From 2b8bc1494c4212dc29c12bf2597bd78b90795fe8 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 6 Nov 2023 12:31:37 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2262-c75j-5hr5.json | 35 ++++++++++++++++ .../GHSA-24m4-9q2q-2374.json | 35 ++++++++++++++++ .../GHSA-2cgw-gvv3-hc6c.json | 35 ++++++++++++++++ .../GHSA-53xh-mr6w-445f.json | 38 +++++++++++++++++ .../GHSA-6f53-979p-cv25.json | 35 ++++++++++++++++ .../GHSA-7hqp-rpqf-qcm8.json | 35 ++++++++++++++++ .../GHSA-7m7m-p296-cg75.json | 35 ++++++++++++++++ .../GHSA-c9c3-3fvf-8q99.json | 35 ++++++++++++++++ .../GHSA-ccf8-r983-v699.json | 38 +++++++++++++++++ .../GHSA-f67c-8m2w-79hm.json | 42 +++++++++++++++++++ .../GHSA-fgv4-2qmx-fqgr.json | 35 ++++++++++++++++ .../GHSA-gvg4-qv8f-cm99.json | 35 ++++++++++++++++ .../GHSA-gwvc-g4vv-pjx6.json | 42 +++++++++++++++++++ .../GHSA-jc9g-7x7r-c8w7.json | 35 ++++++++++++++++ .../GHSA-mhrw-cvv9-pwvf.json | 35 ++++++++++++++++ .../GHSA-mjhv-v484-p28j.json | 35 ++++++++++++++++ .../GHSA-r4qh-qg67-8mh2.json | 35 ++++++++++++++++ .../GHSA-v87x-w98p-pcgx.json | 35 ++++++++++++++++ .../GHSA-w5h8-wfm4-w243.json | 35 ++++++++++++++++ .../GHSA-x9wm-pw72-c8fj.json | 35 ++++++++++++++++ .../GHSA-xp8c-wvr5-8f8x.json | 35 ++++++++++++++++ .../GHSA-xpp7-7rw8-qmff.json | 35 ++++++++++++++++ .../GHSA-xprj-4wm5-xgr4.json | 35 ++++++++++++++++ .../GHSA-xqh2-p25v-rv7v.json | 35 ++++++++++++++++ .../GHSA-xr4f-2rrr-cm48.json | 35 ++++++++++++++++ 25 files changed, 895 insertions(+) create mode 100644 advisories/unreviewed/2023/11/GHSA-2262-c75j-5hr5/GHSA-2262-c75j-5hr5.json create mode 100644 advisories/unreviewed/2023/11/GHSA-24m4-9q2q-2374/GHSA-24m4-9q2q-2374.json create mode 100644 advisories/unreviewed/2023/11/GHSA-2cgw-gvv3-hc6c/GHSA-2cgw-gvv3-hc6c.json create mode 100644 advisories/unreviewed/2023/11/GHSA-53xh-mr6w-445f/GHSA-53xh-mr6w-445f.json create mode 100644 advisories/unreviewed/2023/11/GHSA-6f53-979p-cv25/GHSA-6f53-979p-cv25.json create mode 100644 advisories/unreviewed/2023/11/GHSA-7hqp-rpqf-qcm8/GHSA-7hqp-rpqf-qcm8.json create mode 100644 advisories/unreviewed/2023/11/GHSA-7m7m-p296-cg75/GHSA-7m7m-p296-cg75.json create mode 100644 advisories/unreviewed/2023/11/GHSA-c9c3-3fvf-8q99/GHSA-c9c3-3fvf-8q99.json create mode 100644 advisories/unreviewed/2023/11/GHSA-ccf8-r983-v699/GHSA-ccf8-r983-v699.json create mode 100644 advisories/unreviewed/2023/11/GHSA-f67c-8m2w-79hm/GHSA-f67c-8m2w-79hm.json create mode 100644 advisories/unreviewed/2023/11/GHSA-fgv4-2qmx-fqgr/GHSA-fgv4-2qmx-fqgr.json create mode 100644 advisories/unreviewed/2023/11/GHSA-gvg4-qv8f-cm99/GHSA-gvg4-qv8f-cm99.json create mode 100644 advisories/unreviewed/2023/11/GHSA-gwvc-g4vv-pjx6/GHSA-gwvc-g4vv-pjx6.json create mode 100644 advisories/unreviewed/2023/11/GHSA-jc9g-7x7r-c8w7/GHSA-jc9g-7x7r-c8w7.json create mode 100644 advisories/unreviewed/2023/11/GHSA-mhrw-cvv9-pwvf/GHSA-mhrw-cvv9-pwvf.json create mode 100644 advisories/unreviewed/2023/11/GHSA-mjhv-v484-p28j/GHSA-mjhv-v484-p28j.json create mode 100644 advisories/unreviewed/2023/11/GHSA-r4qh-qg67-8mh2/GHSA-r4qh-qg67-8mh2.json create mode 100644 advisories/unreviewed/2023/11/GHSA-v87x-w98p-pcgx/GHSA-v87x-w98p-pcgx.json create mode 100644 advisories/unreviewed/2023/11/GHSA-w5h8-wfm4-w243/GHSA-w5h8-wfm4-w243.json create mode 100644 advisories/unreviewed/2023/11/GHSA-x9wm-pw72-c8fj/GHSA-x9wm-pw72-c8fj.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xp8c-wvr5-8f8x/GHSA-xp8c-wvr5-8f8x.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xpp7-7rw8-qmff/GHSA-xpp7-7rw8-qmff.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xprj-4wm5-xgr4/GHSA-xprj-4wm5-xgr4.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xqh2-p25v-rv7v/GHSA-xqh2-p25v-rv7v.