diff --git a/advisories/unreviewed/2024/05/GHSA-4xwg-j5w5-pj88/GHSA-4xwg-j5w5-pj88.json b/advisories/unreviewed/2024/05/GHSA-4xwg-j5w5-pj88/GHSA-4xwg-j5w5-pj88.json new file mode 100644 index 00000000000..2d803e9870a --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-4xwg-j5w5-pj88/GHSA-4xwg-j5w5-pj88.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xwg-j5w5-pj88", + "modified": "2024-05-22T06:30:38Z", + "published": "2024-05-22T06:30:38Z", + "aliases": [ + "CVE-2024-3066" + ], + "details": "The Elegant Addons for elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping on user supplied tag attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3066" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/elegant-addons-for-elementor" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/affa8b39-94b8-474d-9310-a93ebdb7c1b8?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T06:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-593h-749q-pv4x/GHSA-593h-749q-pv4x.json b/advisories/unreviewed/2024/05/GHSA-593h-749q-pv4x/GHSA-593h-749q-pv4x.json new file mode 100644 index 00000000000..9ed7512979a --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-593h-749q-pv4x/GHSA-593h-749q-pv4x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-593h-749q-pv4x", + "modified": "2024-05-22T06:30:39Z", + "published": "2024-05-22T06:30:39Z", + "aliases": [ + "CVE-2024-3611" + ], + "details": "The Toolbar Extras for Elementor & More – WordPress Admin Bar Enhanced plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tbex-version' shortcode in all versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3611" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/toolbar-extras/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/50631f6c-de8b-408e-ab1f-ef74d3180e7f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T06:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-5p7q-vjp4-vcrg/GHSA-5p7q-vjp4-vcrg.json b/advisories/unreviewed/2024/05/GHSA-5p7q-vjp4-vcrg/GHSA-5p7q-vjp4-vcrg.json new file mode 100644 index 00000000000..334a5998c2f --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-5p7q-vjp4-vcrg/GHSA-5p7q-vjp4-vcrg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5p7q-vjp4-vcrg", + "modified": "2024-05-22T06:30:38Z", + "published": "2024-05-22T06:30:38Z", + "aliases": [ + "CVE-2024-30420" + ], + "details": "Server-side request forgery (SSRF) vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If this vulnerability is exploited, a user with an administrator or higher privilege who can log in to the product may obtain arbitrary files on the server and information on the internal server that is not disclosed to the public.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30420" + }, + { + "type": "WEB", + "url": "https://developer.a-blogcms.jp/blog/news/JVN-70977403.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN70977403" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T05:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-5qvg-g2v8-cghm/GHSA-5qvg-g2v8-cghm.json b/advisories/unreviewed/2024/05/GHSA-5qvg-g2v8-cghm/GHSA-5qvg-g2v8-cghm.json new file mode 100644 index 00000000000..b57de917e20 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-5qvg-g2v8-cghm/GHSA-5qvg-g2v8-cghm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qvg-g2v8-cghm", + "modified": "2024-05-22T06:30:38Z", + "published": "2024-05-22T06:30:38Z", + "aliases": [ + "CVE-2024-35162" + ], + "details": "Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulnerability is exploited, a remote authenticated attacker with \"switch_themes\" privilege may obtain arbitrary files on the server.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35162" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN85380030" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/download-plugins-dashboard" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T06:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-9ggc-jprr-xmm8/GHSA-9ggc-jprr-xmm8.json b/advisories/unreviewed/2024/05/GHSA-9ggc-jprr-xmm8/GHSA-9ggc-jprr-xmm8.json new file mode 100644 index 00000000000..2efb0de33a9 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-9ggc-jprr-xmm8/GHSA-9ggc-jprr-xmm8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9ggc-jprr-xmm8", + "modified": "2024-05-22T06:30:39Z", + "published": "2024-05-22T06:30:39Z", + "aliases": [ + "CVE-2024-4971" + ], + "details": "The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.2.