diff --git a/advisories/unreviewed/2022/05/GHSA-rmm3-6hwr-c8q9/GHSA-rmm3-6hwr-c8q9.json b/advisories/unreviewed/2022/05/GHSA-rmm3-6hwr-c8q9/GHSA-rmm3-6hwr-c8q9.json index 6606f388bc0..df8f36a6ff7 100644 --- a/advisories/unreviewed/2022/05/GHSA-rmm3-6hwr-c8q9/GHSA-rmm3-6hwr-c8q9.json +++ b/advisories/unreviewed/2022/05/GHSA-rmm3-6hwr-c8q9/GHSA-rmm3-6hwr-c8q9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rmm3-6hwr-c8q9", - "modified": "2022-05-24T17:13:46Z", + "modified": "2023-10-20T21:30:51Z", "published": "2022-05-24T17:13:46Z", "aliases": [ "CVE-2019-20636" ], "details": "In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds writes via a crafted keycode table, as demonstrated by input_set_keycode, aka CID-cb222aed03d7.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/03/GHSA-6qh2-62r9-72q3/GHSA-6qh2-62r9-72q3.json b/advisories/unreviewed/2023/03/GHSA-6qh2-62r9-72q3/GHSA-6qh2-62r9-72q3.json index 1caffb588c9..0672e5020d1 100644 --- a/advisories/unreviewed/2023/03/GHSA-6qh2-62r9-72q3/GHSA-6qh2-62r9-72q3.json +++ b/advisories/unreviewed/2023/03/GHSA-6qh2-62r9-72q3/GHSA-6qh2-62r9-72q3.json @@ -56,6 +56,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/08/GHSA-p564-948g-fpq9/GHSA-p564-948g-fpq9.json b/advisories/unreviewed/2023/08/GHSA-p564-948g-fpq9/GHSA-p564-948g-fpq9.json index 1ca3dfe16b9..42d835a776f 100644 --- a/advisories/unreviewed/2023/08/GHSA-p564-948g-fpq9/GHSA-p564-948g-fpq9.json +++ b/advisories/unreviewed/2023/08/GHSA-p564-948g-fpq9/GHSA-p564-948g-fpq9.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-4p52-qfg6-cwjr/GHSA-4p52-qfg6-cwjr.json b/advisories/unreviewed/2023/10/GHSA-4p52-qfg6-cwjr/GHSA-4p52-qfg6-cwjr.json new file mode 100644 index 00000000000..31f11d63eff --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-4p52-qfg6-cwjr/GHSA-4p52-qfg6-cwjr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p52-qfg6-cwjr", + "modified": "2023-10-20T21:31:01Z", + "published": "2023-10-20T21:31:01Z", + "aliases": [ + "CVE-2023-37824" + ], + "details": "Sitolog sitologapplicationconnect v7.8.a and before was discovered to contain a SQL injection vulnerability via the component /activate_hook.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37824" + }, + { + "type": "WEB", + "url": "https://security.friendsofpresta.org/modules/2023/10/11/sitologapplicationconnect.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-4v9x-wfx7-57r9/GHSA-4v9x-wfx7-57r9.json b/advisories/unreviewed/2023/10/GHSA-4v9x-wfx7-57r9/GHSA-4v9x-wfx7-57r9.json index 037eb605fc8..59928513451 100644 --- a/advisories/unreviewed/2023/10/GHSA-4v9x-wfx7-57r9/GHSA-4v9x-wfx7-57r9.json +++ b/advisories/unreviewed/2023/10/GHSA-4v9x-wfx7-57r9/GHSA-4v9x-wfx7-57r9.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-5g84-rh9g-367c/GHSA-5g84-rh9g-367c.json b/advisories/unreviewed/2023/10/GHSA-5g84-rh9g-367c/GHSA-5g84-rh9g-367c.json new file mode 100644 index 00000000000..d442f0fb800 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-5g84-rh9g-367c/GHSA-5g84-rh9g-367c.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g84-rh9g-367c", + "modified": "2023-10-20T21:31:01Z", + "published": "2023-10-20T21:31:01Z", + "aliases": [ + "CVE-2023-5682" + ], + "details": "A vulnerability has been found in Tongda OA 2017 and classified as critical. This vulnerability affects unknown code of the file general/hr/training/record/delete.php. The manipulation of the argument RECORD_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-243058 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5682" + }, + { + "type": "WEB", + "url": "https://github.com/Godfather-onec/cve/blob/main/sql.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.243058" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.243058" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-j56p-gcm8-59g5/GHSA-j56p-gcm8-59g5.json b/advisories/unreviewed/2023/10/GHSA-j56p-gcm8-59g5/GHSA-j56p-gcm8-59g5.json new file mode 100644 index 00000000000..2e5dfd6a7df --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-j56p-gcm8-59g5/GHSA-j56p-gcm8-59g5.