Publish Advisories

GHSA-39q6-4vrm-fv3g
GHSA-3jr9-479w-vh8c
GHSA-3vj4-3g37-rf7w
GHSA-47h2-h6q2-ghrw
GHSA-4qg2-wr83-m4mf
GHSA-5mrw-cpfj-cjh6
GHSA-5q5q-4pvv-q47c
GHSA-8cgf-r9f6-hj56
GHSA-c89h-9543-w7hx
GHSA-h9qg-8cx4-mh74
GHSA-jh7f-2hf7-8vxp
GHSA-jq2h-j9qf-53rv
GHSA-mvw9-7543-rjjg
GHSA-r4wr-j2mc-r37v
GHSA-vwhm-7rfg-7rqc
GHSA-whr7-4gp3-wpwc
GHSA-xq99-q5xg-8fq7
This commit is contained in:
advisory-database[bot]
2023-10-23 00:31:32 +00:00
parent ec41f9874b
commit 2e400f2695
17 changed files with 677 additions and 0 deletions
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-final"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230908-0004/"
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3jr9-479w-vh8c",
"modified": "2023-10-23T00:30:21Z",
"published": "2023-10-23T00:30:21Z",
"aliases": [
"CVE-2023-5695"
],
"details": "A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file pages_reset_pwd.php. The manipulation of the argument email with the input testing%40example.com'%26%25<ScRiPt%20>alert(9860)</ScRiPt> leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243133 was assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5695"
},
{
"type": "WEB",
"url": "https://github.com/E1CHO/cve_hub/blob/main/Internet%20Banking%20System/Internet%20Banking%20System%20-%20vuln%203.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.243133"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.243133"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3vj4-3g37-rf7w",
"modified": "2023-10-23T00:30:20Z",
"published": "2023-10-23T00:30:20Z",
"aliases": [
"CVE-2023-46085"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.2.4 versions.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46085"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/wp-ultimate-review/wordpress-wp-ultimate-review-plugin-2-2-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-47h2-h6q2-ghrw",
"modified": "2023-10-23T00:30:21Z",
"published": "2023-10-23T00:30:21Z",
"aliases": [
"CVE-2023-46319"
],
"details": "WALLIX Bastion 9.x before 9.0.9 and 10.x before 10.0.5 allows unauthenticated access to sensitive information by bypassing access control on a network access administration web interface.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46319"
},
{
"type": "WEB",
"url": "https://www.wallix.com/support/alerts/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4qg2-wr83-m4mf",
"modified": "2023-10-23T00:30:21Z",
"published": "2023-10-23T00:30:21Z",
"aliases": [
"CVE-2023-5700"
],
"details": "A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected is an unknown function of the file /protocol/iscgwtunnel/uploadiscgwrouteconf.php. The manipulation of the argument GWLinkId leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-243138 is the identifier assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5700"
},
{
"type": "WEB",
"url": "https://github.com/istlnight/cve/blob/main/NS-ASG-sql-uploadiscgwrouteconf.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.243138"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.243138"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5mrw-cpfj-cjh6",
"modified": "2023-10-23T00:30:21Z",
"published": "2023-10-23T00:30:21Z",
"aliases": [
"CVE-2023-5698"
],
"details": "A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. This vulnerability affects unknown code of the file pages_deposit_money.php. The manipulation of the argument account_number with the input 421873905--><ScRiPt%20>alert(9523)</ScRiPt><!-- leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243136.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5698"
},
{
"type": "WEB",
"url": "https://github.com/E1CHO/cve_hub/blob/main/Internet%20Banking%20System/Internet%20Banking%20System%20-%20vuln%206.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.243136"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.243136"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5q5q-4pvv-q47c",
"modified": "2023-10-23T00:30:20Z",
"published": "2023-10-23T00:30:20Z",
"aliases": [
"CVE-2023-46089"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in Lee Le @ Userback Userback plugin <= 1.0.13 versions.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46089"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/userback/wordpress-userback-plugin-1-0-13-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8cgf-r9f6-hj56",
"modified": "2023-10-23T00:30:21Z",
"published": "2023-10-23T00:30:21Z",
"aliases": [
"CVE-2023-5694"
],
"details": "A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been classified as problematic. Affected is an unknown function of the file pages_system_settings.php. The manipulation of the argument sys_name with the input <ScRiPt >alert(991)</ScRiPt> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243132.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5694"
},
{
"type": "WEB",
"url": "https://github.com/E1CHO/cve_hub/blob/main/Internet%20Banking%20System/Internet%20Banking%20System%20-%20vuln%202.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.243132"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.243132"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c89h-9543-w7hx",
"modified": "2023-10-23T00:30:20Z",
"published": "2023-10-23T00:30:20Z",
"aliases": [
"CVE-2023-46095"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole Smooth Scroll Links [SSL] plugin <= 1.1.0 versions.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46095"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/smooth-scrolling-links-ssl/wordpress-smooth-scroll-links-ssl-plugin-1-1-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h9qg-8cx4-mh74",
"modified": "2023-10-23T00:30:21Z",
"published": "2023-10-23T00:30:21Z",
