From 2f56bb1c22488b6eeaab369ee0c4869a525c18ca Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 25 Sep 2024 06:32:10 +0000 Subject: [PATCH] Publish Advisories GHSA-qq5c-v7vr-8ggg GHSA-rv7p-jc8q-jrfw GHSA-7c7g-wccp-rrhj GHSA-2q3v-8m45-45jg GHSA-cwc9-j2pg-9jgm GHSA-g3fr-5hfh-3cj5 GHSA-gwm9-fmrx-q4pp GHSA-m5hw-c3rg-5mf5 GHSA-mj2f-7q85-79p2 GHSA-qq5m-8wpj-8q6h GHSA-r9fv-vpgh-mfpg GHSA-v6x4-m48j-jm68 GHSA-wq9m-3r6j-2866 --- .../GHSA-qq5c-v7vr-8ggg.json | 6 +- .../GHSA-rv7p-jc8q-jrfw.json | 6 +- .../GHSA-7c7g-wccp-rrhj.json | 6 +- .../GHSA-2q3v-8m45-45jg.json | 35 ++++++++++ .../GHSA-cwc9-j2pg-9jgm.json | 46 ++++++++++++ .../GHSA-g3fr-5hfh-3cj5.json | 70 +++++++++++++++++++ .../GHSA-gwm9-fmrx-q4pp.json | 35 ++++++++++ .../GHSA-m5hw-c3rg-5mf5.json | 42 +++++++++++ .../GHSA-mj2f-7q85-79p2.json | 35 ++++++++++ .../GHSA-qq5m-8wpj-8q6h.json | 42 +++++++++++ .../GHSA-r9fv-vpgh-mfpg.json | 50 +++++++++++++ .../GHSA-v6x4-m48j-jm68.json | 50 +++++++++++++ .../GHSA-wq9m-3r6j-2866.json | 46 ++++++++++++ 13 files changed, 466 insertions(+), 3 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-2q3v-8m45-45jg/GHSA-2q3v-8m45-45jg.json create mode 100644 advisories/unreviewed/2024/09/GHSA-cwc9-j2pg-9jgm/GHSA-cwc9-j2pg-9jgm.json create mode 100644 advisories/unreviewed/2024/09/GHSA-g3fr-5hfh-3cj5/GHSA-g3fr-5hfh-3cj5.json create mode 100644 advisories/unreviewed/2024/09/GHSA-gwm9-fmrx-q4pp/GHSA-gwm9-fmrx-q4pp.json create mode 100644 advisories/unreviewed/2024/09/GHSA-m5hw-c3rg-5mf5/GHSA-m5hw-c3rg-5mf5.json create mode 100644 advisories/unreviewed/2024/09/GHSA-mj2f-7q85-79p2/GHSA-mj2f-7q85-79p2.json create mode 100644 advisories/unreviewed/2024/09/GHSA-qq5m-8wpj-8q6h/GHSA-qq5m-8wpj-8q6h.json create mode 100644 advisories/unreviewed/2024/09/GHSA-r9fv-vpgh-mfpg/GHSA-r9fv-vpgh-mfpg.json create mode 100644 advisories/unreviewed/2024/09/GHSA-v6x4-m48j-jm68/GHSA-v6x4-m48j-jm68.json create mode 100644 advisories/unreviewed/2024/09/GHSA-wq9m-3r6j-2866/GHSA-wq9m-3r6j-2866.json diff --git a/advisories/unreviewed/2024/04/GHSA-qq5c-v7vr-8ggg/GHSA-qq5c-v7vr-8ggg.json b/advisories/unreviewed/2024/04/GHSA-qq5c-v7vr-8ggg/GHSA-qq5c-v7vr-8ggg.json index b6e0f49c1b2..ed591df8e37 100644 --- a/advisories/unreviewed/2024/04/GHSA-qq5c-v7vr-8ggg/GHSA-qq5c-v7vr-8ggg.json +++ b/advisories/unreviewed/2024/04/GHSA-qq5c-v7vr-8ggg/GHSA-qq5c-v7vr-8ggg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qq5c-v7vr-8ggg", - "modified": "2024-07-03T18:34:23Z", + "modified": "2024-09-25T06:30:42Z", "published": "2024-04-15T12:30:34Z", "aliases": [ "CVE-2024-29218" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://www.keyence.com/kv_vulnerability240329_en" + }, + { + "type": "WEB", + "url": "https://www.keyence.com/kv_vulnerability240924_en" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-rv7p-jc8q-jrfw/GHSA-rv7p-jc8q-jrfw.json b/advisories/unreviewed/2024/04/GHSA-rv7p-jc8q-jrfw/GHSA-rv7p-jc8q-jrfw.json index 2a2585fcef2..fe3e83dfd69 100644 --- a/advisories/unreviewed/2024/04/GHSA-rv7p-jc8q-jrfw/GHSA-rv7p-jc8q-jrfw.json +++ b/advisories/unreviewed/2024/04/GHSA-rv7p-jc8q-jrfw/GHSA-rv7p-jc8q-jrfw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rv7p-jc8q-jrfw", - "modified": "2024-08-01T15:31:39Z", + "modified": "2024-09-25T06:30:42Z", "published": "2024-04-15T12:30:34Z", "aliases": [ "CVE-2024-29219" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://www.keyence.com/kv_vulnerability240329_en" + }, + { + "type": "WEB", + "url": "https://www.keyence.com/kv_vulnerability240924_en" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json b/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json index d54e0af3fb2..c70a678b45d 100644 --- a/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json +++ b/advisories/unreviewed/2024/08/GHSA-7c7g-wccp-rrhj/GHSA-7c7g-wccp-rrhj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7c7g-wccp-rrhj", - "modified": "2024-09-25T03:30:35Z", + "modified": "2024-09-25T06:30:42Z", "published": "2024-08-05T15:30:53Z", "aliases": [ "CVE-2024-7409" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7409" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:6811" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:6964" diff --git a/advisories/unreviewed/2024/09/GHSA-2q3v-8m45-45jg/GHSA-2q3v-8m45-45jg.json b/advisories/unreviewed/2024/09/GHSA-2q3v-8m45-45jg/GHSA-2q3v-8m45-45jg.json new file mode 100644 index 00000000000..05cf0c60aad --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2q3v-8m45-45jg/GHSA-2q3v-8m45-45jg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2q3v-8m45-45jg", + "modified": "2024-09-25T06:30:42Z", + "published": "2024-09-25T06:30:42Z", + "aliases": [ + "CVE-2024-6845" + ], + "details": "The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6845" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/cfaaa843-d89e-42d4-90d9-988293499d26" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T06:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cwc9-j2pg-9jgm/GHSA-cwc9-j2pg-9jgm.json b/advisories/unreviewed/2024/09/GHSA-cwc9-j2pg-9jgm/GHSA-cwc9-j2pg-9jgm.json new file mode 100644 index 00000000000..5d3a9df377c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cwc9-j2pg-9jgm/GHSA-cwc9-j2pg-9jgm.