diff --git a/advisories/github-reviewed/2022/04/GHSA-483f-wxw9-3rpq/GHSA-483f-wxw9-3rpq.json b/advisories/github-reviewed/2022/04/GHSA-483f-wxw9-3rpq/GHSA-483f-wxw9-3rpq.json new file mode 100644 index 00000000000..9efab7381a3 --- /dev/null +++ b/advisories/github-reviewed/2022/04/GHSA-483f-wxw9-3rpq/GHSA-483f-wxw9-3rpq.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-483f-wxw9-3rpq", + "modified": "2024-04-25T21:39:29Z", + "published": "2022-04-22T00:24:25Z", + "aliases": [ + "CVE-2011-1150" + ], + "summary": "bbPress Cross-site Scripting (XSS) vulnerability", + "details": "bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "bbpress/bbpress" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "1.0.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2011-1150" + }, + { + "type": "PACKAGE", + "url": "https://github.com/bbpress/bbPress" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2011/03/14/20" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-25T21:39:29Z", + "nvd_published_at": "2020-02-05T22:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-277w-qpxr-2549/GHSA-277w-qpxr-2549.json b/advisories/github-reviewed/2022/05/GHSA-277w-qpxr-2549/GHSA-277w-qpxr-2549.json new file mode 100644 index 00000000000..36998f9d6a3 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-277w-qpxr-2549/GHSA-277w-qpxr-2549.json @@ -0,0 +1,155 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-277w-qpxr-2549", + "modified": "2024-04-25T21:38:55Z", + "published": "2022-05-17T03:35:09Z", + "aliases": [ + "CVE-2016-4567" + ], + "summary": "MediaElement Vulnerable to Reflected XSS ", + "details": "Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.swf in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by \"jsinitfunctio%gn.\"", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "mediaelement" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.11.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "contao-components/mediaelement" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.14.2" + }, + { + "fixed": "2.21.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "contao/core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.0.0" + }, + { + "fixed": "3.5.15" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-4567" + }, + { + "type": "WEB", + "url": "https://github.com/johndyer/mediaelement/commit/34834eef8ac830b9145df169ec22016a4350f06e" + }, + { + "type": "WEB", + "url": "https://github.com/mediaelement/mediaelement/commit/34834eef8ac830b9145df169ec22016a4350f06e" + }, + { + "type": "WEB", + "url": "https://codex.wordpress.org/Version_4.5.2" + }, + { + "type": "WEB", + "url": "https://contao.org/en/news/contao-3_5_15.html" + }, + { + "type": "WEB", + "url": "https://core.trac.wordpress.org/changeset/37371" + }, + { + "type": "WEB", + "url": "https://gist.github.com/cure53/df34ea68c26441f3ae98f821ba1feb9c" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/contao-components/mediaelement/CVE-2016-4567.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core/CVE-2016-4567.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/johndyer/mediaelement/blob/master/changelog.md" + }, + { + "type": "WEB", + "url": "https://github.com/mediaelement/mediaelement/blob/b992ccf5f0c04a207d98bbb0868420751a61ec90/changelog.md?plain=1#L1024" + }, + { + "type": "WEB", + "url": "https://github.com/mediaelement/mediaelement/blob/master/changelog.md" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20170205142412/http://www.securitytracker.com/id/1035818" + }, + { + "type": "WEB", + "url": "https://wordpress.org/news/2016/05/wordpress-4-5-2" + }, + { + "type": "WEB", + "url": "https://wpvulndb.com/vulnerabilities/8488" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2016/05/07/2" + }, + { + "type": "WEB", + "url": "http://www.securitytracker.com/id/1035818" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-25T21:38:55Z", + "nvd_published_at": "2016-05-22T01:59:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-8h24-3cjr-xxmh/GHSA-8h24-3cjr-xxmh.json b/advisories/github-reviewed/2022/05/GHSA-8h24-3cjr-xxmh/GHSA-8h24-3cjr-xxmh.json new file mode 100644 index 00000000000..ba34627fe4b --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-8h24-3cjr-xxmh/GHSA-8h24-3cjr-xxmh.