From 529004781e75fc08edf99cfc0a210e68c412edd7 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 30 Aug 2024 15:32:49 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-gc9m-33cp-rmpj.json | 1 + .../GHSA-2w7q-mj4w-9cm2.json | 3 +- .../GHSA-3492-v7j6-2xgv.json | 3 +- .../GHSA-73p8-f56m-692w.json | 3 +- .../GHSA-9m27-xfxh-7vgv.json | 11 ++-- .../GHSA-c3ph-4hj5-r598.json | 1 + .../GHSA-chjh-944f-687f.json | 3 +- .../GHSA-wcf6-w83f-hp3h.json | 11 ++-- .../GHSA-5qwh-g35c-5mmm.json | 3 +- .../GHSA-2gjq-7pvc-8hj3.json | 2 +- .../GHSA-36fq-3276-7898.json | 54 ++++++++++++++++ .../GHSA-3xcx-qx62-cpcx.json | 58 +++++++++++++++++ .../GHSA-52jj-6w68-3m25.json | 3 +- .../GHSA-5qxm-qvmj-8v79.json | 11 ++-- .../GHSA-76qm-c9j2-wm6v.json | 2 +- .../GHSA-784x-7qm2-gp97.json | 11 ++-- .../GHSA-7rfp-vjgq-5q3f.json | 58 +++++++++++++++++ .../GHSA-9759-w49c-9j8f.json | 58 +++++++++++++++++ .../GHSA-c77r-fh37-x2px.json | 38 ++++++++++++ .../GHSA-cmm9-5j5g-mhq5.json | 11 ++-- .../GHSA-cqxm-p8fm-64vf.json | 6 +- .../GHSA-g79x-6jx3-7f7g.json | 3 +- .../GHSA-g94g-fjpj-qccw.json | 11 ++-- .../GHSA-gjcf-776g-8w8g.json | 11 ++-- .../GHSA-j37h-9m2q-gr9m.json | 54 ++++++++++++++++ .../GHSA-m2m3-8mcw-w486.json | 11 ++-- .../GHSA-mvpq-r829-8jx3.json | 1 + .../GHSA-pr6w-8mm7-gvqj.json | 11 ++-- .../GHSA-r75v-8c97-7xvm.json | 11 ++-- .../GHSA-w6q4-mr7w-cv4x.json | 54 ++++++++++++++++ .../GHSA-w72p-2gg6-35cm.json | 58 +++++++++++++++++ .../GHSA-whcw-39v8-h8p9.json | 2 +- .../GHSA-x72g-3j3q-w4wf.json | 3 +- .../GHSA-xf8q-53cx-26jx.json | 62 +++++++++++++++++++ 34 files changed, 591 insertions(+), 52 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-36fq-3276-7898/GHSA-36fq-3276-7898.json create mode 100644 advisories/unreviewed/2024/08/GHSA-3xcx-qx62-cpcx/GHSA-3xcx-qx62-cpcx.json create mode 100644 advisories/unreviewed/2024/08/GHSA-7rfp-vjgq-5q3f/GHSA-7rfp-vjgq-5q3f.json create mode 100644 advisories/unreviewed/2024/08/GHSA-9759-w49c-9j8f/GHSA-9759-w49c-9j8f.json create mode 100644 advisories/unreviewed/2024/08/GHSA-c77r-fh37-x2px/GHSA-c77r-fh37-x2px.json create mode 100644 advisories/unreviewed/2024/08/GHSA-j37h-9m2q-gr9m/GHSA-j37h-9m2q-gr9m.json create mode 100644 advisories/unreviewed/2024/08/GHSA-w6q4-mr7w-cv4x/GHSA-w6q4-mr7w-cv4x.json create mode 100644 advisories/unreviewed/2024/08/GHSA-w72p-2gg6-35cm/GHSA-w72p-2gg6-35cm.json create mode 100644 advisories/unreviewed/2024/08/GHSA-xf8q-53cx-26jx/GHSA-xf8q-53cx-26jx.json diff --git a/advisories/unreviewed/2022/05/GHSA-gc9m-33cp-rmpj/GHSA-gc9m-33cp-rmpj.json b/advisories/unreviewed/2022/05/GHSA-gc9m-33cp-rmpj/GHSA-gc9m-33cp-rmpj.json index 18f2ee7f0ce..c025caec6b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-gc9m-33cp-rmpj/GHSA-gc9m-33cp-rmpj.json +++ b/advisories/unreviewed/2022/05/GHSA-gc9m-33cp-rmpj/GHSA-gc9m-33cp-rmpj.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-668" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/01/GHSA-2w7q-mj4w-9cm2/GHSA-2w7q-mj4w-9cm2.json b/advisories/unreviewed/2024/01/GHSA-2w7q-mj4w-9cm2/GHSA-2w7q-mj4w-9cm2.json index 013e1dfc2b6..a0b3af7f923 100644 --- a/advisories/unreviewed/2024/01/GHSA-2w7q-mj4w-9cm2/GHSA-2w7q-mj4w-9cm2.json +++ b/advisories/unreviewed/2024/01/GHSA-2w7q-mj4w-9cm2/GHSA-2w7q-mj4w-9cm2.json @@ -29,7 +29,8 @@ "database_specific": { "cwe_ids": [ "CWE-284", - "CWE-668" + "CWE-668", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-3492-v7j6-2xgv/GHSA-3492-v7j6-2xgv.json b/advisories/unreviewed/2024/06/GHSA-3492-v7j6-2xgv/GHSA-3492-v7j6-2xgv.json index b4b178d9a45..6166f1e0bd3 100644 --- a/advisories/unreviewed/2024/06/GHSA-3492-v7j6-2xgv/GHSA-3492-v7j6-2xgv.json +++ b/advisories/unreviewed/2024/06/GHSA-3492-v7j6-2xgv/GHSA-3492-v7j6-2xgv.