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwc9-j2pg-9jgm", + "modified": "2024-09-25T06:30:42Z", + "published": "2024-09-25T06:30:42Z", + "aliases": [ + "CVE-2024-7385" + ], + "details": "The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7385" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-simple-html-sitemap/tags/3.1/inc/wshs_saved.php#L47" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3155037/wp-simple-html-sitemap/trunk/inc/wshs_saved.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f529b981-623f-4bd3-9155-ebfab4c65d1d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T04:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g3fr-5hfh-3cj5/GHSA-g3fr-5hfh-3cj5.json b/advisories/unreviewed/2024/09/GHSA-g3fr-5hfh-3cj5/GHSA-g3fr-5hfh-3cj5.json new file mode 100644 index 00000000000..77a7ecb2ff0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g3fr-5hfh-3cj5/GHSA-g3fr-5hfh-3cj5.json @@ -0,0 +1,70 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3fr-5hfh-3cj5", + "modified": "2024-09-25T06:30:42Z", + "published": "2024-09-25T06:30:42Z", + "aliases": [ + "CVE-2024-8515" + ], + "details": "The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like 'TF E Slider Widget', 'TF Video Widget', 'TF Team Widget' and more in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on URL attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8515" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/themesflat-addons-for-elementor/trunk/assets/js/tf-carousel.js#L41" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/themesflat-addons-for-elementor/trunk/assets/js/tf-post.js#L42" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/themesflat-addons-for-elementor/trunk/assets/js/tf-testimonial.js#L41" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/themesflat-addons-for-elementor/trunk/assets/js/tf-woo-product.js#L42" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/themesflat-addons-for-elementor/trunk/widgets/widget-flex-slide.php#L2522" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/themesflat-addons-for-elementor/trunk/widgets/widget-team.php#L1234" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/themesflat-addons-for-elementor/trunk/widgets/widget-team.php#L1285" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/themesflat-addons-for-elementor/trunk/widgets/widget-video.php#L318" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1603c61b-11a3-41e5-b339-a9411b02f383?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T04:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gwm9-fmrx-q4pp/GHSA-gwm9-fmrx-q4pp.json b/advisories/unreviewed/2024/09/GHSA-gwm9-fmrx-q4pp/GHSA-gwm9-fmrx-q4pp.json new file mode 100644 index 00000000000..6791749ed5d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gwm9-fmrx-q4pp/GHSA-gwm9-fmrx-q4pp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwm9-fmrx-q4pp", + "modified": "2024-09-25T06:30:42Z", + "published": "2024-09-25T06:30:42Z", + "aliases": [ + "CVE-2024-7892" + ], + "details": "The adstxt Plugin WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7892" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c07a4992-c9a1-46a4-9a52-9e38b6d15440" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T06:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m5hw-c3rg-5mf5/GHSA-m5hw-c3rg-5mf5.json b/advisories/unreviewed/2024/09/GHSA-m5hw-c3rg-5mf5/GHSA-m5hw-c3rg-5mf5.json new file mode 100644 index 00000000000..84434ebde2a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m5hw-c3rg-5mf5/GHSA-m5hw-c3rg-5mf5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5hw-c3rg-5mf5", + "modified": "2024-09-25T06:30:42Z", + "published": "2024-09-25T06:30:42Z", + "aliases": [ + "CVE-2024-8516" + ], + "details": "The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.1 via the render() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract limited post information from draft and future scheduled posts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8516" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/themesflat-addons-for-elementor/trunk/widgets/widget-posts.php#L3327" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/75c5d4e6-9ef3-4b12-9ee9-67121dbb0fcd?