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h24-3cjr-xxmh", + "modified": "2024-04-25T21:40:11Z", + "published": "2022-05-14T01:31:07Z", + "aliases": [ + "CVE-2018-16637" + ], + "summary": "Evolution CMS Stored Cross-site Scripting (XSS) ", + "details": "Evolution CMS 1.4.x prior to 1.4.6 allows XSS via the page weblink title parameter to the manager/ URI.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "evolutioncms/evolution" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.4" + }, + { + "fixed": "1.4.6" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-16637" + }, + { + "type": "WEB", + "url": "https://github.com/evolution-cms/evolution/issues/788" + }, + { + "type": "WEB", + "url": "https://github.com/evolution-cms/evolution/commit/2b8aaa6224997155de0fe9440ad106bd98dc4f4b" + }, + { + "type": "PACKAGE", + "url": "https://github.com/evolution-cms/evolution" + }, + { + "type": "WEB", + "url": "https://github.com/security-breachlock/CVE-2018-16637/blob/master/evolution_xss_stored.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-25T21:40:11Z", + "nvd_published_at": "2018-12-28T17:29:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-mwxh-6j9v-45ph/GHSA-mwxh-6j9v-45ph.json b/advisories/github-reviewed/2022/05/GHSA-mwxh-6j9v-45ph/GHSA-mwxh-6j9v-45ph.json similarity index 57% rename from advisories/unreviewed/2022/05/GHSA-mwxh-6j9v-45ph/GHSA-mwxh-6j9v-45ph.json rename to advisories/github-reviewed/2022/05/GHSA-mwxh-6j9v-45ph/GHSA-mwxh-6j9v-45ph.json index c6b83254d2e..6f757068b01 100644 --- a/advisories/unreviewed/2022/05/GHSA-mwxh-6j9v-45ph/GHSA-mwxh-6j9v-45ph.json +++ b/advisories/github-reviewed/2022/05/GHSA-mwxh-6j9v-45ph/GHSA-mwxh-6j9v-45ph.json @@ -1,17 +1,39 @@ { "schema_version": "1.4.0", "id": "GHSA-mwxh-6j9v-45ph", - "modified": "2022-05-24T17:18:50Z", + "modified": "2024-04-25T21:39:38Z", "published": "2022-05-24T17:18:50Z", "aliases": [ "CVE-2020-13693" ], + "summary": "bbPress unauthenticated privilege-escalation", "details": "An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "bbpress/bbpress" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.6.5" + } + ] + } + ] + } ], "references": [ { @@ -26,6 +48,10 @@ "type": "WEB", "url": "https://codex.bbpress.org/releases" }, + { + "type": "PACKAGE", + "url": "https://github.com/bbpress/bbPress" + }, { "type": "WEB", "url": "https://wordpress.org/plugins/bbpress/#developers" @@ -39,9 +65,9 @@ "cwe_ids": [ "CWE-269" ], - "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-04-25T21:39:38Z", "nvd_published_at": "2020-05-29T00:15:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-p9xp-xghp-gqvp/GHSA-p9xp-xghp-gqvp.json b/advisories/github-reviewed/2022/05/GHSA-p9xp-xghp-gqvp/GHSA-p9xp-xghp-gqvp.json similarity index 56% rename from advisories/unreviewed/2022/05/GHSA-p9xp-xghp-gqvp/GHSA-p9xp-xghp-gqvp.json rename to advisories/github-reviewed/2022/05/GHSA-p9xp-xghp-gqvp/GHSA-p9xp-xghp-gqvp.json index 5c5611a8c1e..3595f024c40 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9xp-xghp-gqvp/GHSA-p9xp-xghp-gqvp.json +++ b/advisories/github-reviewed/2022/05/GHSA-p9xp-xghp-gqvp/GHSA-p9xp-xghp-gqvp.json @@ -1,17 +1,39 @@ { "schema_version": "1.4.0", "id": "GHSA-p9xp-xghp-gqvp", - "modified": "2022-05-24T17:18:42Z", + "modified": "2024-04-25T21:39:32Z", "published": "2022-05-24T17:18:42Z", "aliases": [ "CVE-2020-13487" ], + "summary": "bbPress stored Cross-Site Scripting (XSS) vulnerability in the Forum creation section", "details": "The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?post_type=forum (aka the Forum listing page) for all users. An administrator can exploit this at the wp-admin/post.php?action=edit URI.