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xr4f-2rrr-cm48/GHSA-xr4f-2rrr-cm48.json diff --git a/advisories/unreviewed/2023/11/GHSA-2262-c75j-5hr5/GHSA-2262-c75j-5hr5.json b/advisories/unreviewed/2023/11/GHSA-2262-c75j-5hr5/GHSA-2262-c75j-5hr5.json new file mode 100644 index 00000000000..b957dc8724c --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-2262-c75j-5hr5/GHSA-2262-c75j-5hr5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2262-c75j-5hr5", + "modified": "2023-11-06T12:30:24Z", + "published": "2023-11-06T12:30:24Z", + "aliases": [ + "CVE-2023-47182" + ], + "details": "Cross-Site Request Forgery (CSRF) leading to a Stored Cross-Site Scripting (XSS) vulnerability in Nazmul Hossain Nihal Login Screen Manager plugin <= 3.5.2 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47182" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/login-screen-manager/wordpress-login-screen-manager-plugin-3-5-2-unauth-stored-cross-site-scripting-xss-via-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-24m4-9q2q-2374/GHSA-24m4-9q2q-2374.json b/advisories/unreviewed/2023/11/GHSA-24m4-9q2q-2374/GHSA-24m4-9q2q-2374.json new file mode 100644 index 00000000000..81030f77bf0 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-24m4-9q2q-2374/GHSA-24m4-9q2q-2374.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24m4-9q2q-2374", + "modified": "2023-11-06T12:30:24Z", + "published": "2023-11-06T12:30:24Z", + "aliases": [ + "CVE-2023-47177" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Yakir Sitbon, Ariel Klikstein Linker plugin <= 1.2.1 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47177" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/linker/wordpress-linker-plugin-1-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-2cgw-gvv3-hc6c/GHSA-2cgw-gvv3-hc6c.json b/advisories/unreviewed/2023/11/GHSA-2cgw-gvv3-hc6c/GHSA-2cgw-gvv3-hc6c.json new file mode 100644 index 00000000000..496edcb4a93 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-2cgw-gvv3-hc6c/GHSA-2cgw-gvv3-hc6c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cgw-gvv3-hc6c", + "modified": "2023-11-06T12:30:24Z", + "published": "2023-11-06T12:30:24Z", + "aliases": [ + "CVE-2023-46824" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Om Ak Solutions Slick Popup: Contact Form 7 Popup Plugin plugin <= 1.7.14 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46824" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/slick-popup/wordpress-slick-popup-plugin-1-7-14-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-53xh-mr6w-445f/GHSA-53xh-mr6w-445f.json b/advisories/unreviewed/2023/11/GHSA-53xh-mr6w-445f/GHSA-53xh-mr6w-445f.json new file mode 100644 index 00000000000..b5fa4f62d24 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-53xh-mr6w-445f/GHSA-53xh-mr6w-445f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53xh-mr6w-445f", + "modified": "2023-11-06T12:30:24Z", + "published": "2023-11-06T12:30:24Z", + "aliases": [ + "CVE-2023-5831" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, and all versions starting from 16.5.0 before 16.5.1 which have the `super_sidebar_logged_out` feature flag enabled. Affected versions with this default-disabled feature flag enabled may unintentionally disclose GitLab version metadata to unauthorized actors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5831" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/428919" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-6f53-979p-cv25/GHSA-6f53-979p-cv25.json b/advisories/unreviewed/2023/11/GHSA-6f53-979p-cv25/GHSA-6f53-979p-cv25.json new file mode 100644 index 00000000000..701080e81d2 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-6f53-979p-cv25/GHSA-6f53-979p-cv25.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f53-979p-cv25", + "modified": "2023-11-06T12:30:24Z", + "published": "2023-11-06T12:30:24Z", + "aliases": [ + "CVE-2023-46778" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in TheFreeWindows Auto Limit Posts Reloaded plugin <= 2.5 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46778" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/auto-limit-posts-reloaded/wordpress-auto-limit-posts-reloaded-plugin-2-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7hqp-rpqf-qcm8/GHSA-7hqp-rpqf-qcm8.json b/advisories/unreviewed/2023/11/GHSA-7hqp-rpqf-qcm8/GHSA-7hqp-rpqf-qcm8.json new file mode 100644 index 00000000000..1b76c0f33b1 