diff --git a/advisories/unreviewed/2024/06/GHSA-gwrq-pgf5-r942/GHSA-gwrq-pgf5-r942.json b/advisories/unreviewed/2024/06/GHSA-gwrq-pgf5-r942/GHSA-gwrq-pgf5-r942.json index a84221355d2..e92ae181889 100644 --- a/advisories/unreviewed/2024/06/GHSA-gwrq-pgf5-r942/GHSA-gwrq-pgf5-r942.json +++ b/advisories/unreviewed/2024/06/GHSA-gwrq-pgf5-r942/GHSA-gwrq-pgf5-r942.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gwrq-pgf5-r942", - "modified": "2024-06-06T03:30:57Z", + "modified": "2024-08-06T12:30:32Z", "published": "2024-06-06T03:30:57Z", "aliases": [ "CVE-2024-5179" @@ -52,7 +52,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-2367-v666-24m6/GHSA-2367-v666-24m6.json b/advisories/unreviewed/2024/07/GHSA-2367-v666-24m6/GHSA-2367-v666-24m6.json index c7df688c739..3dd340b450e 100644 --- a/advisories/unreviewed/2024/07/GHSA-2367-v666-24m6/GHSA-2367-v666-24m6.json +++ b/advisories/unreviewed/2024/07/GHSA-2367-v666-24m6/GHSA-2367-v666-24m6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2367-v666-24m6", - "modified": "2024-07-21T06:30:35Z", + "modified": "2024-08-06T12:30:32Z", "published": "2024-07-15T00:30:40Z", "aliases": [ "CVE-2024-6732" @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://reports-kunull.vercel.app/CVE%20research/Student-study-center-desk-management-system-save_user" }, + { + "type": "WEB", + "url": "https://reports-kunull.vercel.app/CVEs/2024/CVE-2024-6732" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.271450" diff --git a/advisories/unreviewed/2024/07/GHSA-hrw3-f4qp-9h27/GHSA-hrw3-f4qp-9h27.json b/advisories/unreviewed/2024/07/GHSA-hrw3-f4qp-9h27/GHSA-hrw3-f4qp-9h27.json index 301e0d7eeec..4689ae33fd0 100644 --- a/advisories/unreviewed/2024/07/GHSA-hrw3-f4qp-9h27/GHSA-hrw3-f4qp-9h27.json +++ b/advisories/unreviewed/2024/07/GHSA-hrw3-f4qp-9h27/GHSA-hrw3-f4qp-9h27.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hrw3-f4qp-9h27", - "modified": "2024-07-21T15:30:26Z", + "modified": "2024-08-06T12:30:32Z", "published": "2024-07-17T03:31:38Z", "aliases": [ "CVE-2024-6802" @@ -33,6 +33,14 @@ "type": "WEB", "url": "https://reports-kunull.vercel.app/CVE%20research/computer-laboratory-management-system-save_record" }, + { + "type": "WEB", + "url": "https://reports-kunull.vercel.app/CVEs/2024/CVE-2024-6802" + }, + { + "type": "WEB", + "url": "https://reports-kunull.vercel.app/CVEs/CVE-2024-6802" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.271704" diff --git a/advisories/unreviewed/2024/07/GHSA-m6q8-3vcx-vm5c/GHSA-m6q8-3vcx-vm5c.json b/advisories/unreviewed/2024/07/GHSA-m6q8-3vcx-vm5c/GHSA-m6q8-3vcx-vm5c.json index 7015b8ce173..e81b12ab686 100644 --- a/advisories/unreviewed/2024/07/GHSA-m6q8-3vcx-vm5c/GHSA-m6q8-3vcx-vm5c.json +++ b/advisories/unreviewed/2024/07/GHSA-m6q8-3vcx-vm5c/GHSA-m6q8-3vcx-vm5c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m6q8-3vcx-vm5c", - "modified": "2024-07-21T06:30:35Z", + "modified": "2024-08-06T12:30:32Z", "published": "2024-07-15T00:30:40Z", "aliases": [ "CVE-2024-6731" @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://reports-kunull.vercel.app/CVE%20research/student-study-center-desk-management-system-save_student" }, + { + "type": "WEB", + "url": "https://reports-kunull.vercel.app/CVEs/2024/CVE-2024-6731" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.271449" diff --git a/advisories/unreviewed/2024/07/GHSA-q3p2-f3g7-w74p/GHSA-q3p2-f3g7-w74p.json b/advisories/unreviewed/2024/07/GHSA-q3p2-f3g7-w74p/GHSA-q3p2-f3g7-w74p.json index ab7b33cc0e7..9a3124aaf08 100644 --- a/advisories/unreviewed/2024/07/GHSA-q3p2-f3g7-w74p/GHSA-q3p2-f3g7-w74p.json +++ b/advisories/unreviewed/2024/07/GHSA-q3p2-f3g7-w74p/GHSA-q3p2-f3g7-w74p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q3p2-f3g7-w74p", - "modified": "2024-07-21T06:30:35Z", + "modified": "2024-08-06T12:30:32Z", "published": "2024-07-14T03:30:37Z", "aliases": [ "CVE-2024-6729" @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://reports-kunull.vercel.app/CVE%20research/2024/cve-2024-6729" }, + { + "type": "WEB", + "url": "https://reports-kunull.vercel.app/CVEs/2024/CVE-2024-6729" + }, { "type": "WEB", "url": "https://reports-kunull.vercel.app/sourcecodester-advocate-Management-system-add-act" diff --git a/advisories/unreviewed/2024/07/GHSA-r2jx-292h-wx26/GHSA-r2jx-292h-wx26.json b/advisories/unreviewed/2024/07/GHSA-r2jx-292h-wx26/GHSA-r2jx-292h-wx26.json index 051156397c3..875394f8340 100644 --- a/advisories/unreviewed/2024/07/GHSA-r2jx-292h-wx26/GHSA-r2jx-292h-wx26.json +++ b/advisories/unreviewed/2024/07/GHSA-r2jx-292h-wx26/GHSA-r2jx-292h-wx26.