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j56p-gcm8-59g5", + "modified": "2023-10-20T21:31:01Z", + "published": "2023-10-20T21:31:01Z", + "aliases": [ + "CVE-2023-5681" + ], + "details": "A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /admin/list_addr_fwresource_ip.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243057 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5681" + }, + { + "type": "WEB", + "url": "https://github.com/Wsecpro/cve1/blob/main/NS-ASG-sql-list_addr_fwresource_ip.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.243057" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.243057" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-jqxm-w4mh-hq99/GHSA-jqxm-w4mh-hq99.json b/advisories/unreviewed/2023/10/GHSA-jqxm-w4mh-hq99/GHSA-jqxm-w4mh-hq99.json index 4d36768c4d5..fd161bb93a2 100644 --- a/advisories/unreviewed/2023/10/GHSA-jqxm-w4mh-hq99/GHSA-jqxm-w4mh-hq99.json +++ b/advisories/unreviewed/2023/10/GHSA-jqxm-w4mh-hq99/GHSA-jqxm-w4mh-hq99.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jqxm-w4mh-hq99", - "modified": "2023-10-16T21:30:27Z", + "modified": "2023-10-20T21:31:00Z", "published": "2023-10-16T21:30:27Z", "aliases": [ "CVE-2023-5133" ], "details": "This user-activity-log-pro WordPress plugin before 2.3.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-mq29-j5xf-cjwr/GHSA-mq29-j5xf-cjwr.json b/advisories/unreviewed/2023/10/GHSA-mq29-j5xf-cjwr/GHSA-mq29-j5xf-cjwr.json index 703e155c0e0..3bf248e29ed 100644 --- a/advisories/unreviewed/2023/10/GHSA-mq29-j5xf-cjwr/GHSA-mq29-j5xf-cjwr.json +++ b/advisories/unreviewed/2023/10/GHSA-mq29-j5xf-cjwr/GHSA-mq29-j5xf-cjwr.json @@ -40,6 +40,10 @@ { "type": "WEB", "url": "https://www.winimage.com/zLibDll/minizip.html" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/10/20/9" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-p7q4-fcj5-j6x7/GHSA-p7q4-fcj5-j6x7.json b/advisories/unreviewed/2023/10/GHSA-p7q4-fcj5-j6x7/GHSA-p7q4-fcj5-j6x7.json index ae094629fc2..23db8f75abb 100644 --- a/advisories/unreviewed/2023/10/GHSA-p7q4-fcj5-j6x7/GHSA-p7q4-fcj5-j6x7.json +++ b/advisories/unreviewed/2023/10/GHSA-p7q4-fcj5-j6x7/GHSA-p7q4-fcj5-j6x7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p7q4-fcj5-j6x7", - "modified": "2023-10-16T21:30:27Z", + "modified": "2023-10-20T21:31:00Z", "published": "2023-10-16T21:30:27Z", "aliases": [ "CVE-2023-5167" ], "details": "The User Activity Log Pro WordPress plugin before 2.3.4 does not properly escape recorded User-Agents in the user activity logs dashboard, which may allow visitors to conduct Stored Cross-Site Scripting attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-wxww-3fw5-44w4/GHSA-wxww-3fw5-44w4.json b/advisories/unreviewed/2023/10/GHSA-wxww-3fw5-44w4/GHSA-wxww-3fw5-44w4.json index 05749bde5cd..1ab428f6eda 100644 --- a/advisories/unreviewed/2023/10/GHSA-wxww-3fw5-44w4/GHSA-wxww-3fw5-44w4.json +++ b/advisories/unreviewed/2023/10/GHSA-wxww-3fw5-44w4/GHSA-wxww-3fw5-44w4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wxww-3fw5-44w4", - "modified": "2023-10-13T12:30:17Z", + "modified": "2023-10-20T21:31:00Z", "published": "2023-10-13T12:30:17Z", "aliases": [ "CVE-2023-43079" diff --git a/advisories/unreviewed/2023/10/GHSA-x7w6-3cp2-qjcv/GHSA-x7w6-3cp2-qjcv.json b/advisories/unreviewed/2023/10/GHSA-x7w6-3cp2-qjcv/GHSA-x7w6-3cp2-qjcv.json index fa798e2975e..ae3bced04c3 100644 --- a/advisories/unreviewed/2023/10/GHSA-x7w6-3cp2-qjcv/GHSA-x7w6-3cp2-qjcv.json +++ b/advisories/unreviewed/2023/10/GHSA-x7w6-3cp2-qjcv/GHSA-x7w6-3cp2-qjcv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x7w6-3cp2-qjcv", - "modified": "2023-10-16T21:30:27Z", + "modified": "2023-10-20T21:31:00Z", "published": "2023-10-16T21:30:27Z", "aliases": [ "CVE-2023-5561" ], "details": "The Popup Builder WordPress plugin through 4.1.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-xhr4-fjfq-6r46/GHSA-xhr4-fjfq-6r46.json b/advisories/unreviewed/2023/10/GHSA-xhr4-fjfq-6r46/GHSA-xhr4-fjfq-6r46.json index 03ca821074c..69481d14823 100644 --- a/advisories/unreviewed/2023/10/GHSA-xhr4-fjfq-6r46/GHSA-xhr4-fjfq-6r46.json +++ b/advisories/unreviewed/2023/10/GHSA-xhr4-fjfq-6r46/GHSA-xhr4-fjfq-6r46.json @@ -40,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false,