Publish Advisories

GHSA-2g58-2r94-f674
GHSA-8235-8498-xmmj
GHSA-8v62-x5cp-8hx4
GHSA-97c4-2w4v-c7r8
GHSA-9xxq-vvgh-v3r9
GHSA-gfw8-mh94-9w58
GHSA-hmw7-rcmw-2wqj
GHSA-m695-893g-ffg2
GHSA-qpfv-2pqx-cqjq
GHSA-v3r3-642v-rqj8
GHSA-w2gr-9pwc-5pm2
GHSA-xv2w-3fww-7hvf
This commit is contained in:
advisory-database[bot]
2024-07-31 12:33:53 +00:00
parent dd6c577b78
commit 46c694387b
12 changed files with 391 additions and 5 deletions
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2g58-2r94-f674",
"modified": "2024-07-31T12:31:48Z",
"published": "2024-07-31T12:31:48Z",
"aliases": [
"CVE-2024-7321"
],
"details": "A vulnerability classified as problematic was found in itsourcecode Online Blood Bank Management System 1.0. This vulnerability affects unknown code of the file signup.php of the component User Registration Handler. The manipulation of the argument user leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273232.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7321"
},
{
"type": "WEB",
"url": "https://github.com/cl4irv0yance/CVEs/issues/4"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.273232"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.273232"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.383437"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-31T12:15:02Z"
}
}
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8235-8498-xmmj",
"modified": "2024-07-31T12:31:47Z",
"published": "2024-07-31T12:31:47Z",
"aliases": [
"CVE-2024-7310"
],
"details": "A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file sort_user.php. The manipulation of the argument sort leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273202 is the identifier assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7310"
},
{
"type": "WEB",
"url": "https://github.com/zw-a11y/VUL/blob/main/Record-Management-System-2.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.273202"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.273202"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.382507"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-31T10:15:03Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8v62-x5cp-8hx4",
"modified": "2024-07-31T12:31:48Z",
"published": "2024-07-31T12:31:48Z",
"aliases": [
"CVE-2024-7135"
],
"details": "The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions up to, and including, 0.21.7. The function is also vulnerable to directory traversal. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7135"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/tainacan/trunk/classes/api/endpoints/class-tainacan-rest-background-processes-controller.php#L370"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/tainacan/trunk/classes/api/endpoints/class-tainacan-rest-background-processes-controller.php#L378"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3127693"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e4dd0c6a-75af-4b53-ac13-fc4ef0e9001d?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-31T11:15:11Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-97c4-2w4v-c7r8",
"modified": "2024-07-31T09:30:49Z",
"modified": "2024-07-31T12:31:47Z",
"published": "2024-07-31T09:30:49Z",
"aliases": [
"CVE-2024-7264"
@@ -29,6 +29,10 @@
{
"type": "WEB",
"url": "https://curl.se/docs/CVE-2024-7264.json"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/07/31/1"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9xxq-vvgh-v3r9",
"modified": "2024-07-23T18:31:07Z",
"modified": "2024-07-31T12:31:47Z",
"published": "2024-07-23T15:31:09Z",
"aliases": [
"CVE-2024-1737"
@@ -32,6 +32,10 @@
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/07/23/1"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/07/31/2"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gfw8-mh94-9w58",
"modified": "2024-07-23T18:31:07Z",
"modified": "2024-07-31T12:31:47Z",
"published": "2024-07-23T15:31:09Z",
"aliases": [
"CVE-2024-4076"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/07/23/1"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/07/31/2"
}
],
"database_specific": {
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hmw7-rcmw-2wqj",
"modified": "2024-07-31T12:31:47Z",
"published": "2024-07-31T12:31:47Z",
"aliases": [
"CVE-2024-7309"
],
"details": "A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as problematic. This affects an unknown part of the file entry.php. The manipulation of the argument school leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273201 was assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7309"
},
{
"type": "WEB",
"url": "https://github.com/zw-a11y/VUL/blob/main/Record-Management-System-1.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.273201"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.273201"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.382506"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-31T10:15:02Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m695-893g-ffg2",
"modified": "2024-07-31T12:31:47Z",
"published": "2024-07-31T12:31:47Z",
"aliases": [
"CVE-2024-6725"
],
"details": "The Formidable Forms Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the html parameter in all versions up to, and including, 6.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with form editing permissions and Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6725"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/formidable/trunk/classes/models/fields/FrmFieldType.php#L875"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3128202"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/848cfa72-4211-4576-91c2-4f643e3161c3?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-31T11:15:10Z"
}
}
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qpfv-2pqx-cqjq",
"modified": "2024-07-31T12:31:48Z",
"published": "2024-07-31T12:31:48Z",
"aliases": [
"CVE-2024-7311"
],
"details": "A vulnerability was found in code-projects Online Bus Reservation Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file register.php. The manipulation of the argument Email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273203.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7311"
},
{
"type": "WEB",
"url": "https://github.com/23588hk/cve/issues/1"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.273203"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.273203"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.383201"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-31T11:15:11Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v3r3-642v-rqj8",
"modified": "2024-07-23T18:31:07Z",
"modified": "2024-07-31T12:31:46Z",
"published": "2024-07-23T15:31:09Z",
"aliases": [
"CVE-2024-0760"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/07/23/1"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/07/31/2"
}
],
"database_specific": {
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w2gr-9pwc-5pm2",
"modified": "2024-07-31T12:31:48Z",
"published": "2024-07-31T12:31:48Z",
"aliases": [
"CVE-2024-7320"
],
"details": "A vulnerability classified as critical has been found in itsourcecode Online Blood Bank Management System 1.0. This affects an unknown part of the file /admin/index.php of the component Admin Login. The manipulation of the argument user leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273231.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7320"
},
{
"type": "WEB",
"url": "https://github.com/cl4irv0yance/CVEs/issues/3"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.273231"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.273231"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.383397"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-31T11:15:11Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xv2w-3fww-7hvf",
"modified": "2024-07-23T18:31:07Z",
"modified": "2024-07-31T12:31:47Z",
"published": "2024-07-23T15:31:09Z",
"aliases": [
"CVE-2024-1975"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/07/23/1"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/07/31/2"
}
],
"database_specific": {