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r2jx-292h-wx26", - "modified": "2024-07-21T15:30:26Z", + "modified": "2024-08-06T12:30:32Z", "published": "2024-07-17T06:30:47Z", "aliases": [ "CVE-2024-6807" @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://reports-kunull.vercel.app/CVE%20research/student-study-center-desk-management-system-xss-firstname" }, + { + "type": "WEB", + "url": "https://reports-kunull.vercel.app/CVEs/2024/CVE-2024-6807" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.271706" diff --git a/advisories/unreviewed/2024/08/GHSA-44vq-rpm7-q5q6/GHSA-44vq-rpm7-q5q6.json b/advisories/unreviewed/2024/08/GHSA-44vq-rpm7-q5q6/GHSA-44vq-rpm7-q5q6.json new file mode 100644 index 00000000000..5c948f71054 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-44vq-rpm7-q5q6/GHSA-44vq-rpm7-q5q6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44vq-rpm7-q5q6", + "modified": "2024-08-06T12:30:34Z", + "published": "2024-08-06T12:30:34Z", + "aliases": [ + "CVE-2024-33960" + ], + "details": "SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'end' in '/admin/mod_reports/printreport.php' parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33960" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T12:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5v4x-p332-82v3/GHSA-5v4x-p332-82v3.json b/advisories/unreviewed/2024/08/GHSA-5v4x-p332-82v3/GHSA-5v4x-p332-82v3.json new file mode 100644 index 00000000000..6ddb42462df --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5v4x-p332-82v3/GHSA-5v4x-p332-82v3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v4x-p332-82v3", + "modified": "2024-08-06T12:30:33Z", + "published": "2024-08-06T12:30:33Z", + "aliases": [ + "CVE-2024-33981" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'start' parameter in '/admin/mod_reports/index.php'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33981" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T11:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6fq7-24vv-8ph3/GHSA-6fq7-24vv-8ph3.json b/advisories/unreviewed/2024/08/GHSA-6fq7-24vv-8ph3/GHSA-6fq7-24vv-8ph3.json new file mode 100644 index 00000000000..0bb265d93e5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6fq7-24vv-8ph3/GHSA-6fq7-24vv-8ph3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fq7-24vv-8ph3", + "modified": "2024-08-06T12:30:32Z", + "published": "2024-08-06T12:30:32Z", + "aliases": [ + "CVE-2024-33958" + ], + "details": "SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in 'phonenumber' in '/passwordrecover.php' parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33958" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T11:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6xh7-8hpv-jjq6/GHSA-6xh7-8hpv-jjq6.json b/advisories/unreviewed/2024/08/GHSA-6xh7-8hpv-jjq6/GHSA-6xh7-8hpv-jjq6.json new file mode 100644 index 00000000000..6ba58cdfee5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6xh7-8hpv-jjq6/GHSA-6xh7-8hpv-jjq6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xh7-8hpv-jjq6", + "modified": "2024-08-06T12:30:35Z", + "published": "2024-08-06T12:30:35Z", + "aliases": [ + "CVE-2024-33964" + ], + "details": "SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'id' in '/admin/mod_users/index.php' parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33964" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T12:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-75hc-c75r-vgm6/GHSA-75hc-c75r-vgm6.json b/advisories/unreviewed/2024/08/GHSA-75hc-c75r-vgm6/GHSA-75hc-c75r-vgm6.json new file mode 100644 index 00000000000..446fecbae38 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-75hc-c75r-vgm6/GHSA-75hc-c75r-vgm6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75hc-c75r-vgm6", + "modified": "2024-08-06T12:30:35Z", + "published": "2024-08-06T12:30:35Z", + "aliases": [ + "CVE-2024-33966" + ], + "details": "SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'xtsearch' in '/admin/mod_reports/index.php' parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33966" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T12:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7q88-7984-xv4j/GHSA-7q88-7984-xv4j.json b/advisories/unreviewed/2024/08/GHSA-7q88-7984-xv4j/GHSA-7q88-7984-xv4j.json new file mode 100644 index 00000000000..73d67dcf5f5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7q88-7984-xv4j/GHSA-7q88-7984-xv4j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q88-7984-xv4j", + "modified": "2024-08-06T12:30:33Z", + "published": "2024-08-06T12:30:33Z", + "aliases": [ + "CVE-2024-33979" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'q', 'arrival', 'departure' and 'accomodation' parameters in '/index.php'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33979" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T11:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-98fw-2rw5-qx3j/GHSA-98fw-2rw5-qx3j.json b/advisories/unreviewed/2024/08/GHSA-98fw-2rw5-qx3j/GHSA-98fw-2rw5-qx3j.json new file mode 100644 index 00000000000..072aab68edd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-98fw-2rw5-qx3j/GHSA-98fw-2rw5-qx3j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98fw-2rw5-qx3j", + "modified": "2024-08-06T12:30:35Z", + "published": "2024-08-06T12:30:35Z", + "aliases": [ + "CVE-2024-33963" + ], + "details": "SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'id' in '/admin/mod_room/index.php' parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33963" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T12:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ccg8-wmfg-jr2m/GHSA-ccg8-wmfg-jr2m.json b/advisories/unreviewed/2024/08/GHSA-ccg8-wmfg-jr2m/GHSA-ccg8-wmfg-jr2m.json new file mode 100644 index 00000000000..076a271fcd2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ccg8-wmfg-jr2m/GHSA-ccg8-wmfg-jr2m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccg8-wmfg-jr2m", + "modified": "2024-08-06T12:30:35Z", + "published": "2024-08-06T12:30:35Z", + "aliases": [ + "CVE-2024-33961" + ], + "details": "SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'code' in '/admin/mod_reservation/controller.php' parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33961" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T12:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cp63-qrw4-jq9g/GHSA-cp63-qrw4-jq9g.json b/advisories/unreviewed/2024/08/GHSA-cp63-qrw4-jq9g/GHSA-cp63-qrw4-jq9g.json new file mode 100644 index 00000000000..e4678db2eb1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cp63-qrw4-jq9g/GHSA-cp63-qrw4-jq9g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp63-qrw4-jq9g", + "modified": "2024-08-06T12:30:35Z", + "published": "2024-08-06T12:30:35Z", + "aliases": [ + "CVE-2024-33968" + ], + "details": "SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Attendance' and 'YearLevel' in '/AttendanceMonitoring/report/index.php' parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33968" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T12:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cxwg-qv44-9w7m/GHSA-cxwg-qv44-9w7m.json b/advisories/unreviewed/2024/08/GHSA-cxwg-qv44-9w7m/GHSA-cxwg-qv44-9w7m.json new file mode 100644 index 00000000000..f38ccc417d0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cxwg-qv44-9w7m/GHSA-cxwg-qv44-9w7m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxwg-qv44-9w7m", + "modified": "2024-08-06T12:30:33Z", + "published": "2024-08-06T12:30:33Z", + "aliases": [ + "CVE-2024-33980" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'start' parameter in '/admin/mod_reports/printreport.php'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33980" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T11:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ghwg-gpp4-w4x3/GHSA-ghwg-gpp4-w4x3.json b/advisories/unreviewed/2024/08/GHSA-ghwg-gpp4-w4x3/GHSA-ghwg-gpp4-w4x3.json new file mode 100644 index 00000000000..0754077b8d8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ghwg-gpp4-w4x3/GHSA-ghwg-gpp4-w4x3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghwg-gpp4-w4x3", + "modified": "2024-08-06T12:30:34Z", + "published": "2024-08-06T12:30:34Z", + "aliases": [ + "CVE-2024-7246" + ], + "details": "It's possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table between the proxy and the backend such that other clients see failed requests. It's also possible to use this vulnerability to leak other clients HTTP header keys, but not values.