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4971" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/learnpress/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/10b08a05-3561-4d05-985b-6a2339a547a7?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T06:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-chxf-xv64-xxfr/GHSA-chxf-xv64-xxfr.json b/advisories/unreviewed/2024/05/GHSA-chxf-xv64-xxfr/GHSA-chxf-xv64-xxfr.json new file mode 100644 index 00000000000..082c165e689 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-chxf-xv64-xxfr/GHSA-chxf-xv64-xxfr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chxf-xv64-xxfr", + "modified": "2024-05-22T06:30:38Z", + "published": "2024-05-22T06:30:38Z", + "aliases": [ + "CVE-2024-31396" + ], + "details": "Code injection vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If this vulnerability is exploited, a user with an administrator or higher privilege who can log in to the product may execute an arbitrary command on the server.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31396" + }, + { + "type": "WEB", + "url": "https://developer.a-blogcms.jp/blog/news/JVN-70977403.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN70977403" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T05:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-cwwf-74gf-jf68/GHSA-cwwf-74gf-jf68.json b/advisories/unreviewed/2024/05/GHSA-cwwf-74gf-jf68/GHSA-cwwf-74gf-jf68.json new file mode 100644 index 00000000000..effa5289950 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-cwwf-74gf-jf68/GHSA-cwwf-74gf-jf68.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwwf-74gf-jf68", + "modified": "2024-05-22T06:30:38Z", + "published": "2024-05-22T06:30:38Z", + "aliases": [ + "CVE-2024-0452" + ], + "details": "The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_upload_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files to a linked OpenAI account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0452" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/chatbot/trunk/includes/openai/qcld-bot-openai.php#L208" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3089461/chatbot/trunk/includes/openai/qcld-bot-openai.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/34b6475c-b5dd-42a1-98d1-9b5ae9ff4ad5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T04:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-fgj9-c4qh-7wrf/GHSA-fgj9-c4qh-7wrf.json b/advisories/unreviewed/2024/05/GHSA-fgj9-c4qh-7wrf/GHSA-fgj9-c4qh-7wrf.json new file mode 100644 index 00000000000..6dcc800ef3f --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-fgj9-c4qh-7wrf/GHSA-fgj9-c4qh-7wrf.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgj9-c4qh-7wrf", + "modified": "2024-05-22T06:30:39Z", + "published": "2024-05-22T06:30:39Z", + "aliases": [ + "CVE-2024-5092" + ], + "details": "The Elegant Addons for elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Switcher, Slider, and Iconbox widgets in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5092" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elegant-addons-for-elementor/trunk/widgets/eae-iconbox.php#L1667" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elegant-addons-for-elementor/trunk/widgets/eae-slider.php#L1091" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elegant-addons-for-elementor/trunk/widgets/eae-switcher.php#L516" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7ab3e286-05db-430e-bbe7-bfaa31134c3c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T06:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-h8rv-v4gm-prcg/GHSA-h8rv-v4gm-prcg.json b/advisories/unreviewed/2024/05/GHSA-h8rv-v4gm-prcg/GHSA-h8rv-v4gm-prcg.json new file mode 100644 index 00000000000..0a2f076ced7 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-h8rv-v4gm-prcg/GHSA-h8rv-v4gm-prcg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8rv-v4gm-prcg", + "modified": "2024-05-22T06:30:38Z", + "published": "2024-05-22T06:30:38Z", + "aliases": [ + "CVE-2024-30419" + ], + "details": "Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions prior to Ver.2.11.61, Ver.2.10.x series versions prior to Ver.2.10.53, and Ver.2.9 and earlier versions. If this vulnerability is exploited, a user with a contributor or higher privilege who can log in to the product may execute an arbitrary script on the web browser of the user who accessed the website using the product.