From 30fc42668dda31fe5610988da245cbd00d468267 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 31 Jan 2024 03:31:51 +0000 Subject: [PATCH] Publish Advisories GHSA-vh2x-5rx6-qqhv GHSA-8p5h-3mcg-frjf GHSA-g7qw-4p9h-v9vx GHSA-27hv-w8j5-r6ww GHSA-3w6w-r9vq-3r79 GHSA-4c3x-wrfg-6pjr GHSA-pj8j-f4gx-wrgf GHSA-whch-9pr2-9fvq --- .../GHSA-vh2x-5rx6-qqhv.json | 4 ++ .../GHSA-8p5h-3mcg-frjf.json | 4 ++ .../GHSA-g7qw-4p9h-v9vx.json | 1 + .../GHSA-27hv-w8j5-r6ww.json | 35 ++++++++++++++ .../GHSA-3w6w-r9vq-3r79.json | 35 ++++++++++++++ .../GHSA-4c3x-wrfg-6pjr.json | 35 ++++++++++++++ .../GHSA-pj8j-f4gx-wrgf.json | 42 +++++++++++++++++ .../GHSA-whch-9pr2-9fvq.json | 46 +++++++++++++++++++ 8 files changed, 202 insertions(+) create mode 100644 advisories/unreviewed/2024/01/GHSA-27hv-w8j5-r6ww/GHSA-27hv-w8j5-r6ww.json create mode 100644 advisories/unreviewed/2024/01/GHSA-3w6w-r9vq-3r79/GHSA-3w6w-r9vq-3r79.json create mode 100644 advisories/unreviewed/2024/01/GHSA-4c3x-wrfg-6pjr/GHSA-4c3x-wrfg-6pjr.json create mode 100644 advisories/unreviewed/2024/01/GHSA-pj8j-f4gx-wrgf/GHSA-pj8j-f4gx-wrgf.json create mode 100644 advisories/unreviewed/2024/01/GHSA-whch-9pr2-9fvq/GHSA-whch-9pr2-9fvq.json diff --git a/advisories/unreviewed/2023/04/GHSA-vh2x-5rx6-qqhv/GHSA-vh2x-5rx6-qqhv.json b/advisories/unreviewed/2023/04/GHSA-vh2x-5rx6-qqhv/GHSA-vh2x-5rx6-qqhv.json index 518b83582b9..42a1b2637e3 100644 --- a/advisories/unreviewed/2023/04/GHSA-vh2x-5rx6-qqhv/GHSA-vh2x-5rx6-qqhv.json +++ b/advisories/unreviewed/2023/04/GHSA-vh2x-5rx6-qqhv/GHSA-vh2x-5rx6-qqhv.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230517-0009/" diff --git a/advisories/unreviewed/2023/12/GHSA-8p5h-3mcg-frjf/GHSA-8p5h-3mcg-frjf.json b/advisories/unreviewed/2023/12/GHSA-8p5h-3mcg-frjf/GHSA-8p5h-3mcg-frjf.json index 6397ddc1350..0746e1cd348 100644 --- a/advisories/unreviewed/2023/12/GHSA-8p5h-3mcg-frjf/GHSA-8p5h-3mcg-frjf.json +++ b/advisories/unreviewed/2023/12/GHSA-8p5h-3mcg-frjf/GHSA-8p5h-3mcg-frjf.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50495" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/" + }, { "type": "WEB", "url": "https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html" diff --git a/advisories/unreviewed/2023/12/GHSA-g7qw-4p9h-v9vx/GHSA-g7qw-4p9h-v9vx.json b/advisories/unreviewed/2023/12/GHSA-g7qw-4p9h-v9vx/GHSA-g7qw-4p9h-v9vx.json index 4acc3b09719..bf797158a40 100644 --- a/advisories/unreviewed/2023/12/GHSA-g7qw-4p9h-v9vx/GHSA-g7qw-4p9h-v9vx.json +++ b/advisories/unreviewed/2023/12/GHSA-g7qw-4p9h-v9vx/GHSA-g7qw-4p9h-v9vx.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-20", "CWE-79" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/01/GHSA-27hv-w8j5-r6ww/GHSA-27hv-w8j5-r6ww.json b/advisories/unreviewed/2024/01/GHSA-27hv-w8j5-r6ww/GHSA-27hv-w8j5-r6ww.json new file mode 100644 index 00000000000..b31ca867c96 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-27hv-w8j5-r6ww/GHSA-27hv-w8j5-r6ww.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27hv-w8j5-r6ww", + "modified": "2024-01-31T03:30:30Z", + "published": "2024-01-31T03:30:30Z", + "aliases": [ + "CVE-2024-23745" + ], + "details": "In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can be manipulated to execute arbitrary commands. Additionally, even if a NIB file is modified within an application, Gatekeeper may still permit the execution of the application, enabling the execution of arbitrary commands within the application's context.