Publish Advisories

GHSA-483f-wxw9-3rpq
GHSA-277w-qpxr-2549
GHSA-8h24-3cjr-xxmh
GHSA-mwxh-6j9v-45ph
GHSA-p9xp-xghp-gqvp
GHSA-483f-wxw9-3rpq
GHSA-277w-qpxr-2549
GHSA-8h24-3cjr-xxmh
This commit is contained in:
advisory-database[bot]
2024-04-25 21:40:33 +00:00
parent de8bc3117f
commit 479305e2fd
8 changed files with 350 additions and 156 deletions
@@ -0,0 +1,61 @@
{
"schema_version": "1.4.0",
"id": "GHSA-483f-wxw9-3rpq",
"modified": "2024-04-25T21:39:29Z",
"published": "2022-04-22T00:24:25Z",
"aliases": [
"CVE-2011-1150"
],
"summary": "bbPress Cross-site Scripting (XSS) vulnerability",
"details": "bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "bbpress/bbpress"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.0.2"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2011-1150"
},
{
"type": "PACKAGE",
"url": "https://github.com/bbpress/bbPress"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2011/03/14/20"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-04-25T21:39:29Z",
"nvd_published_at": "2020-02-05T22:15:00Z"
}
}
@@ -0,0 +1,155 @@
{
"schema_version": "1.4.0",
"id": "GHSA-277w-qpxr-2549",
"modified": "2024-04-25T21:38:55Z",
"published": "2022-05-17T03:35:09Z",
"aliases": [
"CVE-2016-4567"
],
"summary": "MediaElement Vulnerable to Reflected XSS ",
"details": "Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.swf in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by \"jsinitfunctio%gn.\"",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "mediaelement"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "2.11.1"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "contao-components/mediaelement"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.14.2"
},
{
"fixed": "2.21.1"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "contao/core"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.0.0"
},
{
"fixed": "3.5.15"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2016-4567"
},
{
"type": "WEB",
"url": "https://github.com/johndyer/mediaelement/commit/34834eef8ac830b9145df169ec22016a4350f06e"
},
{
"type": "WEB",
"url": "https://github.com/mediaelement/mediaelement/commit/34834eef8ac830b9145df169ec22016a4350f06e"
},
{
"type": "WEB",
"url": "https://codex.wordpress.org/Version_4.5.2"
},
{
"type": "WEB",
"url": "https://contao.org/en/news/contao-3_5_15.html"
},
{
"type": "WEB",
"url": "https://core.trac.wordpress.org/changeset/37371"
},
{
"type": "WEB",
"url": "https://gist.github.com/cure53/df34ea68c26441f3ae98f821ba1feb9c"
},
{
"type": "WEB",
"url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/contao-components/mediaelement/CVE-2016-4567.yaml"
},
{
"type": "WEB",
"url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core/CVE-2016-4567.yaml"
},
{
"type": "WEB",
"url": "https://github.com/johndyer/mediaelement/blob/master/changelog.md"
},
{
"type": "WEB",
"url": "https://github.com/mediaelement/mediaelement/blob/b992ccf5f0c04a207d98bbb0868420751a61ec90/changelog.md?plain=1#L1024"
},
{
"type": "WEB",
"url": "https://github.com/mediaelement/mediaelement/blob/master/changelog.md"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20170205142412/http://www.securitytracker.com/id/1035818"
},
{
"type": "WEB",
"url": "https://wordpress.org/news/2016/05/wordpress-4-5-2"
},
{
"type": "WEB",
"url": "https://wpvulndb.com/vulnerabilities/8488"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2016/05/07/2"
},
{
"type": "WEB",
"url": "http://www.securitytracker.com/id/1035818"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-04-25T21:38:55Z",
"nvd_published_at": "2016-05-22T01:59:00Z"
}
}
@@ -0,0 +1,69 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8h24-3cjr-xxmh",
"modified": "2024-04-25T21:40:11Z",
"published": "2022-05-14T01:31:07Z",
"aliases": [
"CVE-2018-16637"
],
"summary": "Evolution CMS Stored Cross-site Scripting (XSS) ",
"details": "Evolution CMS 1.4.x prior to 1.4.6 allows XSS via the page weblink title parameter to the manager/ URI.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "evolutioncms/evolution"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.4"
},
{
"fixed": "1.4.6"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-16637"
},
{
"type": "WEB",
"url": "https://github.com/evolution-cms/evolution/issues/788"
},
{
"type": "WEB",
