From 457880cd700677f792ada85d46b00db9c7785287 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 9 Mar 2024 09:31:59 +0000 Subject: [PATCH] Publish Advisories GHSA-4wf2-8qpc-j8cv GHSA-9mq3-jxwh-fh25 GHSA-c484-4w5f-vv73 GHSA-hhwv-mrvc-q6mv GHSA-qpg5-fc22-gh5w GHSA-r334-cg32-8chf GHSA-r382-478w-qwfw GHSA-r5r4-7hp9-q2xp GHSA-rgh8-xq22-272j --- .../GHSA-4wf2-8qpc-j8cv.json | 46 +++++++++++++++++++ .../GHSA-9mq3-jxwh-fh25.json | 42 +++++++++++++++++ .../GHSA-c484-4w5f-vv73.json | 39 ++++++++++++++++ .../GHSA-hhwv-mrvc-q6mv.json | 42 +++++++++++++++++ .../GHSA-qpg5-fc22-gh5w.json | 35 ++++++++++++++ .../GHSA-r334-cg32-8chf.json | 42 +++++++++++++++++ .../GHSA-r382-478w-qwfw.json | 42 +++++++++++++++++ .../GHSA-r5r4-7hp9-q2xp.json | 42 +++++++++++++++++ .../GHSA-rgh8-xq22-272j.json | 46 +++++++++++++++++++ 9 files changed, 376 insertions(+) create mode 100644 advisories/unreviewed/2024/03/GHSA-4wf2-8qpc-j8cv/GHSA-4wf2-8qpc-j8cv.json create mode 100644 advisories/unreviewed/2024/03/GHSA-9mq3-jxwh-fh25/GHSA-9mq3-jxwh-fh25.json create mode 100644 advisories/unreviewed/2024/03/GHSA-c484-4w5f-vv73/GHSA-c484-4w5f-vv73.json create mode 100644 advisories/unreviewed/2024/03/GHSA-hhwv-mrvc-q6mv/GHSA-hhwv-mrvc-q6mv.json create mode 100644 advisories/unreviewed/2024/03/GHSA-qpg5-fc22-gh5w/GHSA-qpg5-fc22-gh5w.json create mode 100644 advisories/unreviewed/2024/03/GHSA-r334-cg32-8chf/GHSA-r334-cg32-8chf.json create mode 100644 advisories/unreviewed/2024/03/GHSA-r382-478w-qwfw/GHSA-r382-478w-qwfw.json create mode 100644 advisories/unreviewed/2024/03/GHSA-r5r4-7hp9-q2xp/GHSA-r5r4-7hp9-q2xp.json create mode 100644 advisories/unreviewed/2024/03/GHSA-rgh8-xq22-272j/GHSA-rgh8-xq22-272j.json diff --git a/advisories/unreviewed/2024/03/GHSA-4wf2-8qpc-j8cv/GHSA-4wf2-8qpc-j8cv.json b/advisories/unreviewed/2024/03/GHSA-4wf2-8qpc-j8cv/GHSA-4wf2-8qpc-j8cv.json new file mode 100644 index 00000000000..179a4852345 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4wf2-8qpc-j8cv/GHSA-4wf2-8qpc-j8cv.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wf2-8qpc-j8cv", + "modified": "2024-03-09T09:30:42Z", + "published": "2024-03-09T09:30:42Z", + "aliases": [ + "CVE-2024-2330" + ], + "details": "A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This affects an unknown part of the file /protocol/index.php. The manipulation of the argument IPAddr leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256281 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2330" + }, + { + "type": "WEB", + "url": "https://github.com/jikedaodao/cve/blob/main/NS-ASG-sql-addmacbind.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.256281" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.256281" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-09T09:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9mq3-jxwh-fh25/GHSA-9mq3-jxwh-fh25.json b/advisories/unreviewed/2024/03/GHSA-9mq3-jxwh-fh25/GHSA-9mq3-jxwh-fh25.json new file mode 100644 index 00000000000..ca4b4273ae9 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9mq3-jxwh-fh25/GHSA-9mq3-jxwh-fh25.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mq3-jxwh-fh25", + "modified": "2024-03-09T09:30:42Z", + "published": "2024-03-09T09:30:42Z", + "aliases": [ + "CVE-2024-1767" + ], + "details": "The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 2.0.26 due to insufficient input sanitization and output escaping on user supplied attributes like 'className' and 'radius'. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1767" + }, + { + "type": "WEB", + "url": "https://themes.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=219324%40blocksy&new=219324%40blocksy&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/fdeab668-9094-485f-aa01-13ba5c10ea89?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-09T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-c484-4w5f-vv73/GHSA-c484-4w5f-vv73.json b/advisories/unreviewed/2024/03/GHSA-c484-4w5f-vv73/GHSA-c484-4w5f-vv73.json new file mode 100644 index 00000000000..5da16f1146d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-c484-4w5f-vv73/GHSA-c484-4w5f-vv73.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c484-4w5f-vv73", + "modified": "2024-03-09T09:30:41Z", + "published": "2024-03-09T09:30:41Z", + "aliases": [ + "CVE-2024-28089" + ], + "details": "Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity (who has access to the router admin panel) to conduct a DOM-based stored XSS attack that can fetch remote resources. The payload is executed at index.html#advanced_location (aka the Device Location page). This can cause a denial of service or lead to information disclosure.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28089" + }, + { + "type": "WEB", + "url": "https://drive.proton.me/urls/8RVTDGP9C0#GLVSkEMRYULI" + }, + { + "type": "WEB", + "url": "https://github.com/actuator/cve/blob/main/Hitron/CVE-2024-28089" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-09T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-hhwv-mrvc-q6mv/GHSA-hhwv-mrvc-q6mv.json b/advisories/unreviewed/2024/03/GHSA-hhwv-mrvc-q6mv/GHSA-hhwv-mrvc-q6mv.json new file mode 100644 index 00000000000..4f004f1eadf --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-hhwv-mrvc-q6mv/GHSA-hhwv-mrvc-q6mv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhwv-mrvc-q6mv", + "modified": "2024-03-09T09:30:41Z", + "published": "2024-03-09T09:30:41Z", + "aliases": [ + "CVE-2024-1124" + ], + "details": "The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the ep_send_attendees_email() function in all versions up to, and including, 3.4.