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-863" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-73p8-f56m-692w/GHSA-73p8-f56m-692w.json b/advisories/unreviewed/2024/06/GHSA-73p8-f56m-692w/GHSA-73p8-f56m-692w.json index a26e2e8576d..a0108936540 100644 --- a/advisories/unreviewed/2024/06/GHSA-73p8-f56m-692w/GHSA-73p8-f56m-692w.json +++ b/advisories/unreviewed/2024/06/GHSA-73p8-f56m-692w/GHSA-73p8-f56m-692w.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-9m27-xfxh-7vgv/GHSA-9m27-xfxh-7vgv.json b/advisories/unreviewed/2024/06/GHSA-9m27-xfxh-7vgv/GHSA-9m27-xfxh-7vgv.json index 6d8046b6ec6..4185496e925 100644 --- a/advisories/unreviewed/2024/06/GHSA-9m27-xfxh-7vgv/GHSA-9m27-xfxh-7vgv.json +++ b/advisories/unreviewed/2024/06/GHSA-9m27-xfxh-7vgv/GHSA-9m27-xfxh-7vgv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9m27-xfxh-7vgv", - "modified": "2024-06-19T15:30:53Z", + "modified": "2024-08-30T15:31:25Z", "published": "2024-06-19T15:30:53Z", "aliases": [ "CVE-2024-38561" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nkunit: Fix kthread reference\n\nThere is a race condition when a kthread finishes after the deadline and\nbefore the call to kthread_stop(), which may lead to use after free.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:16Z" diff --git a/advisories/unreviewed/2024/06/GHSA-c3ph-4hj5-r598/GHSA-c3ph-4hj5-r598.json b/advisories/unreviewed/2024/06/GHSA-c3ph-4hj5-r598/GHSA-c3ph-4hj5-r598.json index 58bbacfde3c..f4ac54dfcd5 100644 --- a/advisories/unreviewed/2024/06/GHSA-c3ph-4hj5-r598/GHSA-c3ph-4hj5-r598.json +++ b/advisories/unreviewed/2024/06/GHSA-c3ph-4hj5-r598/GHSA-c3ph-4hj5-r598.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1333", "CWE-400" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/06/GHSA-chjh-944f-687f/GHSA-chjh-944f-687f.json b/advisories/unreviewed/2024/06/GHSA-chjh-944f-687f/GHSA-chjh-944f-687f.json index aec9b421c83..41b67ea36b8 100644 --- a/advisories/unreviewed/2024/06/GHSA-chjh-944f-687f/GHSA-chjh-944f-687f.json +++ b/advisories/unreviewed/2024/06/GHSA-chjh-944f-687f/GHSA-chjh-944f-687f.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-653" + "CWE-653", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-wcf6-w83f-hp3h/GHSA-wcf6-w83f-hp3h.json b/advisories/unreviewed/2024/06/GHSA-wcf6-w83f-hp3h/GHSA-wcf6-w83f-hp3h.json index 0d799f51b9b..87f62e7c0bc 100644 --- a/advisories/unreviewed/2024/06/GHSA-wcf6-w83f-hp3h/GHSA-wcf6-w83f-hp3h.json +++ b/advisories/unreviewed/2024/06/GHSA-wcf6-w83f-hp3h/GHSA-wcf6-w83f-hp3h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wcf6-w83f-hp3h", - "modified": "2024-06-19T15:30:53Z", + "modified": "2024-08-30T15:31:25Z", "published": "2024-06-19T15:30:53Z", "aliases": [ "CVE-2024-38562" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: nl80211: Avoid address calculations via out of bounds array indexing\n\nBefore request->channels[] can be used, request->n_channels must be set.\nAdditionally, address calculations for memory after the \"channels\" array\nneed to be calculated from the allocation base (\"request\") rather than\nvia the first \"out of bounds\" index of \"channels\", otherwise run-time\nbounds checking will throw a warning.