"url": "https://github.com/evolution-cms/evolution/commit/2b8aaa6224997155de0fe9440ad106bd98dc4f4b"
},
{
"type": "PACKAGE",
"url": "https://github.com/evolution-cms/evolution"
},
{
"type": "WEB",
"url": "https://github.com/security-breachlock/CVE-2018-16637/blob/master/evolution_xss_stored.pdf"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-04-25T21:40:11Z",
"nvd_published_at": "2018-12-28T17:29:00Z"
}
}
@@ -1,17 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mwxh-6j9v-45ph",
"modified": "2022-05-24T17:18:50Z",
"modified": "2024-04-25T21:39:38Z",
"published": "2022-05-24T17:18:50Z",
"aliases": [
"CVE-2020-13693"
],
"summary": "bbPress unauthenticated privilege-escalation",
"details": "An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "bbpress/bbpress"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "2.6.5"
}
]
}
]
}
],
"references": [
{
@@ -26,6 +48,10 @@
"type": "WEB",
"url": "https://codex.bbpress.org/releases"
},
{
"type": "PACKAGE",
"url": "https://github.com/bbpress/bbPress"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/bbpress/#developers"
@@ -39,9 +65,9 @@
"cwe_ids": [
"CWE-269"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2024-04-25T21:39:38Z",
"nvd_published_at": "2020-05-29T00:15:00Z"
}
}
@@ -1,17 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p9xp-xghp-gqvp",
"modified": "2022-05-24T17:18:42Z",
"modified": "2024-04-25T21:39:32Z",
"published": "2022-05-24T17:18:42Z",
"aliases": [
"CVE-2020-13487"
],
"summary": "bbPress stored Cross-Site Scripting (XSS) vulnerability in the Forum creation section",
"details": "The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?post_type=forum (aka the Forum listing page) for all users. An administrator can exploit this at the wp-admin/post.php?action=edit URI.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "bbpress/bbpress"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.6.4"
}
]
}
]
}
],
"references": [
{
@@ -26,6 +48,10 @@
"type": "WEB",
"url": "https://codex.bbpress.org/releases"
},
{
"type": "PACKAGE",
"url": "https://github.com/bbpress/bbPress"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/bbpress/#developers"
@@ -37,11 +63,11 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-04-25T21:39:32Z",
"nvd_published_at": "2020-05-26T14:15:00Z"
}
}
@@ -1,35 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-483f-wxw9-3rpq",
"modified": "2022-04-22T00:24:25Z",
"published": "2022-04-22T00:24:25Z",
"aliases": [
"CVE-2011-1150"
],
"details": "bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2011-1150"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2011/03/14/20"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2020-02-05T22:15:00Z"
}
}
@@ -1,70 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-277w-qpxr-2549",
"modified": "2022-05-17T03:35:09Z",
"published": "2022-05-17T03:35:09Z",
"aliases": [
"CVE-2016-4567"
],
"details": "Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by \"jsinitfunctio%gn.\"",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2016-4567"
},
{
"type": "WEB",
"url": "https://github.com/johndyer/mediaelement/commit/34834eef8ac830b9145df169ec22016a4350f06e"
},
{
"type": "WEB",
"url": "https://codex.wordpress.org/Version_4.5.2"
},
{
"type": "WEB",
"url": "https://core.trac.wordpress.org/changeset/37371"
},
{
"type": "WEB",
"url": "https://gist.github.com/cure53/df34ea68c26441f3ae98f821ba1feb9c"
},
{
"type": "WEB",
"url": "https://github.com/johndyer/mediaelement/blob/master/changelog.md"
},
{
"type": "WEB",
"url": "https://wordpress.org/news/2016/05/wordpress-4-5-2"
},
{
"type": "WEB",
"url": "https://wpvulndb.com/vulnerabilities/8488"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2016/05/07/2"
},
{
"type": "WEB",
"url": "http://www.securitytracker.com/id/1035818"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2016-05-22T01:59:00Z"
}
}
@@ -1,38 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8h24-3cjr-xxmh",
"modified": "2022-05-14T01:31:07Z",
"published": "2022-05-14T01:31:07Z",
"aliases": [
"CVE-2018-16637"
],
"details": "Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-16637"
},
{
"type": "WEB",
"url": "https://github.com/security-breachlock/CVE-2018-16637/blob/master/evolution_xss_stored.pdf"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2018-12-28T17:29:00Z"
}
}