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to send arbitrary emails with arbitrary content from the site.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1124" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3043888%40eventprime-event-calendar-management&new=3043888%40eventprime-event-calendar-management&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/346049ca-1bc5-4e02-9f38-d1f64338709d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-09T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qpg5-fc22-gh5w/GHSA-qpg5-fc22-gh5w.json b/advisories/unreviewed/2024/03/GHSA-qpg5-fc22-gh5w/GHSA-qpg5-fc22-gh5w.json new file mode 100644 index 00000000000..7f34ba4d301 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qpg5-fc22-gh5w/GHSA-qpg5-fc22-gh5w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpg5-fc22-gh5w", + "modified": "2024-03-09T09:30:42Z", + "published": "2024-03-09T09:30:42Z", + "aliases": [ + "CVE-2024-25501" + ], + "details": "An issue WinMail v.7.1 and v.5.1 and before allows a remote attacker to execute arbitrary code via a crafted script to the email parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25501" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Drun1baby/8270239bed2952dbd99cc8d4262728e8" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-09T08:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-r334-cg32-8chf/GHSA-r334-cg32-8chf.json b/advisories/unreviewed/2024/03/GHSA-r334-cg32-8chf/GHSA-r334-cg32-8chf.json new file mode 100644 index 00000000000..7e4974ba3a6 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-r334-cg32-8chf/GHSA-r334-cg32-8chf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r334-cg32-8chf", + "modified": "2024-03-09T09:30:42Z", + "published": "2024-03-09T09:30:42Z", + "aliases": [ + "CVE-2024-1320" + ], + "details": "The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'offline_status' parameter in all versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1320" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3043888%40eventprime-event-calendar-management&new=3043888%40eventprime-event-calendar-management&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7e82e1c5-0ed4-4dee-9990-976591693eb5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-09T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-r382-478w-qwfw/GHSA-r382-478w-qwfw.json b/advisories/unreviewed/2024/03/GHSA-r382-478w-qwfw/GHSA-r382-478w-qwfw.json new file mode 100644 index 00000000000..98ddd3b14f6 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-r382-478w-qwfw/GHSA-r382-478w-qwfw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r382-478w-qwfw", + "modified": "2024-03-09T09:30:41Z", + "published": "2024-03-09T09:30:41Z", + "aliases": [ + "CVE-2024-1123" + ], + "details": "The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_frontend_event_submission() function in all versions up to, and including, 3.4.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the title and content of arbitrary posts. This can also be exploited by unauthenticated attackers when the allow_submission_by_anonymous_user setting is enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1123" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3033882%40eventprime-event-calendar-management&new=3033882%40eventprime-event-calendar-management&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/351926d4-a9be-4fbd-bdf2-8bbff41d97ef?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-09T07:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-r5r4-7hp9-q2xp/GHSA-r5r4-7hp9-q2xp.json b/advisories/unreviewed/2024/03/GHSA-r5r4-7hp9-q2xp/GHSA-r5r4-7hp9-q2xp.json new file mode 100644 index 00000000000..be636a0f953 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-r5r4-7hp9-q2xp/GHSA-r5r4-7hp9-q2xp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5r4-7hp9-q2xp", + "modified": "2024-03-09T09:30:41Z", + "published": "2024-03-09T09:30:41Z", + "aliases": [ + "CVE-2024-1125" + ], + "details": "The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the calendar_events_delete() function in all versions up to, and including, 3.4.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary posts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1125" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3043888%40eventprime-event-calendar-management&new=3043888%40eventprime-event-calendar-management&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b5278afb-9db3-4b1d-bb2f-e6595f0ac6dc?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-09T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rgh8-xq22-272j/GHSA-rgh8-xq22-272j.json b/advisories/unreviewed/2024/03/GHSA-rgh8-xq22-272j/GHSA-rgh8-xq22-272j.json new file mode 100644 index 00000000000..ef87482f251 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rgh8-xq22-272j/GHSA-rgh8-xq22-272j.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgh8-xq22-272j", + "modified": "2024-03-09T09:30:42Z", + "published": "2024-03-09T09:30:42Z", + "aliases": [ + "CVE-2024-2329" + ], + "details": "A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/list_resource_icon.php?action=delete. The manipulation of the argument IconId leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-256280. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2329" + }, + { + "type": "WEB", + "url": "https://github.com/flyyue2001/cve/blob/main/NS-ASG-sql-list_resource_icon.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.256280" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.256280" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-09T08:15:06Z" + } +} \ No newline at end of file