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:16Z" diff --git a/advisories/unreviewed/2024/07/GHSA-5qwh-g35c-5mmm/GHSA-5qwh-g35c-5mmm.json b/advisories/unreviewed/2024/07/GHSA-5qwh-g35c-5mmm/GHSA-5qwh-g35c-5mmm.json index a15f848f197..7af9509517c 100644 --- a/advisories/unreviewed/2024/07/GHSA-5qwh-g35c-5mmm/GHSA-5qwh-g35c-5mmm.json +++ b/advisories/unreviewed/2024/07/GHSA-5qwh-g35c-5mmm/GHSA-5qwh-g35c-5mmm.json @@ -33,7 +33,8 @@ "database_specific": { "cwe_ids": [ "CWE-427", - "CWE-434" + "CWE-434", + "CWE-451" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-2gjq-7pvc-8hj3/GHSA-2gjq-7pvc-8hj3.json b/advisories/unreviewed/2024/08/GHSA-2gjq-7pvc-8hj3/GHSA-2gjq-7pvc-8hj3.json index 02f64ac477c..d9d49972214 100644 --- a/advisories/unreviewed/2024/08/GHSA-2gjq-7pvc-8hj3/GHSA-2gjq-7pvc-8hj3.json +++ b/advisories/unreviewed/2024/08/GHSA-2gjq-7pvc-8hj3/GHSA-2gjq-7pvc-8hj3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2gjq-7pvc-8hj3", - "modified": "2024-08-27T18:31:37Z", + "modified": "2024-08-30T15:31:26Z", "published": "2024-08-27T18:31:37Z", "aliases": [ "CVE-2024-8200" diff --git a/advisories/unreviewed/2024/08/GHSA-36fq-3276-7898/GHSA-36fq-3276-7898.json b/advisories/unreviewed/2024/08/GHSA-36fq-3276-7898/GHSA-36fq-3276-7898.json new file mode 100644 index 00000000000..5ddfba32c41 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-36fq-3276-7898/GHSA-36fq-3276-7898.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36fq-3276-7898", + "modified": "2024-08-30T15:31:31Z", + "published": "2024-08-30T15:31:31Z", + "aliases": [ + "CVE-2024-8335" + ], + "details": "A vulnerability classified as critical has been found in OpenRapid RapidCMS up to 1.3.1. Affected is an unknown function of the file /resource/runlogon.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8335" + }, + { + "type": "WEB", + "url": "https://gitee.com/A0kooo/cve_article/blob/master/RapidCMS/SQL%20injection2/rapidcms%20runlogon.php%20SQL%20injection.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276210" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276210" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.399005" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3xcx-qx62-cpcx/GHSA-3xcx-qx62-cpcx.json b/advisories/unreviewed/2024/08/GHSA-3xcx-qx62-cpcx/GHSA-3xcx-qx62-cpcx.json new file mode 100644 index 00000000000..5b733790d06 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3xcx-qx62-cpcx/GHSA-3xcx-qx62-cpcx.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xcx-qx62-cpcx", + "modified": "2024-08-30T15:31:31Z", + "published": "2024-08-30T15:31:31Z", + "aliases": [ + "CVE-2024-8340" + ], + "details": "A vulnerability classified as critical has been found in SourceCodester Electric Billing Management System 1.0. This affects an unknown part of the file /Actions.php?a=login. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8340" + }, + { + "type": "WEB", + "url": "https://github.com/enjoyworld/webray.com.cn/blob/main/cves/Electric%20Billing%20Management%20System/Electric%20Billing%20Managemen%20SQL-inject%20System%20Action.php%20SQL-inject.