diff --git a/advisories/unreviewed/2023/10/GHSA-2x4w-j73f-g9qq/GHSA-2x4w-j73f-g9qq.json b/advisories/unreviewed/2023/10/GHSA-2x4w-j73f-g9qq/GHSA-2x4w-j73f-g9qq.json new file mode 100644 index 00000000000..0757927a274 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-2x4w-j73f-g9qq/GHSA-2x4w-j73f-g9qq.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2x4w-j73f-g9qq", + "modified": "2023-10-27T18:30:24Z", + "published": "2023-10-27T18:30:24Z", + "aliases": [ + "CVE-2023-5826" + ], + "details": "A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/list_onlineuser.php. The manipulation of the argument SessionId leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243716. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5826" + }, + { + "type": "WEB", + "url": "https://github.com/Cubi123123123/cve/blob/main/NS-ASG-sql-list_onlineuser.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.243716" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.243716" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-8qqf-9w4f-fp2m/GHSA-8qqf-9w4f-fp2m.json b/advisories/unreviewed/2023/10/GHSA-8qqf-9w4f-fp2m/GHSA-8qqf-9w4f-fp2m.json index a613483e440..033e3e2711c 100644 --- a/advisories/unreviewed/2023/10/GHSA-8qqf-9w4f-fp2m/GHSA-8qqf-9w4f-fp2m.json +++ b/advisories/unreviewed/2023/10/GHSA-8qqf-9w4f-fp2m/GHSA-8qqf-9w4f-fp2m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8qqf-9w4f-fp2m", - "modified": "2023-10-20T09:30:27Z", + "modified": "2023-10-27T18:30:24Z", "published": "2023-10-20T09:30:27Z", "aliases": [ "CVE-2023-4274" diff --git a/advisories/unreviewed/2023/10/GHSA-96rf-64j2-34rj/GHSA-96rf-64j2-34rj.json b/advisories/unreviewed/2023/10/GHSA-96rf-64j2-34rj/GHSA-96rf-64j2-34rj.json index fd9969919c9..9554a37baf6 100644 --- a/advisories/unreviewed/2023/10/GHSA-96rf-64j2-34rj/GHSA-96rf-64j2-34rj.json +++ b/advisories/unreviewed/2023/10/GHSA-96rf-64j2-34rj/GHSA-96rf-64j2-34rj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-96rf-64j2-34rj", - "modified": "2023-10-20T09:30:27Z", + "modified": "2023-10-27T18:30:24Z", "published": "2023-10-20T09:30:27Z", "aliases": [ "CVE-2023-4488" @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-829", "CWE-98" ], "severity": null, diff --git a/advisories/unreviewed/2023/10/GHSA-m923-pj5j-h9qp/GHSA-m923-pj5j-h9qp.json b/advisories/unreviewed/2023/10/GHSA-m923-pj5j-h9qp/GHSA-m923-pj5j-h9qp.json new file mode 100644 index 00000000000..4bf50f96484 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-m923-pj5j-h9qp/GHSA-m923-pj5j-h9qp.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m923-pj5j-h9qp", + "modified": "2023-10-27T18:30:24Z", + "published": "2023-10-27T18:30:24Z", + "aliases": [ + "CVE-2023-5827" + ], + "details": "A vulnerability was found in Shanghai CTI Navigation CTI Monitoring and Early Warning System 2.2. It has been classified as critical. This affects an unknown part of the file /Web/SysManage/UserEdit.aspx. The manipulation of the argument ID leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-243717 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5827" + }, + { + "type": "WEB", + "url": "https://github.com/Ox1dq/cve/blob/main/rce.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.243717" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.243717" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file