From 3b7aa6c50b7e6d272ed22871d7ff50171200e513 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sun, 27 Oct 2024 06:32:09 +0000 Subject: [PATCH] Publish Advisories GHSA-q7m5-4xhc-7xfr GHSA-4j2f-5w52-j8cj GHSA-v7v6-3chw-vv8j GHSA-6gp9-jm2x-w6c4 GHSA-3xwr-f848-5v5p GHSA-79wf-qgrg-2p6c GHSA-vhqp-wh25-fv36 --- .../GHSA-q7m5-4xhc-7xfr.json | 11 ++-- .../GHSA-4j2f-5w52-j8cj.json | 9 ++- .../GHSA-v7v6-3chw-vv8j.json | 11 ++-- .../GHSA-6gp9-jm2x-w6c4.json | 11 ++-- .../GHSA-3xwr-f848-5v5p.json | 58 +++++++++++++++++++ .../GHSA-79wf-qgrg-2p6c.json | 35 +++++++++++ .../GHSA-vhqp-wh25-fv36.json | 58 +++++++++++++++++++ 7 files changed, 178 insertions(+), 15 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-3xwr-f848-5v5p/GHSA-3xwr-f848-5v5p.json create mode 100644 advisories/unreviewed/2024/10/GHSA-79wf-qgrg-2p6c/GHSA-79wf-qgrg-2p6c.json create mode 100644 advisories/unreviewed/2024/10/GHSA-vhqp-wh25-fv36/GHSA-vhqp-wh25-fv36.json diff --git a/advisories/unreviewed/2024/03/GHSA-q7m5-4xhc-7xfr/GHSA-q7m5-4xhc-7xfr.json b/advisories/unreviewed/2024/03/GHSA-q7m5-4xhc-7xfr/GHSA-q7m5-4xhc-7xfr.json index d84f9bf28c6..378c290b489 100644 --- a/advisories/unreviewed/2024/03/GHSA-q7m5-4xhc-7xfr/GHSA-q7m5-4xhc-7xfr.json +++ b/advisories/unreviewed/2024/03/GHSA-q7m5-4xhc-7xfr/GHSA-q7m5-4xhc-7xfr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q7m5-4xhc-7xfr", - "modified": "2024-03-25T06:30:24Z", + "modified": "2024-10-27T06:30:46Z", "published": "2024-03-25T06:30:24Z", "aliases": [ "CVE-2024-21865" ], "details": "HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may connect to the product via SSH and use a shell.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-521" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T05:15:50Z" diff --git a/advisories/unreviewed/2024/04/GHSA-4j2f-5w52-j8cj/GHSA-4j2f-5w52-j8cj.json b/advisories/unreviewed/2024/04/GHSA-4j2f-5w52-j8cj/GHSA-4j2f-5w52-j8cj.json index e1dc88b8c58..d558b410343 100644 --- a/advisories/unreviewed/2024/04/GHSA-4j2f-5w52-j8cj/GHSA-4j2f-5w52-j8cj.json +++ b/advisories/unreviewed/2024/04/GHSA-4j2f-5w52-j8cj/GHSA-4j2f-5w52-j8cj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4j2f-5w52-j8cj", - "modified": "2024-04-15T12:30:34Z", + "modified": "2024-10-27T06:30:46Z", "published": "2024-04-15T12:30:34Z", "aliases": [ "CVE-2024-30219" ], "details": "Active debug code vulnerability exists in MZK-MF300N all firmware versions. If a logged-in user who knows how to use the debug function accesses the device's management page, an unintended operation may be performed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T11:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-v7v6-3chw-vv8j/GHSA-v7v6-3chw-vv8j.json b/advisories/unreviewed/2024/04/GHSA-v7v6-3chw-vv8j/GHSA-v7v6-3chw-vv8j.json index 2c6ed351e33..4bf62afebf4 100644 --- a/advisories/unreviewed/2024/04/GHSA-v7v6-3chw-vv8j/GHSA-v7v6-3chw-vv8j.json +++ b/advisories/unreviewed/2024/04/GHSA-v7v6-3chw-vv8j/GHSA-v7v6-3chw-vv8j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v7v6-3chw-vv8j", - "modified": "2024-04-11T06:30:35Z", + "modified": "2024-10-27T06:30:46Z", "published": "2024-04-11T06:30:35Z", "aliases": [ "CVE-2024-30879" ], "details": "Reflected Cross Site Scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensitive information via a crafted payload injected into the boxId parameter in the image cropping function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-11T05:15:47Z" diff --git a/advisories/unreviewed/2024/05/GHSA-6gp9-jm2x-w6c4/GHSA-6gp9-jm2x-w6c4.json