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "bbpress/bbpress" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.6.4" + } + ] + } + ] + } ], "references": [ { @@ -26,6 +48,10 @@ "type": "WEB", "url": "https://codex.bbpress.org/releases" }, + { + "type": "PACKAGE", + "url": "https://github.com/bbpress/bbPress" + }, { "type": "WEB", "url": "https://wordpress.org/plugins/bbpress/#developers" @@ -37,11 +63,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": "LOW", - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-25T21:39:32Z", "nvd_published_at": "2020-05-26T14:15:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/04/GHSA-483f-wxw9-3rpq/GHSA-483f-wxw9-3rpq.json b/advisories/unreviewed/2022/04/GHSA-483f-wxw9-3rpq/GHSA-483f-wxw9-3rpq.json deleted file mode 100644 index 49cd0e0ab01..00000000000 --- a/advisories/unreviewed/2022/04/GHSA-483f-wxw9-3rpq/GHSA-483f-wxw9-3rpq.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-483f-wxw9-3rpq", - "modified": "2022-04-22T00:24:25Z", - "published": "2022-04-22T00:24:25Z", - "aliases": [ - "CVE-2011-1150" - ], - "details": "bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2011-1150" - }, - { - "type": "WEB", - "url": "https://www.openwall.com/lists/oss-security/2011/03/14/20" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2020-02-05T22:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-277w-qpxr-2549/GHSA-277w-qpxr-2549.json b/advisories/unreviewed/2022/05/GHSA-277w-qpxr-2549/GHSA-277w-qpxr-2549.json deleted file mode 100644 index 8546bb68563..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-277w-qpxr-2549/GHSA-277w-qpxr-2549.json +++ /dev/null @@ -1,70 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-277w-qpxr-2549", - "modified": "2022-05-17T03:35:09Z", - "published": "2022-05-17T03:35:09Z", - "aliases": [ - "CVE-2016-4567" - ], - "details": "Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by \"jsinitfunctio%gn.\"", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-4567" - }, - { - "type": "WEB", - "url": "https://github.com/johndyer/mediaelement/commit/34834eef8ac830b9145df169ec22016a4350f06e" - }, - { - "type": "WEB", - "url": "https://codex.wordpress.org/Version_4.5.2" - }, - { - "type": "WEB", - "url": "https://core.trac.wordpress.org/changeset/37371" - }, - { - "type": "WEB", - "url": "https://gist.github.com/cure53/df34ea68c26441f3ae98f821ba1feb9c" - }, - { - "type": "WEB", - "url": "https://github.com/johndyer/mediaelement/blob/master/changelog.md" - }, - { - "type": "WEB", - "url": "https://wordpress.org/news/2016/05/wordpress-4-5-2" - }, - { - "type": "WEB", - "url": "https://wpvulndb.com/vulnerabilities/8488" - }, - { - "type": "WEB", - "url": "http://www.openwall.com/lists/oss-security/2016/05/07/2" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id/1035818" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2016-05-22T01:59:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-8h24-3cjr-xxmh/GHSA-8h24-3cjr-xxmh.json b/advisories/unreviewed/2022/05/GHSA-8h24-3cjr-xxmh/GHSA-8h24-3cjr-xxmh.json deleted file mode 100644 index af3dc6a20c1..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-8h24-3cjr-xxmh/GHSA-8h24-3cjr-xxmh.json +++ /dev/null @@ -1,38 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-8h24-3cjr-xxmh", - "modified": "2022-05-14T01:31:07Z", - "published": "2022-05-14T01:31:07Z", - "aliases": [ - "CVE-2018-16637" - ], - "details": "Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-16637" - }, - { - "type": "WEB", - "url": "https://github.com/security-breachlock/CVE-2018-16637/blob/master/evolution_xss_stored.pdf" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2018-12-28T17:29:00Z" - } -} \ No newline at end of file