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T04:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mj2f-7q85-79p2/GHSA-mj2f-7q85-79p2.json b/advisories/unreviewed/2024/09/GHSA-mj2f-7q85-79p2/GHSA-mj2f-7q85-79p2.json new file mode 100644 index 00000000000..a3bbc5ba634 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mj2f-7q85-79p2/GHSA-mj2f-7q85-79p2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mj2f-7q85-79p2", + "modified": "2024-09-25T06:30:42Z", + "published": "2024-09-25T06:30:42Z", + "aliases": [ + "CVE-2024-7878" + ], + "details": "The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7878" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/9166cf91-69e5-4786-a6a9-816db7d47b07" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T06:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qq5m-8wpj-8q6h/GHSA-qq5m-8wpj-8q6h.json b/advisories/unreviewed/2024/09/GHSA-qq5m-8wpj-8q6h/GHSA-qq5m-8wpj-8q6h.json new file mode 100644 index 00000000000..d3b3d66c4e1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qq5m-8wpj-8q6h/GHSA-qq5m-8wpj-8q6h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq5m-8wpj-8q6h", + "modified": "2024-09-25T06:30:42Z", + "published": "2024-09-25T06:30:42Z", + "aliases": [ + "CVE-2024-8658" + ], + "details": "The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mycred_update_database() function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to upgrade an out of date database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8658" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3156989/mycred/trunk/includes/mycred-database-upgrade.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/20be9a37-9e9f-4791-a27c-e0db007be787?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T06:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r9fv-vpgh-mfpg/GHSA-r9fv-vpgh-mfpg.json b/advisories/unreviewed/2024/09/GHSA-r9fv-vpgh-mfpg/GHSA-r9fv-vpgh-mfpg.json new file mode 100644 index 00000000000..d42fa473385 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r9fv-vpgh-mfpg/GHSA-r9fv-vpgh-mfpg.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9fv-vpgh-mfpg", + "modified": "2024-09-25T06:30:42Z", + "published": "2024-09-25T06:30:42Z", + "aliases": [ + "CVE-2024-8668" + ], + "details": "The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tooltip and countdown functionality in all versions up to, and including, 2.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8668" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/woolentor-addons/tags/2.9.7/assets/js/woolentor-widgets-active.js#L111" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/woolentor-addons/tags/2.9.7/assets/js/woolentor-widgets-active.js#L151" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3155859%40woolentor-addons&new=3155859%40woolentor-addons&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/afe2b2e5-601f-4b6b-940a-b82f723b8776?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T05:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-v6x4-m48j-jm68/GHSA-v6x4-m48j-jm68.json b/advisories/unreviewed/2024/09/GHSA-v6x4-m48j-jm68/GHSA-v6x4-m48j-jm68.json new file mode 100644 index 00000000000..c2ee482ff2b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-v6x4-m48j-jm68/GHSA-v6x4-m48j-jm68.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6x4-m48j-jm68", + "modified": "2024-09-25T06:30:42Z", + "published": "2024-09-25T06:30:42Z", + "aliases": [ + "CVE-2024-8275" + ], + "details": "The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Only sites that have manually added tribe_has_next_event() will be vulnerable to this SQL injection.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8275" + }, + { + "type": "WEB", + "url": "https://docs.theeventscalendar.com/reference/functions/tribe_has_next_event" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3152853%40the-events-calendar&new=3152853%40the-events-calendar&sfp_email=&sfph_mail=#file18" + }, + { + "type": "WEB", + "url": "https://theeventscalendar.com/knowledgebase/customizing-template-files-2-legacy" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f59891c7-db1a-4688-8616-8877d7d7960d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T05:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wq9m-3r6j-2866/GHSA-wq9m-3r6j-2866.json b/advisories/unreviewed/2024/09/GHSA-wq9m-3r6j-2866/GHSA-wq9m-3r6j-2866.json new file mode 100644 index 00000000000..228b6108d95 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wq9m-3r6j-2866/GHSA-wq9m-3r6j-2866.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq9m-3r6j-2866", + "modified": "2024-09-25T06:30:42Z", + "published": "2024-09-25T06:30:42Z", + "aliases": [ + "CVE-2024-8514" + ], + "details": "The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.11 via deserialization of untrusted input from the 'prisna_import' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8514" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/google-website-translator/tags/1.4.11/classes/admin.class.php#L267" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3155285" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4183c3f7-7794-45f3-8fad-b87ffec3639c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-25T04:15:04Z" + } +} \ No newline at end of file