Publish Advisories

GHSA-rmm3-6hwr-c8q9
GHSA-6qh2-62r9-72q3
GHSA-p564-948g-fpq9
GHSA-4p52-qfg6-cwjr
GHSA-4v9x-wfx7-57r9
GHSA-5g84-rh9g-367c
GHSA-j56p-gcm8-59g5
GHSA-jqxm-w4mh-hq99
GHSA-mq29-j5xf-cjwr
GHSA-p7q4-fcj5-j6x7
GHSA-wxww-3fw5-44w4
GHSA-x7w6-3cp2-qjcv
GHSA-xhr4-fjfq-6r46
This commit is contained in:
advisory-database[bot]
2023-10-20 21:33:04 +00:00
parent 85259e5596
commit 33dd6b4516
13 changed files with 163 additions and 13 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rmm3-6hwr-c8q9",
"modified": "2022-05-24T17:13:46Z",
"modified": "2023-10-20T21:30:51Z",
"published": "2022-05-24T17:13:46Z",
"aliases": [
"CVE-2019-20636"
],
"details": "In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds writes via a crafted keycode table, as demonstrated by input_set_keycode, aka CID-cb222aed03d7.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -45,7 +48,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -56,6 +56,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-125",
"CWE-416"
],
"severity": "HIGH",
@@ -44,7 +44,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400"
"CWE-400",
"CWE-770"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4p52-qfg6-cwjr",
"modified": "2023-10-20T21:31:01Z",
"published": "2023-10-20T21:31:01Z",
"aliases": [
"CVE-2023-37824"
],
"details": "Sitolog sitologapplicationconnect v7.8.a and before was discovered to contain a SQL injection vulnerability via the component /activate_hook.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37824"
},
{
"type": "WEB",
"url": "https://security.friendsofpresta.org/modules/2023/10/11/sitologapplicationconnect.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
"CWE-20",
"CWE-787"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5g84-rh9g-367c",
"modified": "2023-10-20T21:31:01Z",
"published": "2023-10-20T21:31:01Z",
"aliases": [
"CVE-2023-5682"
],
"details": "A vulnerability has been found in Tongda OA 2017 and classified as critical. This vulnerability affects unknown code of the file general/hr/training/record/delete.php. The manipulation of the argument RECORD_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-243058 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5682"
},
{
"type": "WEB",
"url": "https://github.com/Godfather-onec/cve/blob/main/sql.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.243058"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.243058"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j56p-gcm8-59g5",
"modified": "2023-10-20T21:31:01Z",
"published": "2023-10-20T21:31:01Z",
"aliases": [
"CVE-2023-5681"
],
"details": "A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /admin/list_addr_fwresource_ip.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243057 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5681"
},
{
"type": "WEB",
"url": "https://github.com/Wsecpro/cve1/blob/main/NS-ASG-sql-list_addr_fwresource_ip.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.243057"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.243057"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jqxm-w4mh-hq99",
"modified": "2023-10-16T21:30:27Z",
"modified": "2023-10-20T21:31:00Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-5133"
],
"details": "This user-activity-log-pro WordPress plugin before 2.3.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
@@ -40,6 +40,10 @@
{
"type": "WEB",
"url": "https://www.winimage.com/zLibDll/minizip.html"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/10/20/9"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p7q4-fcj5-j6x7",
"modified": "2023-10-16T21:30:27Z",
"modified": "2023-10-20T21:31:00Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-5167"
],
"details": "The User Activity Log Pro WordPress plugin before 2.3.4 does not properly escape recorded User-Agents in the user activity logs dashboard, which may allow visitors to conduct Stored Cross-Site Scripting attacks.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wxww-3fw5-44w4",
"modified": "2023-10-13T12:30:17Z",
"modified": "2023-10-20T21:31:00Z",
"published": "2023-10-13T12:30:17Z",
"aliases": [
"CVE-2023-43079"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x7w6-3cp2-qjcv",
"modified": "2023-10-16T21:30:27Z",
"modified": "2023-10-20T21:31:00Z",
"published": "2023-10-16T21:30:27Z",
"aliases": [
"CVE-2023-5561"
],
"details": "The Popup Builder WordPress plugin through 4.1.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
@@ -40,7 +40,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-122"
"CWE-122",
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,