\n\nThis occurs because the error status for a misencoded header is not cleared between header reads, resulting in subsequent (incrementally indexed) added headers in the first request being poisoned until cleared from the HPACK table.\n\nPlease update to a fixed version of gRPC as soon as possible. This bug has been fixed in 1.58.3, 1.59.5, 1.60.2, 1.61.3, 1.62.3, 1.63.2, 1.64.3, 1.65.4.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7246" + }, + { + "type": "WEB", + "url": "https://github.com/grpc/grpc/issues/36245" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-440" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T11:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gpmp-jfx6-m9rh/GHSA-gpmp-jfx6-m9rh.json b/advisories/unreviewed/2024/08/GHSA-gpmp-jfx6-m9rh/GHSA-gpmp-jfx6-m9rh.json new file mode 100644 index 00000000000..730da1cf07d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gpmp-jfx6-m9rh/GHSA-gpmp-jfx6-m9rh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpmp-jfx6-m9rh", + "modified": "2024-08-06T12:30:36Z", + "published": "2024-08-06T12:30:36Z", + "aliases": [ + "CVE-2024-33972" + ], + "details": "SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'events' in '/report/event_print.php' parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33972" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T12:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gvw9-wmm2-6r96/GHSA-gvw9-wmm2-6r96.json b/advisories/unreviewed/2024/08/GHSA-gvw9-wmm2-6r96/GHSA-gvw9-wmm2-6r96.json new file mode 100644 index 00000000000..034f25c7e0a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gvw9-wmm2-6r96/GHSA-gvw9-wmm2-6r96.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvw9-wmm2-6r96", + "modified": "2024-08-06T12:30:33Z", + "published": "2024-08-06T12:30:33Z", + "aliases": [ + "CVE-2024-33978" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'category' parameter in '/index.php'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33978" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T11:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hjmq-w2m9-vmj6/GHSA-hjmq-w2m9-vmj6.json b/advisories/unreviewed/2024/08/GHSA-hjmq-w2m9-vmj6/GHSA-hjmq-w2m9-vmj6.json new file mode 100644 index 00000000000..f375656a07b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hjmq-w2m9-vmj6/GHSA-hjmq-w2m9-vmj6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjmq-w2m9-vmj6", + "modified": "2024-08-06T12:30:33Z", + "published": "2024-08-06T12:30:33Z", + "aliases": [ + "CVE-2024-33977" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'view' parameter in /admin/orders/index.php'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33977" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T11:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hjr8-mp59-p732/GHSA-hjr8-mp59-p732.json b/advisories/unreviewed/2024/08/GHSA-hjr8-mp59-p732/GHSA-hjr8-mp59-p732.json new file mode 100644 index 00000000000..db6924c3c49 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hjr8-mp59-p732/GHSA-hjr8-mp59-p732.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjr8-mp59-p732", + "modified": "2024-08-06T12:30:36Z", + "published": "2024-08-06T12:30:36Z", + "aliases": [ + "CVE-2024-33971" + ], + "details": "SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'username' in '/login.php' parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33971" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T12:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j85x-9rvx-crcg/GHSA-j85x-9rvx-crcg.json b/advisories/unreviewed/2024/08/GHSA-j85x-9rvx-crcg/GHSA-j85x-9rvx-crcg.json new file mode 100644 index 00000000000..042918cf0e0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j85x-9rvx-crcg/GHSA-j85x-9rvx-crcg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j85x-9rvx-crcg", + "modified": "2024-08-06T12:30:36Z", + "published": "2024-08-06T12:30:36Z", + "aliases": [ + "CVE-2024-33970" + ], + "details": "SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'studid' in '/candidate/controller.php' parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33970" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T12:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mhmm-rgjv-95hx/GHSA-mhmm-rgjv-95hx.json b/advisories/unreviewed/2024/08/GHSA-mhmm-rgjv-95hx/GHSA-mhmm-rgjv-95hx.json new file mode 100644 index 00000000000..079df6366ba --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mhmm-rgjv-95hx/GHSA-mhmm-rgjv-95hx.