diff --git a/advisories/unreviewed/2023/07/GHSA-24cr-56gf-fx38/GHSA-24cr-56gf-fx38.json b/advisories/unreviewed/2023/07/GHSA-24cr-56gf-fx38/GHSA-24cr-56gf-fx38.json index c2a7e06a5c5..66130c9f11c 100644 --- a/advisories/unreviewed/2023/07/GHSA-24cr-56gf-fx38/GHSA-24cr-56gf-fx38.json +++ b/advisories/unreviewed/2023/07/GHSA-24cr-56gf-fx38/GHSA-24cr-56gf-fx38.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-63hm-fq62-wc3p/GHSA-63hm-fq62-wc3p.json b/advisories/unreviewed/2023/07/GHSA-63hm-fq62-wc3p/GHSA-63hm-fq62-wc3p.json index 00d0330d65f..517f5880c73 100644 --- a/advisories/unreviewed/2023/07/GHSA-63hm-fq62-wc3p/GHSA-63hm-fq62-wc3p.json +++ b/advisories/unreviewed/2023/07/GHSA-63hm-fq62-wc3p/GHSA-63hm-fq62-wc3p.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-mw2v-p95m-2vqg/GHSA-mw2v-p95m-2vqg.json b/advisories/unreviewed/2023/07/GHSA-mw2v-p95m-2vqg/GHSA-mw2v-p95m-2vqg.json new file mode 100644 index 00000000000..90ae974f07a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-mw2v-p95m-2vqg/GHSA-mw2v-p95m-2vqg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw2v-p95m-2vqg", + "modified": "2023-07-15T00:30:34Z", + "published": "2023-07-15T00:30:34Z", + "aliases": [ + "CVE-2023-37794" + ], + "details": "WAYOS FBM-291W 19.09.11V was discovered to contain a command injection vulnerability via the component /upgrade_filter.asp.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37794" + }, + { + "type": "WEB", + "url": "https://github.com/PwnYouLin/IOT_vul/tree/main/wayos/1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-p492-c975-6xjf/GHSA-p492-c975-6xjf.json b/advisories/unreviewed/2023/07/GHSA-p492-c975-6xjf/GHSA-p492-c975-6xjf.json index 213e40b8757..ccd5049ff7e 100644 --- a/advisories/unreviewed/2023/07/GHSA-p492-c975-6xjf/GHSA-p492-c975-6xjf.json +++ b/advisories/unreviewed/2023/07/GHSA-p492-c975-6xjf/GHSA-p492-c975-6xjf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p492-c975-6xjf", - "modified": "2023-07-10T18:30:48Z", + "modified": "2023-07-15T00:30:32Z", "published": "2023-07-10T18:30:48Z", "aliases": [ "CVE-2023-2967" ], "details": "The TinyMCE Custom Styles WordPress plugin before 1.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/07/GHSA-rx57-ww84-jwhw/GHSA-rx57-ww84-jwhw.json b/advisories/unreviewed/2023/07/GHSA-rx57-ww84-jwhw/GHSA-rx57-ww84-jwhw.json new file mode 100644 index 00000000000..917209cbf02 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-rx57-ww84-jwhw/GHSA-rx57-ww84-jwhw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx57-ww84-jwhw", + "modified": "2023-07-15T00:30:34Z", + "published": "2023-07-15T00:30:34Z", + "aliases": [ + "CVE-2023-37793" + ], + "details": "WAYOS FBM-291W 19.09.11V was discovered to contain a buffer overflow via the component /upgrade_filter.asp.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37793" + }, + { + "type": "WEB", + "url": "https://github.com/PwnYouLin/IOT_vul/blob/main/wayos/2/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-vc79-65pr-q82v/GHSA-vc79-65pr-q82v.json b/advisories/unreviewed/2023/07/GHSA-vc79-65pr-q82v/GHSA-vc79-65pr-q82v.json new file mode 100644 index 00000000000..2d9b7c78bfa --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-vc79-65pr-q82v/GHSA-vc79-65pr-q82v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vc79-65pr-q82v", + "modified": "2023-07-15T00:30:34Z", + "published": "2023-07-15T00:30:34Z", + "aliases": [ + "CVE-2023-38337" + ], + "details": "rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38337" + }, + { + "type": "WEB", + "url": "https://github.com/rswag/rswag/issues/653" + }, + { + "type": "WEB", + "url": "https://github.com/rswag/rswag/compare/2.9.0...2.10.1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-vg2g-72mx-mj33/GHSA-vg2g-72mx-mj33.json b/advisories/unreviewed/2023/07/GHSA-vg2g-72mx-mj33/GHSA-vg2g-72mx-mj33.json new file mode 100644 index 00000000000..4b3fcdaf301 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-vg2g-72mx-mj33/GHSA-vg2g-72mx-mj33.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg2g-72mx-mj33", + "modified": "2023-07-15T00:30:34Z", + "published": "2023-07-15T00:30:34Z", + "aliases": [ + "CVE-2023-38336" + ], + "details": "netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-2019-7283, and CVE-2020-15778.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38336" + }, + { + "type": "WEB", + "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1039689" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file