From 4f0724d03c2857794c69e3796d46d7c30cb6811f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 2 Aug 2024 03:32:17 +0000 Subject: [PATCH] Publish Advisories GHSA-g5x6-xpv4-w4mm GHSA-2f7j-8pxq-5mww GHSA-j8xm-x2w7-hmgh GHSA-mh7g-3h8c-hq7m GHSA-qqh7-j72m-6p4p GHSA-rr6j-f8h9-f9mp GHSA-xwpx-xxx9-g4xw --- .../GHSA-g5x6-xpv4-w4mm.json | 11 ++-- .../GHSA-2f7j-8pxq-5mww.json | 54 +++++++++++++++++++ .../GHSA-j8xm-x2w7-hmgh.json | 54 +++++++++++++++++++ .../GHSA-mh7g-3h8c-hq7m.json | 54 +++++++++++++++++++ .../GHSA-qqh7-j72m-6p4p.json | 54 +++++++++++++++++++ .../GHSA-rr6j-f8h9-f9mp.json | 54 +++++++++++++++++++ .../GHSA-xwpx-xxx9-g4xw.json | 42 +++++++++++++++ 7 files changed, 319 insertions(+), 4 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-2f7j-8pxq-5mww/GHSA-2f7j-8pxq-5mww.json create mode 100644 advisories/unreviewed/2024/08/GHSA-j8xm-x2w7-hmgh/GHSA-j8xm-x2w7-hmgh.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mh7g-3h8c-hq7m/GHSA-mh7g-3h8c-hq7m.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qqh7-j72m-6p4p/GHSA-qqh7-j72m-6p4p.json create mode 100644 advisories/unreviewed/2024/08/GHSA-rr6j-f8h9-f9mp/GHSA-rr6j-f8h9-f9mp.json create mode 100644 advisories/unreviewed/2024/08/GHSA-xwpx-xxx9-g4xw/GHSA-xwpx-xxx9-g4xw.json diff --git a/advisories/unreviewed/2024/07/GHSA-g5x6-xpv4-w4mm/GHSA-g5x6-xpv4-w4mm.json b/advisories/unreviewed/2024/07/GHSA-g5x6-xpv4-w4mm/GHSA-g5x6-xpv4-w4mm.json index 63f5f8412cb..f16e87a724f 100644 --- a/advisories/unreviewed/2024/07/GHSA-g5x6-xpv4-w4mm/GHSA-g5x6-xpv4-w4mm.json +++ b/advisories/unreviewed/2024/07/GHSA-g5x6-xpv4-w4mm/GHSA-g5x6-xpv4-w4mm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g5x6-xpv4-w4mm", - "modified": "2024-07-03T18:48:29Z", + "modified": "2024-08-02T03:30:50Z", "published": "2024-07-03T18:48:29Z", "aliases": [ "CVE-2024-29506" ], "details": "Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-03T18:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2f7j-8pxq-5mww/GHSA-2f7j-8pxq-5mww.json b/advisories/unreviewed/2024/08/GHSA-2f7j-8pxq-5mww/GHSA-2f7j-8pxq-5mww.json new file mode 100644 index 00000000000..be50bec6193 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2f7j-8pxq-5mww/GHSA-2f7j-8pxq-5mww.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f7j-8pxq-5mww", + "modified": "2024-08-02T03:30:50Z", + "published": "2024-08-02T03:30:50Z", + "aliases": [ + "CVE-2024-7378" + ], + "details": "A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /manage_question.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-273362 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7378" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/d4cb58afc5fb41f647b1021d1364d846" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273362" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273362" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383526" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T03:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j8xm-x2w7-hmgh/GHSA-j8xm-x2w7-hmgh.json b/advisories/unreviewed/2024/08/GHSA-j8xm-x2w7-hmgh/GHSA-j8xm-x2w7-hmgh.json new file mode 100644 index 00000000000..97fecf1084c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j8xm-x2w7-hmgh/GHSA-j8xm-x2w7-hmgh.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8xm-x2w7-hmgh", + "modified": "2024-08-02T03:30:50Z", + "published": "2024-08-02T03:30:50Z", + "aliases": [ + "CVE-2024-7375" + ], + "details": "A vulnerability, which was classified as critical, has been found in SourceCodester Simple Realtime Quiz System 1.0. This issue affects some unknown processing of the file /my_quiz_result.php. The manipulation of the argument quiz leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273359.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7375" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/840587360c33d53efb359ff314f7ea24" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273359" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273359" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383523" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T01:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mh7g-3h8c-hq7m/GHSA-mh7g-3h8c-hq7m.json b/advisories/unreviewed/2024/08/GHSA-mh7g-3h8c-hq7m/GHSA-mh7g-3h8c-hq7m.json new file mode 100644 index 00000000000..71f650e6f07 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mh7g-3h8c-hq7m/GHSA-mh7g-3h8c-hq7m.