Nagios through 81ebfc5 has stored XSS in the AJAX controller via the basket API and filters. This affects 0.6.26.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38350" + }, + { + "type": "WEB", + "url": "https://github.com/pnp4nagios/pnp4nagios/pull/16" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jqw4-fm67-g67w/GHSA-jqw4-fm67-g67w.json b/advisories/unreviewed/2023/07/GHSA-jqw4-fm67-g67w/GHSA-jqw4-fm67-g67w.json new file mode 100644 index 00000000000..67a802c3e70 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jqw4-fm67-g67w/GHSA-jqw4-fm67-g67w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqw4-fm67-g67w", + "modified": "2023-07-15T03:30:28Z", + "published": "2023-07-15T03:30:28Z", + "aliases": [ + "CVE-2023-38349" + ], + "details": "PNP4Nagios through 81ebfc5 lacks CSRF protection in the AJAX controller. This affects 0.6.26.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38349" + }, + { + "type": "WEB", + "url": "https://github.com/pnp4nagios/pnp4nagios/pull/17" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file