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276219" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276219" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.399548" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-52jj-6w68-3m25/GHSA-52jj-6w68-3m25.json b/advisories/unreviewed/2024/08/GHSA-52jj-6w68-3m25/GHSA-52jj-6w68-3m25.json index 620a88367ec..45305732d4f 100644 --- a/advisories/unreviewed/2024/08/GHSA-52jj-6w68-3m25/GHSA-52jj-6w68-3m25.json +++ b/advisories/unreviewed/2024/08/GHSA-52jj-6w68-3m25/GHSA-52jj-6w68-3m25.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-114" + "CWE-114", + "CWE-610" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-5qxm-qvmj-8v79/GHSA-5qxm-qvmj-8v79.json b/advisories/unreviewed/2024/08/GHSA-5qxm-qvmj-8v79/GHSA-5qxm-qvmj-8v79.json index 2f8eaeb3ff0..8a11cbfc924 100644 --- a/advisories/unreviewed/2024/08/GHSA-5qxm-qvmj-8v79/GHSA-5qxm-qvmj-8v79.json +++ b/advisories/unreviewed/2024/08/GHSA-5qxm-qvmj-8v79/GHSA-5qxm-qvmj-8v79.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5qxm-qvmj-8v79", - "modified": "2024-08-30T03:30:44Z", + "modified": "2024-08-30T15:31:30Z", "published": "2024-08-30T03:30:44Z", "aliases": [ "CVE-2024-45492" ], "details": "An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-30T03:15:03Z" diff --git a/advisories/unreviewed/2024/08/GHSA-76qm-c9j2-wm6v/GHSA-76qm-c9j2-wm6v.json b/advisories/unreviewed/2024/08/GHSA-76qm-c9j2-wm6v/GHSA-76qm-c9j2-wm6v.json index 9f0499ca1d5..1a5ade2ba6c 100644 --- a/advisories/unreviewed/2024/08/GHSA-76qm-c9j2-wm6v/GHSA-76qm-c9j2-wm6v.json +++ b/advisories/unreviewed/2024/08/GHSA-76qm-c9j2-wm6v/GHSA-76qm-c9j2-wm6v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-76qm-c9j2-wm6v", - "modified": "2024-08-19T18:32:05Z", + "modified": "2024-08-30T15:31:26Z", "published": "2024-08-12T15:30:51Z", "aliases": [ "CVE-2024-5651" diff --git a/advisories/unreviewed/2024/08/GHSA-784x-7qm2-gp97/GHSA-784x-7qm2-gp97.json b/advisories/unreviewed/2024/08/GHSA-784x-7qm2-gp97/GHSA-784x-7qm2-gp97.json index e09c795df25..c915e7e7ddf 100644 --- a/advisories/unreviewed/2024/08/GHSA-784x-7qm2-gp97/GHSA-784x-7qm2-gp97.json +++ b/advisories/unreviewed/2024/08/GHSA-784x-7qm2-gp97/GHSA-784x-7qm2-gp97.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-784x-7qm2-gp97", - "modified": "2024-08-30T03:30:44Z", + "modified": "2024-08-30T15:31:30Z", "published": "2024-08-30T03:30:44Z", "aliases": [ "CVE-2024-45491" ], "details": "An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-30T03:15:03Z" diff --git a/advisories/unreviewed/2024/08/GHSA-7rfp-vjgq-5q3f/GHSA-7rfp-vjgq-5q3f.json b/advisories/unreviewed/2024/08/GHSA-7rfp-vjgq-5q3f/GHSA-7rfp-vjgq-5q3f.json new file mode 100644 index 00000000000..15a694cbeb5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7rfp-vjgq-5q3f/GHSA-7rfp-vjgq-5q3f.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rfp-vjgq-5q3f", + "modified": "2024-08-30T15:31:31Z", + "published": "2024-08-30T15:31:31Z", + "aliases": [ + "CVE-2024-8336" + ], + "details": "A vulnerability classified as critical was found in SourceCodester Music Gallery Site 1.0. Affected by this vulnerability is an unknown functionality of the file /php-music/classes/Master.php?f=delete_music. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8336" + }, + { + "type": "WEB", + "url": "https://github.com/LiuHaoBin6/cve/blob/main/sql5.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276211" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276211" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.399039" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9759-w49c-9j8f/GHSA-9759-w49c-9j8f.json b/advisories/unreviewed/2024/08/GHSA-9759-w49c-9j8f/GHSA-9759-w49c-9j8f.json new file mode 100644 index 00000000000..67ebc6c82cc --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9759-w49c-9j8f/GHSA-9759-w49c-9j8f.