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30419" + }, + { + "type": "WEB", + "url": "https://developer.a-blogcms.jp/blog/news/JVN-70977403.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN70977403" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T05:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-h93v-cpw2-8m3x/GHSA-h93v-cpw2-8m3x.json b/advisories/unreviewed/2024/05/GHSA-h93v-cpw2-8m3x/GHSA-h93v-cpw2-8m3x.json new file mode 100644 index 00000000000..9e3561f58d8 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-h93v-cpw2-8m3x/GHSA-h93v-cpw2-8m3x.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h93v-cpw2-8m3x", + "modified": "2024-05-22T06:30:38Z", + "published": "2024-05-22T06:30:38Z", + "aliases": [ + "CVE-2024-0453" + ], + "details": "The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_delete_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete files from a linked OpenAI account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0453" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/chatbot/trunk/includes/openai/qcld-bot-openai.php#L133" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3089461/chatbot/trunk/includes/openai/qcld-bot-openai.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7e0ef4a5-42d7-4cea-b19f-51917e3ee55f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T04:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-hpp5-56vf-wwqg/GHSA-hpp5-56vf-wwqg.json b/advisories/unreviewed/2024/05/GHSA-hpp5-56vf-wwqg/GHSA-hpp5-56vf-wwqg.json new file mode 100644 index 00000000000..caf388deb35 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-hpp5-56vf-wwqg/GHSA-hpp5-56vf-wwqg.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpp5-56vf-wwqg", + "modified": "2024-05-22T06:30:38Z", + "published": "2024-05-22T06:30:38Z", + "aliases": [ + "CVE-2024-31340" + ], + "details": "TP-Link Tether versions prior to 4.5.13 and TP-Link Tapo versions prior to 3.3.6 do not properly validate certificates, which may allow a remote unauthenticated attacker to eavesdrop on an encrypted communication via a man-in-the-middle attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31340" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN29471697" + }, + { + "type": "WEB", + "url": "https://play.google.com/store/apps/details?id=com.tplink.iot" + }, + { + "type": "WEB", + "url": "https://play.google.com/store/apps/details?id=com.tplink.tether" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T06:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-j37f-whq4-vg6v/GHSA-j37f-whq4-vg6v.json b/advisories/unreviewed/2024/05/GHSA-j37f-whq4-vg6v/GHSA-j37f-whq4-vg6v.json new file mode 100644 index 00000000000..60f175a329e --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-j37f-whq4-vg6v/GHSA-j37f-whq4-vg6v.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j37f-whq4-vg6v", + "modified": "2024-05-22T06:30:39Z", + "published": "2024-05-22T06:30:39Z", + "aliases": [ + "CVE-2024-4443" + ], + "details": "The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4443" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/business-directory-plugin/trunk/includes/fields/class-fieldtypes-select.php#L110" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3089626" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/982fb304-08d6-4195-97a3-f18e94295492?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T06:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-p689-3c5j-vchp/GHSA-p689-3c5j-vchp.json b/advisories/unreviewed/2024/05/GHSA-p689-3c5j-vchp/GHSA-p689-3c5j-vchp.json new file mode 100644 index 00000000000..3bf767aa044 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-p689-3c5j-vchp/GHSA-p689-3c5j-vchp.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p689-3c5j-vchp", + "modified": "2024-05-22T06:30:38Z", + "published": "2024-05-22T06:30:38Z", + "aliases": [ + "CVE-2024-0451" + ], + "details": "The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the openai_file_list_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to list files existing in a linked OpenAI account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0451" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/chatbot/trunk/includes/openai/qcld-bot-openai.php#L175" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3089461/chatbot/trunk/includes/openai/qcld-bot-openai.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1c0572a5-6cc9-43ab-a4a3-c8d3b93c8fcf?