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-7hqp-rpqf-qcm8/GHSA-7hqp-rpqf-qcm8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hqp-rpqf-qcm8", + "modified": "2023-11-06T12:30:24Z", + "published": "2023-11-06T12:30:24Z", + "aliases": [ + "CVE-2023-46776" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Serena Villa Auto Excerpt everywhere plugin <= 1.5 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46776" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/auto-excerpt-everywhere/wordpress-auto-excerpt-everywhere-plugin-1-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7m7m-p296-cg75/GHSA-7m7m-p296-cg75.json b/advisories/unreviewed/2023/11/GHSA-7m7m-p296-cg75/GHSA-7m7m-p296-cg75.json new file mode 100644 index 00000000000..372b36af03f --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-7m7m-p296-cg75/GHSA-7m7m-p296-cg75.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m7m-p296-cg75", + "modified": "2023-11-06T12:30:22Z", + "published": "2023-11-06T12:30:22Z", + "aliases": [ + "CVE-2023-23702" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.7 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23702" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/comments-ratings/wordpress-comments-ratings-plugin-1-1-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-c9c3-3fvf-8q99/GHSA-c9c3-3fvf-8q99.json b/advisories/unreviewed/2023/11/GHSA-c9c3-3fvf-8q99/GHSA-c9c3-3fvf-8q99.json new file mode 100644 index 00000000000..b4a38ce83d4 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-c9c3-3fvf-8q99/GHSA-c9c3-3fvf-8q99.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9c3-3fvf-8q99", + "modified": "2023-11-06T12:30:24Z", + "published": "2023-11-06T12:30:24Z", + "aliases": [ + "CVE-2023-46781" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Roland Murg Current Menu Item for Custom Post Types plugin <= 1.5 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46781" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/current-menu-item-for-custom-post-types/wordpress-current-menu-item-for-custom-post-types-plugin-1-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-ccf8-r983-v699/GHSA-ccf8-r983-v699.json b/advisories/unreviewed/2023/11/GHSA-ccf8-r983-v699/GHSA-ccf8-r983-v699.json new file mode 100644 index 00000000000..9ee003c4839 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-ccf8-r983-v699/GHSA-ccf8-r983-v699.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccf8-r983-v699", + "modified": "2023-11-06T12:30:24Z", + "published": "2023-11-06T12:30:24Z", + "aliases": [ + "CVE-2023-4996" + ], + "details": "Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a specially-crafted package. The root cause of the problem was a user control code when called by a Windows ServiceController did not validate the permissions associated with the user before executing the user control code. This user control code had permissions to terminate the NSClient service. \n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4996" + }, + { + "type": "WEB", + "url": "https://www.netskope.com/company/security-compliance-and-assurance/security-advisories-and-disclosures/netskope-security-advisory-nskpsa-2023-003" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-281" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-f67c-8m2w-79hm/GHSA-f67c-8m2w-79hm.json b/advisories/unreviewed/2023/11/GHSA-f67c-8m2w-79hm/GHSA-f67c-8m2w-79hm.json new file mode 100644 index 00000000000..939c1948b05 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-f67c-8m2w-79hm/GHSA-f67c-8m2w-79hm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f67c-8m2w-79hm", + "modified": "2023-11-06T12:30:24Z", + "published": "2023-11-06T12:30:24Z", + "aliases": [ + "CVE-2023-5090" + ], + "details": "A flaw was found in KVM. An improper check in svm_set_x2apic_msr_interception() may allow direct access to host x2apic msrs when the guest resets its apic, potentially leading to a denial of service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5090" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-5090" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2248122" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-fgv4-2qmx-fqgr/GHSA-fgv4-2qmx-fqgr.json b/advisories/unreviewed/2023/11/GHSA-fgv4-2qmx-fqgr/GHSA-fgv4-2qmx-fqgr.json new file mode 100644 index 00000000000..7e8dd6ab7aa --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-fgv4-2qmx-fqgr/GHSA-fgv4-2qmx-fqgr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgv4-2qmx-fqgr", + "modified": "2023-11-06T12:30:25Z", + "published": "2023-11-06T12:30:25Z", + "aliases": [ + "CVE-2023-47185" + ], + "details": "Unauth. Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47185" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpdiscuz/wordpress-wpdiscuz-plugin-7-6-11-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-gvg4-qv8f-cm99/GHSA-gvg4-qv8f-cm99.json b/advisories/unreviewed/2023/11/GHSA-gvg4-qv8f-cm99/GHSA-gvg4-qv8f-cm99.json new file mode 100644 index 00000000000..a5e548a0cf9 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-gvg4-qv8f-cm99/GHSA-gvg4-qv8f-cm99.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvg4-qv8f-cm99", + "modified": "2023-11-06T12:30:23Z", + "published": "2023-11-06T12:30:23Z", + "aliases": [ + "CVE-2023-46822" + ], + "details": "Unauth. Reflected Cross-Site Scripting') vulnerability in Visser Labs Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin <= 2.7.2 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46822" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-exporter/wordpress-store-exporter-for-woocommerce-plugin-2-7-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-gwvc-g4vv-pjx6/GHSA-gwvc-g4vv-pjx6.json b/advisories/unreviewed/2023/11/GHSA-gwvc-g4vv-pjx6/GHSA-gwvc-g4vv-pjx6.json new file mode 100644 index 00000000000..7bd21a7a4bf --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-gwvc-g4vv-pjx6/GHSA-gwvc-g4vv-pjx6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwvc-g4vv-pjx6", + "modified": "2023-11-06T12:30:24Z", + "published": "2023-11-06T12:30:24Z", + "aliases": [ + "CVE-2023-5825" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.2 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A low-privileged attacker can point a CI/CD Component to an incorrect path and cause the server to exhaust all available memory through an infinite loop and cause Denial of Service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5825" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2218566" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/428984" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-jc9g-7x7r-c8w7/GHSA-jc9g-7x7r-c8w7.json b/advisories/unreviewed/2023/11/GHSA-jc9g-7x7r-c8w7/GHSA-jc9g-7x7r-c8w7.json new file mode 100644 index 00000000000..f6881d5eaa1 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-jc9g-7x7r-c8w7/GHSA-jc9g-7x7r-c8w7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc9g-7x7r-c8w7", + "modified": "2023-11-06T12:30:24Z", + "published": "2023-11-06T12:30:24Z", + "aliases": [ + "CVE-2023-46823" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum ImageLinks Interactive Image Builder for WordPress allows SQL Injection.This issue affects ImageLinks Interactive Image Builder for WordPress: from n/a through 1.5.4.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46823" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/imagelinks-interactive-image-builder-lite/wordpress-imagelinks-interactive-image-builder-for-wordpress-plugin-1-5-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-mhrw-cvv9-pwvf/GHSA-mhrw-cvv9-pwvf.json b/advisories/unreviewed/2023/11/GHSA-mhrw-cvv9-pwvf/GHSA-mhrw-cvv9-pwvf.json new file mode 100644 index 00000000000..369de8cd2e1 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-mhrw-cvv9-pwvf/GHSA-mhrw-cvv9-pwvf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhrw-cvv9-pwvf", + "modified": "2023-11-06T12:30:23Z", + "published": "2023-11-06T12:30:23Z", + "aliases": [ + "CVE-2023-46782" + ], + "details": "Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Chris Yee MomentoPress for Momento360 plugin <= 1.0.1 