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mh7g-3h8c-hq7m", + "modified": "2024-08-02T03:30:50Z", + "published": "2024-08-02T03:30:50Z", + "aliases": [ + "CVE-2024-7377" + ], + "details": "A vulnerability has been found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /view_result.php. The manipulation of the argument qid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273361 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7377" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/4415a08deadd16356484d5ff540e60f9" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273361" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273361" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383525" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T02:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qqh7-j72m-6p4p/GHSA-qqh7-j72m-6p4p.json b/advisories/unreviewed/2024/08/GHSA-qqh7-j72m-6p4p/GHSA-qqh7-j72m-6p4p.json new file mode 100644 index 00000000000..02d96c50b92 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qqh7-j72m-6p4p/GHSA-qqh7-j72m-6p4p.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqh7-j72m-6p4p", + "modified": "2024-08-02T03:30:50Z", + "published": "2024-08-02T03:30:50Z", + "aliases": [ + "CVE-2024-7376" + ], + "details": "A vulnerability, which was classified as critical, was found in SourceCodester Simple Realtime Quiz System 1.0. Affected is an unknown function of the file /print_quiz_records.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273360.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7376" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/8c36e6a899fc02e8054f67b94e34f6c6" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273360" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273360" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383524" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T02:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rr6j-f8h9-f9mp/GHSA-rr6j-f8h9-f9mp.json b/advisories/unreviewed/2024/08/GHSA-rr6j-f8h9-f9mp/GHSA-rr6j-f8h9-f9mp.json new file mode 100644 index 00000000000..d91f135c787 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rr6j-f8h9-f9mp/GHSA-rr6j-f8h9-f9mp.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr6j-f8h9-f9mp", + "modified": "2024-08-02T03:30:50Z", + "published": "2024-08-02T03:30:50Z", + "aliases": [ + "CVE-2024-7374" + ], + "details": "A vulnerability classified as critical was found in SourceCodester Simple Realtime Quiz System 1.0. This vulnerability affects unknown code of the file /manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273358 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7374" + }, + { + "type": "WEB", + "url": "https://gist.github.com/topsky979/94ae61ff3fc760ac985dcd5e64da06c4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273358" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273358" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.383522" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T01:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xwpx-xxx9-g4xw/GHSA-xwpx-xxx9-g4xw.json b/advisories/unreviewed/2024/08/GHSA-xwpx-xxx9-g4xw/GHSA-xwpx-xxx9-g4xw.json new file mode 100644 index 00000000000..3253f9e2e94 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xwpx-xxx9-g4xw/GHSA-xwpx-xxx9-g4xw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwpx-xxx9-g4xw", + "modified": "2024-08-02T03:30:50Z", + "published": "2024-08-02T03:30:50Z", + "aliases": [ + "CVE-2024-6567" + ], + "details": "The Ebook Store plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.8001. This is due to the plugin utilizing fpdi-protection and not preventing direct access to test files that have display_errors set to true. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6567" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ebook-store/trunk/fpdi/fpdi-protection-master/local-tests/simple.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ebe431a7-b552-4891-9784-c6a7353228da?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-02T02:15:47Z" + } +} \ No newline at end of file