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T04:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-r6m4-7j2j-qxx2/GHSA-r6m4-7j2j-qxx2.json b/advisories/unreviewed/2024/05/GHSA-r6m4-7j2j-qxx2/GHSA-r6m4-7j2j-qxx2.json new file mode 100644 index 00000000000..babecc8d135 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-r6m4-7j2j-qxx2/GHSA-r6m4-7j2j-qxx2.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6m4-7j2j-qxx2", + "modified": "2024-05-22T06:30:38Z", + "published": "2024-05-22T06:30:38Z", + "aliases": [ + "CVE-2024-4980" + ], + "details": "The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id', 'mixColor', 'backgroundColor', 'saveInCookies', and 'autoMatchOsTheme' parameters in all versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4980" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wpkoi-templates-for-elementor/trunk/elements/elements/advanced-heading/advanced-heading.php#L626" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wpkoi-templates-for-elementor/trunk/elements/elements/darkmode/darkmode.php#L291" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wpkoi-templates-for-elementor/trunk/elements/elements/qr-code/qr-code.php#L110" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3088306" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6054a885-e67a-4731-93ea-64d7f90d9ea8?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T05:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-r868-7jmm-2qf4/GHSA-r868-7jmm-2qf4.json b/advisories/unreviewed/2024/05/GHSA-r868-7jmm-2qf4/GHSA-r868-7jmm-2qf4.json new file mode 100644 index 00000000000..5f62fe69c44 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-r868-7jmm-2qf4/GHSA-r868-7jmm-2qf4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r868-7jmm-2qf4", + "modified": "2024-05-22T06:30:38Z", + "published": "2024-05-22T06:30:38Z", + "aliases": [ + "CVE-2024-31394" + ], + "details": "Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions prior to Ver.2.11.61, Ver.2.10.x series versions prior to Ver.2.10.53, and Ver.2.9 and earlier versions. If this vulnerability is exploited, a user with an editor or higher privilege who can log in to the product may obtain arbitrary files on the server.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31394" + }, + { + "type": "WEB", + "url": "https://developer.a-blogcms.jp/blog/news/JVN-70977403.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN70977403" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T05:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-vh8v-4rwj-rmrh/GHSA-vh8v-4rwj-rmrh.json b/advisories/unreviewed/2024/05/GHSA-vh8v-4rwj-rmrh/GHSA-vh8v-4rwj-rmrh.json new file mode 100644 index 00000000000..dd4c3dfb165 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-vh8v-4rwj-rmrh/GHSA-vh8v-4rwj-rmrh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh8v-4rwj-rmrh", + "modified": "2024-05-22T06:30:38Z", + "published": "2024-05-22T06:30:38Z", + "aliases": [ + "CVE-2024-31395" + ], + "details": "Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions prior to Ver.2.11.61, Ver.2.10.x series versions prior to Ver.2.10.53, and Ver.2.9 and earlier versions. If this vulnerability is exploited, a user with an editor or higher privilege who can log in to the product may execute an arbitrary script on the web browser of the user who accessed the schedule management page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31395" + }, + { + "type": "WEB", + "url": "https://developer.a-blogcms.jp/blog/news/JVN-70977403.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN70977403" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T05:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-vjf7-9xrv-fjrq/GHSA-vjf7-9xrv-fjrq.json b/advisories/unreviewed/2024/05/GHSA-vjf7-9xrv-fjrq/GHSA-vjf7-9xrv-fjrq.json new file mode 100644 index 00000000000..fabafef0e2c --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-vjf7-9xrv-fjrq/GHSA-vjf7-9xrv-fjrq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjf7-9xrv-fjrq", + "modified": "2024-05-22T06:30:38Z", + "published": "2024-05-22T06:30:38Z", + "aliases": [ + "CVE-2020-35165" + ], + "details": "Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35165" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000181115/dsa-2020-286-dell-bsafe-crypto-c-micro-edition-4-1-5-and-dell-bsafe-micro-edition-suite-4-6-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-208" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T06:15:09Z" + } +} \ No newline at end of file