"aliases": [
"CVE-2023-46321"
],
"details": "iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs. They may have shell metacharacters for a /usr/bin/man command line.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46321"
},
{
"type": "WEB",
"url": "https://gitlab.com/gnachman/iterm2/-/commit/de3d351e1bd3bc1c1a4f85fe976c592e497dd071"
},
{
"type": "WEB",
"url": "https://iterm2.com/downloads.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jh7f-2hf7-8vxp",
"modified": "2023-10-23T00:30:21Z",
"published": "2023-10-23T00:30:21Z",
"aliases": [
"CVE-2023-5696"
],
"details": "A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file pages_transfer_money.php. The manipulation of the argument account_number with the input 357146928--><ScRiPt%20>alert(9206)</ScRiPt><!-- leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-243134 is the identifier assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5696"
},
{
"type": "WEB",
"url": "https://github.com/E1CHO/cve_hub/blob/main/Internet%20Banking%20System/Internet%20Banking%20System%20-%20vuln%204.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.243134"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.243134"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jq2h-j9qf-53rv",
"modified": "2023-10-23T00:30:20Z",
"published": "2023-10-23T00:30:20Z",
"aliases": [
"CVE-2023-46315"
],
"details": "The zanllp sd-webui-infinite-image-browsing (aka Infinite Image Browsing) extension before 977815a for stable-diffusion-webui (aka Stable Diffusion web UI), if Gradio authentication is enabled without secret key configuration, allows remote attackers to read any local file via /file?path= in the URL, as demonstrated by reading /proc/self/environ to discover credentials.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46315"
},
{
"type": "WEB",
"url": "https://github.com/zanllp/sd-webui-infinite-image-browsing/issues/387"
},
{
"type": "WEB",
"url": "https://github.com/zanllp/sd-webui-infinite-image-browsing/pull/368/commits/977815a2b28ad953c10ef0114c365f698c4b8f19"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mvw9-7543-rjjg",
"modified": "2023-10-23T00:30:21Z",
"published": "2023-10-23T00:30:21Z",
"aliases": [
"CVE-2023-46322"
],
"details": "iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial character may be non-alphanumeric. The hostname's other characters may be outside the set of alphanumeric characters, dash, and period.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46322"
},
{
"type": "WEB",
"url": "https://gitlab.com/gnachman/iterm2/-/commit/ef7bb84520013b2524df9787d4aa9f2c96746c01"
},
{
"type": "WEB",
"url": "https://iterm2.com/downloads.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r4wr-j2mc-r37v",
"modified": "2023-10-23T00:30:21Z",
"published": "2023-10-23T00:30:21Z",
"aliases": [
"CVE-2023-5693"
],
"details": "A vulnerability was found in CodeAstro Internet Banking System 1.0 and classified as critical. This issue affects some unknown processing of the file pages_reset_pwd.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243131.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5693"
},
{
"type": "WEB",
"url": "https://github.com/E1CHO/cve_hub/blob/main/Internet%20Banking%20System/Internet%20Banking%20System%20-%20vuln%201.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.243131"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.243131"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vwhm-7rfg-7rqc",
"modified": "2023-10-23T00:30:21Z",
"published": "2023-10-23T00:30:20Z",
"aliases": [
"CVE-2023-46317"
],
"details": "Knot Resolver before 5.7.0 performs many TCP reconnections upon receiving certain nonsensical responses from servers.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46317"
},
{
"type": "WEB",
"url": "https://gitlab.nic.cz/knot/knot-resolver/-/merge_requests/1448"
},
{
"type": "WEB",
"url": "https://www.knot-resolver.cz/2023-08-22-knot-resolver-5.7.0.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-whr7-4gp3-wpwc",
"modified": "2023-10-23T00:30:21Z",
"published": "2023-10-23T00:30:21Z",
"aliases": [
"CVE-2023-5697"
],
"details": "A vulnerability classified as problematic has been found in CodeAstro Internet Banking System 1.0. This affects an unknown part of the file pages_withdraw_money.php. The manipulation of the argument account_number with the input 287359614--><ScRiPt%20>alert(1234)</ScRiPt><!-- leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243135.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5697"
},
{
"type": "WEB",
"url": "https://github.com/E1CHO/cve_hub/blob/main/Internet%20Banking%20System/Internet%20Banking%20System%20-%20vuln%205.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.243135"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.243135"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xq99-q5xg-8fq7",
"modified": "2023-10-23T00:30:21Z",
"published": "2023-10-23T00:30:21Z",
"aliases": [
"CVE-2023-5699"
],
"details": "A vulnerability, which was classified as problematic, has been found in CodeAstro Internet Banking System 1.0. This issue affects some unknown processing of the file pages_view_client.php. The manipulation of the argument acc_name with the input Johnnie Reyes'\"()&%<zzz><ScRiPt >alert(5646)</ScRiPt> leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243137 was assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5699"
},
{
"type": "WEB",
"url": "https://github.com/E1CHO/cve_hub/blob/main/Internet%20Banking%20System/Internet%20Banking%20System%20-%20vuln%207.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.243137"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.243137"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}