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhmm-rgjv-95hx", + "modified": "2024-08-06T12:30:35Z", + "published": "2024-08-06T12:30:34Z", + "aliases": [ + "CVE-2024-7317" + ], + "details": "The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7317" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/folders/tags/3.0.3/includes/media.replace.php#L1296" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3130880" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3130880/#file25" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/folders/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c2a2c069-5dc6-45e2-8ca1-842759d541c4?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T11:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mvr5-c43p-gf5m/GHSA-mvr5-c43p-gf5m.json b/advisories/unreviewed/2024/08/GHSA-mvr5-c43p-gf5m/GHSA-mvr5-c43p-gf5m.json new file mode 100644 index 00000000000..038a9ceedc0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mvr5-c43p-gf5m/GHSA-mvr5-c43p-gf5m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvr5-c43p-gf5m", + "modified": "2024-08-06T12:30:35Z", + "published": "2024-08-06T12:30:35Z", + "aliases": [ + "CVE-2024-33962" + ], + "details": "SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'code' in '/admin/mod_reservation/index.php' parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33962" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T12:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pwjw-hqj5-93ch/GHSA-pwjw-hqj5-93ch.json b/advisories/unreviewed/2024/08/GHSA-pwjw-hqj5-93ch/GHSA-pwjw-hqj5-93ch.json new file mode 100644 index 00000000000..2246b0380b4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pwjw-hqj5-93ch/GHSA-pwjw-hqj5-93ch.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwjw-hqj5-93ch", + "modified": "2024-08-06T12:30:36Z", + "published": "2024-08-06T12:30:36Z", + "aliases": [ + "CVE-2024-33973" + ], + "details": "SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Attendance' and 'YearLevel' in '/report/attendance_print.php' parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33973" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T12:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qwhw-rpr6-7qq8/GHSA-qwhw-rpr6-7qq8.json b/advisories/unreviewed/2024/08/GHSA-qwhw-rpr6-7qq8/GHSA-qwhw-rpr6-7qq8.json new file mode 100644 index 00000000000..dccc9a7bd69 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qwhw-rpr6-7qq8/GHSA-qwhw-rpr6-7qq8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwhw-rpr6-7qq8", + "modified": "2024-08-06T12:30:32Z", + "published": "2024-08-06T12:30:32Z", + "aliases": [ + "CVE-2024-33976" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially take over their browser session via 'id' parameter in '/admin/user/index.php'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33976" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T11:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-r6p4-7q78-rfh2/GHSA-r6p4-7q78-rfh2.json b/advisories/unreviewed/2024/08/GHSA-r6p4-7q78-rfh2/GHSA-r6p4-7q78-rfh2.json new file mode 100644 index 00000000000..4d01d6a4d5d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-r6p4-7q78-rfh2/GHSA-r6p4-7q78-rfh2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6p4-7q78-rfh2", + "modified": "2024-08-06T12:30:35Z", + "published": "2024-08-06T12:30:35Z", + "aliases": [ + "CVE-2024-33967" + ], + "details": "SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'view' in 'Attendance' and 'YearLevel' in '/AttendanceMonitoring/report/attendance_print.php' parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33967" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T12:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rh36-mh25-42v3/GHSA-rh36-mh25-42v3.json b/advisories/unreviewed/2024/08/GHSA-rh36-mh25-42v3/GHSA-rh36-mh25-42v3.json new file mode 100644 index 