b/advisories/unreviewed/2024/05/GHSA-6gp9-jm2x-w6c4/GHSA-6gp9-jm2x-w6c4.json index 98673c35ce5..ee073a41f11 100644 --- a/advisories/unreviewed/2024/05/GHSA-6gp9-jm2x-w6c4/GHSA-6gp9-jm2x-w6c4.json +++ b/advisories/unreviewed/2024/05/GHSA-6gp9-jm2x-w6c4/GHSA-6gp9-jm2x-w6c4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6gp9-jm2x-w6c4", - "modified": "2024-05-14T18:30:49Z", + "modified": "2024-10-27T06:30:46Z", "published": "2024-05-14T18:30:49Z", "aliases": [ "CVE-2024-34245" ], "details": "An arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by specifying any path in makehtml_js_action.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:37Z" diff --git a/advisories/unreviewed/2024/10/GHSA-3xwr-f848-5v5p/GHSA-3xwr-f848-5v5p.json b/advisories/unreviewed/2024/10/GHSA-3xwr-f848-5v5p/GHSA-3xwr-f848-5v5p.json new file mode 100644 index 00000000000..c38392a7291 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3xwr-f848-5v5p/GHSA-3xwr-f848-5v5p.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xwr-f848-5v5p", + "modified": "2024-10-27T06:30:46Z", + "published": "2024-10-27T06:30:46Z", + "aliases": [ + "CVE-2024-10410" + ], + "details": "A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. Affected by this vulnerability is the function upload of the file /admin/mod_room/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10410" + }, + { + "type": "WEB", + "url": "https://github.com/K1nako0/tmp_vuln9/blob/main/README.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.281953" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.281953" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.431502" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-27T04:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-79wf-qgrg-2p6c/GHSA-79wf-qgrg-2p6c.json b/advisories/unreviewed/2024/10/GHSA-79wf-qgrg-2p6c/GHSA-79wf-qgrg-2p6c.json new file mode 100644 index 00000000000..435fe2a10d3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-79wf-qgrg-2p6c/GHSA-79wf-qgrg-2p6c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79wf-qgrg-2p6c", + "modified": "2024-10-27T06:30:47Z", + "published": "2024-10-27T06:30:47Z", + "aliases": [ + "CVE-2024-50602" + ], + "details": "An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50602" + }, + { + "type": "WEB", + "url": "https://github.com/libexpat/libexpat/pull/915" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-27T05:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vhqp-wh25-fv36/GHSA-vhqp-wh25-fv36.json b/advisories/unreviewed/2024/10/GHSA-vhqp-wh25-fv36/GHSA-vhqp-wh25-fv36.json new file mode 100644 index 00000000000..8a4478e2921 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vhqp-wh25-fv36/GHSA-vhqp-wh25-fv36.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhqp-wh25-fv36", + "modified": "2024-10-27T06:30:47Z", + "published": "2024-10-27T06:30:47Z", + "aliases": [ + "CVE-2024-10411" + ], + "details": "A vulnerability was found in SourceCodester Online Hotel Reservation System 1.0. It has been classified as critical. Affected is the function doCancelRoom/doCancel/doConfirm/doCancel/doCheckin/doCheckout of the file /marimar/admin/mod_room/controller.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10411" + }, + { + "type": "WEB", + "url": "https://github.com/K1nako0/tmp_vuln10/blob/main/README.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.281940" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.281940" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.431586" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-27T05:15:02Z" + } +} \ No newline at end of file