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9759-w49c-9j8f", + "modified": "2024-08-30T15:31:31Z", + "published": "2024-08-30T15:31:31Z", + "aliases": [ + "CVE-2024-8341" + ], + "details": "A vulnerability classified as critical was found in SourceCodester Petshop Management System 1.0. This vulnerability affects unknown code of the file /controllers/add_user.php. The manipulation of the argument avatar leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8341" + }, + { + "type": "WEB", + "url": "https://github.com/enjoyworld/webray.com.cn/blob/main/cves/Petshop_Management_System/Petshop_Management_System%20add_user.php%20any%20file%20upload.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276220" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276220" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.399661" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T15:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c77r-fh37-x2px/GHSA-c77r-fh37-x2px.json b/advisories/unreviewed/2024/08/GHSA-c77r-fh37-x2px/GHSA-c77r-fh37-x2px.json new file mode 100644 index 00000000000..f93d56d9ae3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c77r-fh37-x2px/GHSA-c77r-fh37-x2px.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c77r-fh37-x2px", + "modified": "2024-08-30T15:31:30Z", + "published": "2024-08-30T15:31:30Z", + "aliases": [ + "CVE-2024-8260" + ], + "details": "A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8260" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/research/tra-2024-36" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-294" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cmm9-5j5g-mhq5/GHSA-cmm9-5j5g-mhq5.json b/advisories/unreviewed/2024/08/GHSA-cmm9-5j5g-mhq5/GHSA-cmm9-5j5g-mhq5.json index 083b920987e..c54c70adbac 100644 --- a/advisories/unreviewed/2024/08/GHSA-cmm9-5j5g-mhq5/GHSA-cmm9-5j5g-mhq5.json +++ b/advisories/unreviewed/2024/08/GHSA-cmm9-5j5g-mhq5/GHSA-cmm9-5j5g-mhq5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cmm9-5j5g-mhq5", - "modified": "2024-08-29T21:31:03Z", + "modified": "2024-08-30T15:31:29Z", "published": "2024-08-29T21:31:03Z", "aliases": [ "CVE-2024-41348" ], "details": "openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/alsearch.php", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-29T20:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-cqxm-p8fm-64vf/GHSA-cqxm-p8fm-64vf.json b/advisories/unreviewed/2024/08/GHSA-cqxm-p8fm-64vf/GHSA-cqxm-p8fm-64vf.json index abf520c9f4d..5cc1b9bf466 100644 --- a/advisories/unreviewed/2024/08/GHSA-cqxm-p8fm-64vf/GHSA-cqxm-p8fm-64vf.json +++ b/advisories/unreviewed/2024/08/GHSA-cqxm-p8fm-64vf/GHSA-cqxm-p8fm-64vf.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cqxm-p8fm-64vf", - "modified": "2024-08-27T15:32:52Z", + "modified": "2024-08-30T15:31:26Z", "published": "2024-08-27T15:32:52Z", "aliases": [ "CVE-2024-7071" ], "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in Brain Information Technologies Inc. Brain Low-Code allows SQL Injection.This issue affects Brain Low-Code: before 2.1.0.