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23745" + }, + { + "type": "WEB", + "url": "https://github.com/louiselalanne/CVE-2024-23745" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T02:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3w6w-r9vq-3r79/GHSA-3w6w-r9vq-3r79.json b/advisories/unreviewed/2024/01/GHSA-3w6w-r9vq-3r79/GHSA-3w6w-r9vq-3r79.json new file mode 100644 index 00000000000..bbedb7394b3 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3w6w-r9vq-3r79/GHSA-3w6w-r9vq-3r79.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w6w-r9vq-3r79", + "modified": "2024-01-31T03:30:30Z", + "published": "2024-01-31T03:30:30Z", + "aliases": [ + "CVE-2024-22569" + ], + "details": "Stored Cross-Site Scripting (XSS) vulnerability in POSCMS v4.6.2, allows attackers to execute arbitrary code via a crafted payload to /index.php?c=install&m=index&step=2&is_install_db=0.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22569" + }, + { + "type": "WEB", + "url": "https://github.com/Num-Nine/CVE/issues/12" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T02:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4c3x-wrfg-6pjr/GHSA-4c3x-wrfg-6pjr.json b/advisories/unreviewed/2024/01/GHSA-4c3x-wrfg-6pjr/GHSA-4c3x-wrfg-6pjr.json new file mode 100644 index 00000000000..2e6be09c916 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-4c3x-wrfg-6pjr/GHSA-4c3x-wrfg-6pjr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c3x-wrfg-6pjr", + "modified": "2024-01-31T03:30:30Z", + "published": "2024-01-31T03:30:30Z", + "aliases": [ + "CVE-2023-31505" + ], + "details": "An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrary code and obtain sensitive information via a crafted .phtml file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31505" + }, + { + "type": "WEB", + "url": "https://m3n0sd0n4ld.github.io/patoHackventuras/cve-2023-31505" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-pj8j-f4gx-wrgf/GHSA-pj8j-f4gx-wrgf.json b/advisories/unreviewed/2024/01/GHSA-pj8j-f4gx-wrgf/GHSA-pj8j-f4gx-wrgf.json new file mode 100644 index 00000000000..4116711d64d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-pj8j-f4gx-wrgf/GHSA-pj8j-f4gx-wrgf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj8j-f4gx-wrgf", + "modified": "2024-01-31T03:30:30Z", + "published": "2024-01-31T03:30:30Z", + "aliases": [ + "CVE-2023-2439" + ], + "details": "The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2439" + }, + { + "type": "WEB", + "url": "https://codecanyon.net/item/userpro-user-profiles-with-social-login/5958681" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/21cb424c-4efd-4c12-a08a-6d574f118c28?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-whch-9pr2-9fvq/GHSA-whch-9pr2-9fvq.json b/advisories/unreviewed/2024/01/GHSA-whch-9pr2-9fvq/GHSA-whch-9pr2-9fvq.json new file mode 100644 index 00000000000..28c5e045d04 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-whch-9pr2-9fvq/GHSA-whch-9pr2-9fvq.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whch-9pr2-9fvq", + "modified": "2024-01-31T03:30:31Z", + "published": "2024-01-31T03:30:31Z", + "aliases": [ + "CVE-2024-1069" + ], + "details": "The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'view_page' function in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1069" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/contact-form-entries/trunk/includes/plugin-pages.php?rev=3003884#L1213" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3028640/contact-form-entries#file1" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/120313be-9f98-4448-9f5d-a77186a6ff08?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T03:15:08Z" + } +} \ No newline at end of file