00000000000..751162f5bda --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rh36-mh25-42v3/GHSA-rh36-mh25-42v3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh36-mh25-42v3", + "modified": "2024-08-06T12:30:32Z", + "published": "2024-08-06T12:30:32Z", + "aliases": [ + "CVE-2024-33959" + ], + "details": "SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'categ' in '/admin/mod_reports/printreport.php' parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33959" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T11:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v68r-5mx2-7m49/GHSA-v68r-5mx2-7m49.json b/advisories/unreviewed/2024/08/GHSA-v68r-5mx2-7m49/GHSA-v68r-5mx2-7m49.json new file mode 100644 index 00000000000..4aa9441181f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v68r-5mx2-7m49/GHSA-v68r-5mx2-7m49.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v68r-5mx2-7m49", + "modified": "2024-08-06T12:30:35Z", + "published": "2024-08-06T12:30:35Z", + "aliases": [ + "CVE-2024-33965" + ], + "details": "SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'view' in '/tubigangarden/admin/mod_accomodation/index.php' parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33965" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T12:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vxr5-9pv4-x8xc/GHSA-vxr5-9pv4-x8xc.json b/advisories/unreviewed/2024/08/GHSA-vxr5-9pv4-x8xc/GHSA-vxr5-9pv4-x8xc.json new file mode 100644 index 00000000000..c887d1d7a75 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vxr5-9pv4-x8xc/GHSA-vxr5-9pv4-x8xc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxr5-9pv4-x8xc", + "modified": "2024-08-06T12:30:36Z", + "published": "2024-08-06T12:30:36Z", + "aliases": [ + "CVE-2024-33974" + ], + "details": "SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Users in '/report/printlogs.php' parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33974" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T12:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w532-q68f-hxv4/GHSA-w532-q68f-hxv4.json b/advisories/unreviewed/2024/08/GHSA-w532-q68f-hxv4/GHSA-w532-q68f-hxv4.json new file mode 100644 index 00000000000..4a2f07c505c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w532-q68f-hxv4/GHSA-w532-q68f-hxv4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w532-q68f-hxv4", + "modified": "2024-08-06T12:30:32Z", + "published": "2024-08-06T12:30:32Z", + "aliases": [ + "CVE-2024-33975" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially take over their browser session via 'view' parameter in '/admin/products/index.php'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33975" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T11:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w8hj-r7p6-h955/GHSA-w8hj-r7p6-h955.json b/advisories/unreviewed/2024/08/GHSA-w8hj-r7p6-h955/GHSA-w8hj-r7p6-h955.json new file mode 100644 index 00000000000..eb0763fca6d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w8hj-r7p6-h955/GHSA-w8hj-r7p6-h955.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8hj-r7p6-h955", + "modified": "2024-08-06T12:30:32Z", + "published": "2024-08-06T12:30:32Z", + "aliases": [ + "CVE-2024-33957" + ], + "details": "SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in 'id' in '/admin/orders/controller.php' parameter", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33957" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T11:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xwrx-6pgq-qmcj/GHSA-xwrx-6pgq-qmcj.json b/advisories/unreviewed/2024/08/GHSA-xwrx-6pgq-qmcj/GHSA-xwrx-6pgq-qmcj.json new file mode 100644 index 00000000000..31bd1fa96af --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xwrx-6pgq-qmcj/GHSA-xwrx-6pgq-qmcj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwrx-6pgq-qmcj", + "modified": "2024-08-06T12:30:35Z", + "published": "2024-08-06T12:30:35Z", + "aliases": [ + "CVE-2024-33969" + ], + "details": "SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'id' in '/AttendanceMonitoring/department/index.php' parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33969" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janobe-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-06T12:15:51Z" + } +} \ No newline at end of file