Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2023-11-14 21:31:49 +00:00
parent 65e6b9690e
commit 2c64139ca1
260 changed files with 7878 additions and 157 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pmgm-pv8c-pw29",
"modified": "2021-12-23T00:01:54Z",
"modified": "2023-11-14T21:30:47Z",
"published": "2021-12-17T00:00:23Z",
"aliases": [
"CVE-2021-44315"
],
"details": "In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application, for example: Any file which contains sensitive information of the user or server.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ppr5-jp7h-pvxj",
"modified": "2021-12-23T00:01:53Z",
"modified": "2023-11-14T21:30:48Z",
"published": "2021-12-17T00:00:23Z",
"aliases": [
"CVE-2021-44317"
],
"details": "In Bus Pass Management System v1.0, parameters 'pagedes' and `About Us` are affected with a Stored Cross-site scripting vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2vrv-3jr5-rv6c",
"modified": "2022-05-24T19:17:22Z",
"modified": "2023-11-14T21:30:47Z",
"published": "2022-05-24T19:17:22Z",
"aliases": [
"CVE-2021-42224"
],
"details": "SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-285",
"CWE-863"
],
"severity": "CRITICAL",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-77jf-5mcg-g6m9",
"modified": "2022-05-24T17:47:45Z",
"modified": "2023-11-14T21:30:47Z",
"published": "2022-05-24T17:47:45Z",
"aliases": [
"CVE-2020-2509"
],
"details": "A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c38v-5prm-vhjx",
"modified": "2022-05-24T19:17:23Z",
"modified": "2023-11-14T21:30:47Z",
"published": "2022-05-24T19:17:23Z",
"aliases": [
"CVE-2021-42223"
],
"details": "Cross Site Scripting (XSS).vulnerability exists in Online DJ Booking Management System 1.0 in view-booking-detail.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cj8c-4h22-g2gj",
"modified": "2022-05-24T17:28:59Z",
"modified": "2023-11-14T21:30:47Z",
"published": "2022-05-24T17:28:59Z",
"aliases": [
"CVE-2020-25487"
],
"details": "PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -33,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cpw5-f693-2r28",
"modified": "2022-05-24T17:37:06Z",
"modified": "2023-11-14T21:30:47Z",
"published": "2022-05-24T17:37:06Z",
"aliases": [
"CVE-2020-35151"
],
"details": "The Online Marriage Registration System 1.0 post parameter \"searchdata\" in the user/search.php request is vulnerable to Time Based Sql Injection.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fvqh-qwm3-5j87",
"modified": "2022-05-24T17:42:16Z",
"modified": "2023-11-14T21:30:47Z",
"published": "2022-05-24T17:42:16Z",
"aliases": [
"CVE-2021-26822"
],
"details": "Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in search-teacher.php. This vulnerability can be exploited by a remote unauthenticated attacker to leak sensitive information and perform code execution attacks.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jx9p-jf7x-8rr2",
"modified": "2022-05-24T17:35:56Z",
"modified": "2023-11-14T21:30:47Z",
"published": "2022-05-24T17:35:56Z",
"aliases": [
"CVE-2020-2494"
],
"details": "This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in the following versions of Music Station. QuTS hero h4.5.1: Music Station 5.3.13 and later QTS 4.5.1: Music Station 5.3.12 and later QTS 4.4.3: Music Station 5.3.12 and later",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m7vg-3vj5-h86f",
"modified": "2022-05-24T17:35:56Z",
"modified": "2023-11-14T21:30:47Z",
"published": "2022-05-24T17:35:56Z",
"aliases": [
"CVE-2020-2498"
],
"details": "If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in certificate configuration. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.6.1333 build 20200608 and later QTS 4.3.4.1368 build 20200703 and later QTS 4.3.3.1315 build 20200611 and later QTS 4.2.6 build 20200611 and later",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1816"
},
{
"type": "WEB",
"url": "https://github.com/Xor-Gerke/webray.com.cn/blob/main/cve/Zoo-Management-System/Zoo-Management-System%28XSS%29.md"
},
{
"type": "WEB",
"url": "https://github.com/Xor-Gerke/webray.com.cn/blob/main/cve/Zoo-Management-System/Zoo-Management-System(XSS).md"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w463-hpv4-95pw",
"modified": "2022-05-24T19:06:42Z",
"modified": "2023-11-14T21:30:47Z",
"published": "2022-05-24T19:06:42Z",
"aliases": [
"CVE-2021-28423"
],
"details": "Multiple SQL Injection vulnerabilities in Teachers Record Management System 1.0 allow remote authenticated users to execute arbitrary SQL commands via the 'editid' GET parameter in edit-subjects-detail.php, edit-teacher-detail.php, or the 'searchdata' POST parameter in search.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w962-fvxv-mrr4",
"modified": "2022-05-24T17:41:16Z",
"modified": "2023-11-14T21:30:47Z",
"published": "2022-05-24T17:41:16Z",
"aliases": [
"CVE-2020-26052"
],
"details": "Online Marriage Registration System 1.0 is affected by stored cross-site scripting (XSS) vulnerabilities in multiple parameters.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x62f-6xhh-g5fp",
"modified": "2022-05-24T19:06:42Z",
"modified": "2023-11-14T21:30:47Z",
"published": "2022-05-24T19:06:42Z",
"aliases": [
"CVE-2021-28424"
],
"details": "A stored cross-site scripting (XSS) vulnerability in Teachers Record Management System 1.0 allows remote authenticated users to inject arbitrary web script or HTML via the 'email' POST parameter in adminprofile.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://edk2-docs.gitbook.io/understanding-the-uefi-secure-boot-chain/secure_boot_chain_in_uefi/uefi_secure_boot"
},
{
"type": "WEB",
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01001.html"
},
{
"type": "WEB",
"url": "https://www.kb.cert.org/vuls/id/309662"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://edk2-docs.gitbook.io/understanding-the-uefi-secure-boot-chain/secure_boot_chain_in_uefi/uefi_secure_boot"
},
{
"type": "WEB",
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01001.html"
},
{
"type": "WEB",
"url": "https://www.kb.cert.org/vuls/id/309662"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://edk2-docs.gitbook.io/understanding-the-uefi-secure-boot-chain/secure_boot_chain_in_uefi/uefi_secure_boot"
},
{
"type": "WEB",
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01001.html"
},
{
"type": "WEB",
"url": "https://www.kb.cert.org/vuls/id/309662"
@@ -24,11 +24,16 @@
{
"type": "WEB",
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00747.html"
},
{
"type": "WEB",
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00908.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-276"
"CWE-276",
"CWE-277"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vh59-rfvm-xwqw",
"modified": "2023-05-26T21:30:22Z",
"modified": "2023-11-14T21:30:49Z",
"published": "2023-05-23T15:30:29Z",
"aliases": [
"CVE-2023-33338"
@@ -30,7 +30,7 @@
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-05-23T13:15:09Z"

Some files were not shown because too many files have changed in this diff Show More