Publish Advisories

GHSA-g5x6-xpv4-w4mm
GHSA-2f7j-8pxq-5mww
GHSA-j8xm-x2w7-hmgh
GHSA-mh7g-3h8c-hq7m
GHSA-qqh7-j72m-6p4p
GHSA-rr6j-f8h9-f9mp
GHSA-xwpx-xxx9-g4xw
This commit is contained in:
advisory-database[bot]
2024-08-02 03:32:17 +00:00
parent a4f96aa679
commit 4f0724d03c
7 changed files with 319 additions and 4 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g5x6-xpv4-w4mm",
"modified": "2024-07-03T18:48:29Z",
"modified": "2024-08-02T03:30:50Z",
"published": "2024-07-03T18:48:29Z",
"aliases": [
"CVE-2024-29506"
],
"details": "Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-03T18:15:04Z"
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2f7j-8pxq-5mww",
"modified": "2024-08-02T03:30:50Z",
"published": "2024-08-02T03:30:50Z",
"aliases": [
"CVE-2024-7378"
],
"details": "A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /manage_question.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-273362 is the identifier assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7378"
},
{
"type": "WEB",
"url": "https://gist.github.com/topsky979/d4cb58afc5fb41f647b1021d1364d846"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.273362"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.273362"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.383526"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-02T03:15:52Z"
}
}
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j8xm-x2w7-hmgh",
"modified": "2024-08-02T03:30:50Z",
"published": "2024-08-02T03:30:50Z",
"aliases": [
"CVE-2024-7375"
],
"details": "A vulnerability, which was classified as critical, has been found in SourceCodester Simple Realtime Quiz System 1.0. This issue affects some unknown processing of the file /my_quiz_result.php. The manipulation of the argument quiz leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273359.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7375"
},
{
"type": "WEB",
"url": "https://gist.github.com/topsky979/840587360c33d53efb359ff314f7ea24"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.273359"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.273359"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.383523"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-02T01:16:01Z"
}
}
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mh7g-3h8c-hq7m",
"modified": "2024-08-02T03:30:50Z",
"published": "2024-08-02T03:30:50Z",
"aliases": [
"CVE-2024-7377"
],
"details": "A vulnerability has been found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /view_result.php. The manipulation of the argument qid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273361 was assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7377"
},
{
"type": "WEB",
"url": "https://gist.github.com/topsky979/4415a08deadd16356484d5ff540e60f9"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.273361"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.273361"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.383525"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-02T02:15:47Z"
}
}
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qqh7-j72m-6p4p",
"modified": "2024-08-02T03:30:50Z",
"published": "2024-08-02T03:30:50Z",
"aliases": [
"CVE-2024-7376"
],
"details": "A vulnerability, which was classified as critical, was found in SourceCodester Simple Realtime Quiz System 1.0. Affected is an unknown function of the file /print_quiz_records.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273360.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7376"
},
{
"type": "WEB",
"url": "https://gist.github.com/topsky979/8c36e6a899fc02e8054f67b94e34f6c6"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.273360"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.273360"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.383524"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-02T02:15:47Z"
}
}
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rr6j-f8h9-f9mp",
"modified": "2024-08-02T03:30:50Z",
"published": "2024-08-02T03:30:50Z",
"aliases": [
"CVE-2024-7374"
],
"details": "A vulnerability classified as critical was found in SourceCodester Simple Realtime Quiz System 1.0. This vulnerability affects unknown code of the file /manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273358 is the identifier assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7374"
},
{
"type": "WEB",
"url": "https://gist.github.com/topsky979/94ae61ff3fc760ac985dcd5e64da06c4"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.273358"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.273358"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.383522"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-02T01:16:01Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xwpx-xxx9-g4xw",
"modified": "2024-08-02T03:30:50Z",
"published": "2024-08-02T03:30:50Z",
"aliases": [
"CVE-2024-6567"
],
"details": "The Ebook Store plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.8001. This is due to the plugin utilizing fpdi-protection and not preventing direct access to test files that have display_errors set to true. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6567"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/ebook-store/trunk/fpdi/fpdi-protection-master/local-tests/simple.php"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ebe431a7-b552-4891-9784-c6a7353228da?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-02T02:15:47Z"
}
}