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/08/GHSA-g79x-6jx3-7f7g/GHSA-g79x-6jx3-7f7g.json b/advisories/unreviewed/2024/08/GHSA-g79x-6jx3-7f7g/GHSA-g79x-6jx3-7f7g.json index df77a7c0c56..041115a6aba 100644 --- a/advisories/unreviewed/2024/08/GHSA-g79x-6jx3-7f7g/GHSA-g79x-6jx3-7f7g.json +++ b/advisories/unreviewed/2024/08/GHSA-g79x-6jx3-7f7g/GHSA-g79x-6jx3-7f7g.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-798" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-g94g-fjpj-qccw/GHSA-g94g-fjpj-qccw.json b/advisories/unreviewed/2024/08/GHSA-g94g-fjpj-qccw/GHSA-g94g-fjpj-qccw.json index 1fea4a9e825..0b8bc7811e6 100644 --- a/advisories/unreviewed/2024/08/GHSA-g94g-fjpj-qccw/GHSA-g94g-fjpj-qccw.json +++ b/advisories/unreviewed/2024/08/GHSA-g94g-fjpj-qccw/GHSA-g94g-fjpj-qccw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g94g-fjpj-qccw", - "modified": "2024-08-29T21:31:04Z", + "modified": "2024-08-30T15:31:29Z", "published": "2024-08-29T21:31:04Z", "aliases": [ "CVE-2024-41372" ], "details": "Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/settyping.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-29T20:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-gjcf-776g-8w8g/GHSA-gjcf-776g-8w8g.json b/advisories/unreviewed/2024/08/GHSA-gjcf-776g-8w8g/GHSA-gjcf-776g-8w8g.json index bf9977b03b9..42c25a3d542 100644 --- a/advisories/unreviewed/2024/08/GHSA-gjcf-776g-8w8g/GHSA-gjcf-776g-8w8g.json +++ b/advisories/unreviewed/2024/08/GHSA-gjcf-776g-8w8g/GHSA-gjcf-776g-8w8g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gjcf-776g-8w8g", - "modified": "2024-08-27T18:31:37Z", + "modified": "2024-08-30T15:31:26Z", "published": "2024-08-27T18:31:37Z", "aliases": [ "CVE-2024-40395" ], "details": "An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of access level.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-27T16:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-j37h-9m2q-gr9m/GHSA-j37h-9m2q-gr9m.json b/advisories/unreviewed/2024/08/GHSA-j37h-9m2q-gr9m/GHSA-j37h-9m2q-gr9m.json new file mode 100644 index 00000000000..7fccc5f052b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j37h-9m2q-gr9m/GHSA-j37h-9m2q-gr9m.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j37h-9m2q-gr9m", + "modified": "2024-08-30T15:31:31Z", + "published": "2024-08-30T15:31:31Z", + "aliases": [ + "CVE-2024-8337" + ], + "details": "A vulnerability, which was classified as problematic, has been found in SourceCodester Contact Manager with Export to VCF 1.0. Affected by this issue is some unknown functionality of the file index.html. The manipulation of the argument contact_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8337" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276212" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276212" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.399338" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m2m3-8mcw-w486/GHSA-m2m3-8mcw-w486.json b/advisories/unreviewed/2024/08/GHSA-m2m3-8mcw-w486/GHSA-m2m3-8mcw-w486.json index e4d6992cf72..cfc79d567ae 100644 --- a/advisories/unreviewed/2024/08/GHSA-m2m3-8mcw-w486/GHSA-m2m3-8mcw-w486.json +++ b/advisories/unreviewed/2024/08/GHSA-m2m3-8mcw-w486/GHSA-m2m3-8mcw-w486.