Publish Advisories

GHSA-vh2x-5rx6-qqhv
GHSA-8p5h-3mcg-frjf
GHSA-g7qw-4p9h-v9vx
GHSA-27hv-w8j5-r6ww
GHSA-3w6w-r9vq-3r79
GHSA-4c3x-wrfg-6pjr
GHSA-pj8j-f4gx-wrgf
GHSA-whch-9pr2-9fvq
This commit is contained in:
advisory-database[bot]
2024-01-31 03:31:51 +00:00
parent efd23b5218
commit 30fc42668d
8 changed files with 202 additions and 0 deletions
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230517-0009/"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50495"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"
},
{
"type": "WEB",
"url": "https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html"
@@ -28,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20",
"CWE-79"
],
"severity": "MODERATE",
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-27hv-w8j5-r6ww",
"modified": "2024-01-31T03:30:30Z",
"published": "2024-01-31T03:30:30Z",
"aliases": [
"CVE-2024-23745"
],
"details": "In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can be manipulated to execute arbitrary commands. Additionally, even if a NIB file is modified within an application, Gatekeeper may still permit the execution of the application, enabling the execution of arbitrary commands within the application's context.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23745"
},
{
"type": "WEB",
"url": "https://github.com/louiselalanne/CVE-2024-23745"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-31T02:15:54Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3w6w-r9vq-3r79",
"modified": "2024-01-31T03:30:30Z",
"published": "2024-01-31T03:30:30Z",
"aliases": [
"CVE-2024-22569"
],
"details": "Stored Cross-Site Scripting (XSS) vulnerability in POSCMS v4.6.2, allows attackers to execute arbitrary code via a crafted payload to /index.php?c=install&m=index&step=2&is_install_db=0.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22569"
},
{
"type": "WEB",
"url": "https://github.com/Num-Nine/CVE/issues/12"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-31T02:15:54Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4c3x-wrfg-6pjr",
"modified": "2024-01-31T03:30:30Z",
"published": "2024-01-31T03:30:30Z",
"aliases": [
"CVE-2023-31505"
],
"details": "An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrary code and obtain sensitive information via a crafted .phtml file.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31505"
},
{
"type": "WEB",
"url": "https://m3n0sd0n4ld.github.io/patoHackventuras/cve-2023-31505"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-31T03:15:08Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pj8j-f4gx-wrgf",
"modified": "2024-01-31T03:30:30Z",
"published": "2024-01-31T03:30:30Z",
"aliases": [
"CVE-2023-2439"
],
"details": "The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2439"
},
{
"type": "WEB",
"url": "https://codecanyon.net/item/userpro-user-profiles-with-social-login/5958681"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/21cb424c-4efd-4c12-a08a-6d574f118c28?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-31T03:15:07Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-whch-9pr2-9fvq",
"modified": "2024-01-31T03:30:31Z",
"published": "2024-01-31T03:30:31Z",
"aliases": [
"CVE-2024-1069"
],
"details": "The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'view_page' function in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1069"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/contact-form-entries/trunk/includes/plugin-pages.php?rev=3003884#L1213"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3028640/contact-form-entries#file1"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/120313be-9f98-4448-9f5d-a77186a6ff08?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-31T03:15:08Z"
}
}