diff --git a/advisories/unreviewed/2023/08/GHSA-39q6-4vrm-fv3g/GHSA-39q6-4vrm-fv3g.json b/advisories/unreviewed/2023/08/GHSA-39q6-4vrm-fv3g/GHSA-39q6-4vrm-fv3g.json index efc40400269..b1559869d6d 100644 --- a/advisories/unreviewed/2023/08/GHSA-39q6-4vrm-fv3g/GHSA-39q6-4vrm-fv3g.json +++ b/advisories/unreviewed/2023/08/GHSA-39q6-4vrm-fv3g/GHSA-39q6-4vrm-fv3g.json @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://github.com/krb5/krb5/compare/krb5-1.21-final...krb5-1.21.1-final" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00031.html" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230908-0004/" diff --git a/advisories/unreviewed/2023/10/GHSA-3jr9-479w-vh8c/GHSA-3jr9-479w-vh8c.json b/advisories/unreviewed/2023/10/GHSA-3jr9-479w-vh8c/GHSA-3jr9-479w-vh8c.json new file mode 100644 index 00000000000..4b1e872aab7 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-3jr9-479w-vh8c/GHSA-3jr9-479w-vh8c.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jr9-479w-vh8c", + "modified": "2023-10-23T00:30:21Z", + "published": "2023-10-23T00:30:21Z", + "aliases": [ + "CVE-2023-5695" + ], + "details": "A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file pages_reset_pwd.php. The manipulation of the argument email with the input testing%40example.com'%26%25alert(9860) leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243133 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5695" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Internet%20Banking%20System/Internet%20Banking%20System%20-%20vuln%203.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.243133" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.243133" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-3vj4-3g37-rf7w/GHSA-3vj4-3g37-rf7w.json b/advisories/unreviewed/2023/10/GHSA-3vj4-3g37-rf7w/GHSA-3vj4-3g37-rf7w.json new file mode 100644 index 00000000000..318f43cd938 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-3vj4-3g37-rf7w/GHSA-3vj4-3g37-rf7w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vj4-3g37-rf7w", + "modified": "2023-10-23T00:30:20Z", + "published": "2023-10-23T00:30:20Z", + "aliases": [ + "CVE-2023-46085" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.2.4 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46085" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-ultimate-review/wordpress-wp-ultimate-review-plugin-2-2-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-47h2-h6q2-ghrw/GHSA-47h2-h6q2-ghrw.json b/advisories/unreviewed/2023/10/GHSA-47h2-h6q2-ghrw/GHSA-47h2-h6q2-ghrw.json new file mode 100644 index 00000000000..132f69f7d8d --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-47h2-h6q2-ghrw/GHSA-47h2-h6q2-ghrw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47h2-h6q2-ghrw", + "modified": "2023-10-23T00:30:21Z", + "published": "2023-10-23T00:30:21Z", + "aliases": [ + "CVE-2023-46319" + ], + "details": "WALLIX Bastion 9.x before 9.0.9 and 10.x before 10.0.5 allows unauthenticated access to sensitive information by bypassing access control on a network access administration web interface.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46319" + }, + { + "type": "WEB", + "url": "https://www.wallix.com/support/alerts/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-4qg2-wr83-m4mf/GHSA-4qg2-wr83-m4mf.json b/advisories/unreviewed/2023/10/GHSA-4qg2-wr83-m4mf/GHSA-4qg2-wr83-m4mf.json new file mode 100644 index 00000000000..594f0292305 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-4qg2-wr83-m4mf/GHSA-4qg2-wr83-m4mf.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qg2-wr83-m4mf", + "modified": "2023-10-23T00:30:21Z", + "published": "2023-10-23T00:30:21Z", + "aliases": [ + "CVE-2023-5700" + ], + "details": "A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected is an unknown function of the file /protocol/iscgwtunnel/uploadiscgwrouteconf.php. The manipulation of the argument GWLinkId leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-243138 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5700" + }, + { + "type": "WEB", + "url": "https://github.com/istlnight/cve/blob/main/NS-ASG-sql-uploadiscgwrouteconf.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.243138" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.243138" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-5mrw-cpfj-cjh6/GHSA-5mrw-cpfj-cjh6.json b/advisories/unreviewed/2023/10/GHSA-5mrw-cpfj-cjh6/GHSA-5mrw-cpfj-cjh6.json new file mode 100644 index 00000000000..c6f0f0dc3c6 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-5mrw-cpfj-cjh6/GHSA-5mrw-cpfj-cjh6.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mrw-cpfj-cjh6", + "modified": "2023-10-23T00:30:21Z", + "published": "2023-10-23T00:30:21Z", + "aliases": [ + "CVE-2023-5698" + ], + "details": "A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. This vulnerability affects unknown code of the file pages_deposit_money.php. The manipulation of the argument account_number with the input 421873905-->alert(9523)alert(9206)alert(1234)