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46782" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cmyee-momentopress/wordpress-momentopress-for-momento360-plugin-1-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-mjhv-v484-p28j/GHSA-mjhv-v484-p28j.json b/advisories/unreviewed/2023/11/GHSA-mjhv-v484-p28j/GHSA-mjhv-v484-p28j.json new file mode 100644 index 00000000000..3f68728e025 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-mjhv-v484-p28j/GHSA-mjhv-v484-p28j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjhv-v484-p28j", + "modified": "2023-11-06T12:30:24Z", + "published": "2023-11-06T12:30:24Z", + "aliases": [ + "CVE-2023-46779" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in EasyRecipe plugin <= 3.5.3251 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46779" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/easyrecipe/wordpress-easyrecipe-plugin-3-5-3251-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-r4qh-qg67-8mh2/GHSA-r4qh-qg67-8mh2.json b/advisories/unreviewed/2023/11/GHSA-r4qh-qg67-8mh2/GHSA-r4qh-qg67-8mh2.json new file mode 100644 index 00000000000..fa34456576e --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-r4qh-qg67-8mh2/GHSA-r4qh-qg67-8mh2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4qh-qg67-8mh2", + "modified": "2023-11-06T12:30:23Z", + "published": "2023-11-06T12:30:23Z", + "aliases": [ + "CVE-2023-46783" + ], + "details": "Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bright Plugins Pre-Orders for WooCommerce plugin <= 1.2.13 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46783" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pre-orders-for-woocommerce/wordpress-pre-orders-for-woocommerce-plugin-1-2-13-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-v87x-w98p-pcgx/GHSA-v87x-w98p-pcgx.json b/advisories/unreviewed/2023/11/GHSA-v87x-w98p-pcgx/GHSA-v87x-w98p-pcgx.json new file mode 100644 index 00000000000..6875e08847b --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-v87x-w98p-pcgx/GHSA-v87x-w98p-pcgx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v87x-w98p-pcgx", + "modified": "2023-11-06T12:30:24Z", + "published": "2023-11-06T12:30:24Z", + "aliases": [ + "CVE-2023-5823" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ThemeKraft TK Google Fonts GDPR Compliant plugin <= 2.2.11 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5823" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/tk-google-fonts/wordpress-tk-google-fonts-gdpr-compliant-plugin-2-2-11-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-w5h8-wfm4-w243/GHSA-w5h8-wfm4-w243.json b/advisories/unreviewed/2023/11/GHSA-w5h8-wfm4-w243/GHSA-w5h8-wfm4-w243.json new file mode 100644 index 00000000000..a284d80dfb3 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-w5h8-wfm4-w243/GHSA-w5h8-wfm4-w243.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5h8-wfm4-w243", + "modified": "2023-11-06T12:30:24Z", + "published": "2023-11-06T12:30:24Z", + "aliases": [ + "CVE-2023-47186" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Kadence WP Kadence WooCommerce Email Designer plugin <= 1.5.11 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47186" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/kadence-woocommerce-email-designer/wordpress-kadence-woocommerce-email-designer-plugin-1-5-11-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-x9wm-pw72-c8fj/GHSA-x9wm-pw72-c8fj.json b/advisories/unreviewed/2023/11/GHSA-x9wm-pw72-c8fj/GHSA-x9wm-pw72-c8fj.json new file mode 100644 index 00000000000..2adc1f20ded --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-x9wm-pw72-c8fj/GHSA-x9wm-pw72-c8fj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9wm-pw72-c8fj", + "modified": "2023-11-06T12:30:23Z", + "published": "2023-11-06T12:30:23Z", + "aliases": [ + "CVE-2023-46821" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD Security Headers allows auth. (admin+) SQL Injection.This issue affects GD Security Headers: from n/a through 1.7.