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m2m3-8mcw-w486", - "modified": "2024-08-29T21:31:03Z", + "modified": "2024-08-30T15:31:29Z", "published": "2024-08-29T21:31:03Z", "aliases": [ "CVE-2024-41347" ], "details": "openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/settings.php", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-29T20:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-mvpq-r829-8jx3/GHSA-mvpq-r829-8jx3.json b/advisories/unreviewed/2024/08/GHSA-mvpq-r829-8jx3/GHSA-mvpq-r829-8jx3.json index 121e1cf00e6..7940a6c7953 100644 --- a/advisories/unreviewed/2024/08/GHSA-mvpq-r829-8jx3/GHSA-mvpq-r829-8jx3.json +++ b/advisories/unreviewed/2024/08/GHSA-mvpq-r829-8jx3/GHSA-mvpq-r829-8jx3.json @@ -48,6 +48,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", "CWE-117" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/08/GHSA-pr6w-8mm7-gvqj/GHSA-pr6w-8mm7-gvqj.json b/advisories/unreviewed/2024/08/GHSA-pr6w-8mm7-gvqj/GHSA-pr6w-8mm7-gvqj.json index 688ef453621..711dad1aa83 100644 --- a/advisories/unreviewed/2024/08/GHSA-pr6w-8mm7-gvqj/GHSA-pr6w-8mm7-gvqj.json +++ b/advisories/unreviewed/2024/08/GHSA-pr6w-8mm7-gvqj/GHSA-pr6w-8mm7-gvqj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pr6w-8mm7-gvqj", - "modified": "2024-08-29T21:31:04Z", + "modified": "2024-08-30T15:31:29Z", "published": "2024-08-29T21:31:04Z", "aliases": [ "CVE-2024-41370" ], "details": "Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/setlike.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-29T20:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-r75v-8c97-7xvm/GHSA-r75v-8c97-7xvm.json b/advisories/unreviewed/2024/08/GHSA-r75v-8c97-7xvm/GHSA-r75v-8c97-7xvm.json index 1fce4eb238f..d4a8021e8f5 100644 --- a/advisories/unreviewed/2024/08/GHSA-r75v-8c97-7xvm/GHSA-r75v-8c97-7xvm.json +++ b/advisories/unreviewed/2024/08/GHSA-r75v-8c97-7xvm/GHSA-r75v-8c97-7xvm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r75v-8c97-7xvm", - "modified": "2024-08-29T21:31:03Z", + "modified": "2024-08-30T15:31:29Z", "published": "2024-08-29T21:31:03Z", "aliases": [ "CVE-2024-41346" ], "details": "openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/submit.php", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-29T20:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-w6q4-mr7w-cv4x/GHSA-w6q4-mr7w-cv4x.json b/advisories/unreviewed/2024/08/GHSA-w6q4-mr7w-cv4x/GHSA-w6q4-mr7w-cv4x.json new file mode 100644 index 00000000000..8f66e25297a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w6q4-mr7w-cv4x/GHSA-w6q4-mr7w-cv4x.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6q4-mr7w-cv4x", + "modified": "2024-08-30T15:31:31Z", + "published": "2024-08-30T15:31:31Z", + "aliases": [ + "CVE-2024-8338" + ], + "details": "A vulnerability was found in HFO4 shudong-share 2.4.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /includes/fileReceive.php of the component File Extension Handler. The manipulation of the argument file leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8338" + }, + { + "type": "WEB", + "url": "https://github.com/enjoyworld/webray.com.cn/blob/main/cves/shudong-share%20Any%20File%20Upload.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276217" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276217" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.399538" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w72p-2gg6-35cm/GHSA-w72p-2gg6-35cm.json b/advisories/unreviewed/2024/08/GHSA-w72p-2gg6-35cm/GHSA-w72p-2gg6-35cm.json new file mode 100644 index 00000000000..906f77c4a3d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w72p-2gg6-35cm/GHSA-w72p-2gg6-35cm.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w72p-2gg6-35cm", + "modified": "2024-08-30T15:31:31Z", + "published": "2024-08-30T15:31:31Z", + "aliases": [ + "CVE-2024-8339" + ], + "details": "A vulnerability was found in SourceCodester Electric Billing Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /?page=tracks of the component Connection Code Handler. The manipulation of the argument code leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8339" + }, + { + "type": "WEB", + "url": "https://github.com/enjoyworld/webray.com.cn/blob/main/cves/Electric%20Billing%20Management%20System/Electric%20Billing%20Managemen%20SQL-inject%20System%20tracks.php%20SQL-inject.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276218" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276218" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.399540" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-whcw-39v8-h8p9/GHSA-whcw-39v8-h8p9.json b/advisories/unreviewed/2024/08/GHSA-whcw-39v8-h8p9/GHSA-whcw-39v8-h8p9.json index eb312ccd46d..648f4da1d2e 100644 --- a/advisories/unreviewed/2024/08/GHSA-whcw-39v8-h8p9/GHSA-whcw-39v8-h8p9.json +++ b/advisories/unreviewed/2024/08/GHSA-whcw-39v8-h8p9/GHSA-whcw-39v8-h8p9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-whcw-39v8-h8p9", - "modified": "2024-08-27T18:31:37Z", + "modified": "2024-08-30T15:31:26Z", "published": "2024-08-27T18:31:37Z", "aliases": [ "CVE-2024-8199" diff --git a/advisories/unreviewed/2024/08/GHSA-x72g-3j3q-w4wf/GHSA-x72g-3j3q-w4wf.json b/advisories/unreviewed/2024/08/GHSA-x72g-3j3q-w4wf/GHSA-x72g-3j3q-w4wf.json index a445ce5aa45..0cb50210944 100644 --- a/advisories/unreviewed/2024/08/GHSA-x72g-3j3q-w4wf/GHSA-x72g-3j3q-w4wf.json +++ b/advisories/unreviewed/2024/08/GHSA-x72g-3j3q-w4wf/GHSA-x72g-3j3q-w4wf.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-xf8q-53cx-26jx/GHSA-xf8q-53cx-26jx.json b/advisories/unreviewed/2024/08/GHSA-xf8q-53cx-26jx/GHSA-xf8q-53cx-26jx.json new file mode 100644 index 00000000000..182841b6206 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xf8q-53cx-26jx/GHSA-xf8q-53cx-26jx.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xf8q-53cx-26jx", + "modified": "2024-08-30T15:31:30Z", + "published": "2024-08-30T15:31:30Z", + "aliases": [ + "CVE-2024-8334" + ], + "details": "A vulnerability was found in master-nan Sweet-CMS up to 5f441e022b8876f07cde709c77b5be6d2f262e3f. It has been rated as problematic. This issue affects the function LogHandler of the file middleware/log.go. The manipulation leads to improper output neutralization for logs. The attack may be initiated remotely. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The identifier of the patch is 2024c370e6c78b07b358c9d4257fa5d1be732c38. It is recommended to apply a patch to fix this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8334" + }, + { + "type": "WEB", + "url": "https://github.com/master-nan/sweet-cms/issues/3" + }, + { + "type": "WEB", + "url": "https://github.com/master-nan/sweet-cms/issues/3#issuecomment-2314447003" + }, + { + "type": "WEB", + "url": "https://github.com/master-nan/sweet-cms/commit/2024c370e6c78b07b358c9d4257fa5d1be732c38" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276209" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276209" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.398805" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-117" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-30T13:15:12Z" + } +} \ No newline at end of file