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46821" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/gd-security-headers/wordpress-gd-security-headers-plugin-1-7-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xp8c-wvr5-8f8x/GHSA-xp8c-wvr5-8f8x.json b/advisories/unreviewed/2023/11/GHSA-xp8c-wvr5-8f8x/GHSA-xp8c-wvr5-8f8x.json new file mode 100644 index 00000000000..3f0965d199b --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xp8c-wvr5-8f8x/GHSA-xp8c-wvr5-8f8x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xp8c-wvr5-8f8x", + "modified": "2023-11-06T12:30:24Z", + "published": "2023-11-06T12:30:24Z", + "aliases": [ + "CVE-2023-47184" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Proper Fraction LLC. Admin Bar & Dashboard Access Control plugin <= 1.2.8 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47184" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/admin-bar-dashboard-control/wordpress-admin-bar-dashboard-access-control-plugin-1-2-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xpp7-7rw8-qmff/GHSA-xpp7-7rw8-qmff.json b/advisories/unreviewed/2023/11/GHSA-xpp7-7rw8-qmff/GHSA-xpp7-7rw8-qmff.json new file mode 100644 index 00000000000..fe612bc8d09 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xpp7-7rw8-qmff/GHSA-xpp7-7rw8-qmff.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpp7-7rw8-qmff", + "modified": "2023-11-06T12:30:24Z", + "published": "2023-11-06T12:30:24Z", + "aliases": [ + "CVE-2023-46777" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Custom Login Page | Temporary Users | Rebrand Login | Login Captcha plugin <= 1.1.3 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46777" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/feather-login-page/wordpress-feather-login-page-plugin-1-1-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xprj-4wm5-xgr4/GHSA-xprj-4wm5-xgr4.json b/advisories/unreviewed/2023/11/GHSA-xprj-4wm5-xgr4/GHSA-xprj-4wm5-xgr4.json new file mode 100644 index 00000000000..d9e03a6ff52 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xprj-4wm5-xgr4/GHSA-xprj-4wm5-xgr4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xprj-4wm5-xgr4", + "modified": "2023-11-06T12:30:24Z", + "published": "2023-11-06T12:30:24Z", + "aliases": [ + "CVE-2023-46775" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Djo Original texts Yandex WebMaster plugin <= 1.18 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46775" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/original-texts-yandex-webmaster/wordpress-original-texts-yandex-webmaster-plugin-1-18-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xqh2-p25v-rv7v/GHSA-xqh2-p25v-rv7v.json b/advisories/unreviewed/2023/11/GHSA-xqh2-p25v-rv7v/GHSA-xqh2-p25v-rv7v.json new file mode 100644 index 00000000000..455c7314ac0 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xqh2-p25v-rv7v/GHSA-xqh2-p25v-rv7v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqh2-p25v-rv7v", + "modified": "2023-11-06T12:30:24Z", + "published": "2023-11-06T12:30:24Z", + "aliases": [ + "CVE-2023-46780" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Alter plugin <= 1.0 versions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46780" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/alter/wordpress-alter-plugin-1-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T12:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xr4f-2rrr-cm48/GHSA-xr4f-2rrr-cm48.json b/advisories/unreviewed/2023/11/GHSA-xr4f-2rrr-cm48/GHSA-xr4f-2rrr-cm48.json new file mode 100644 index 00000000000..910d7874ef2 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xr4f-2rrr-cm48/GHSA-xr4f-2rrr-cm48.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr4f-2rrr-cm48", + "modified": "2023-11-06T12:30:23Z", + "published": "2023-11-06T12:30:23Z", + "aliases": [ + "CVE-2023-46084" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bPlugins LLC Icons Font Loader allows SQL Injection.This issue affects Icons Font Loader: from n/a through 1.1.2.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46084" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/icons-font-loader/wordpress-icons-font-loader-plugin-1-1-2-subscriber-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T10:15:07Z" + } +} \ No newline at end of file