From 52b511aa8ca2700e038784293f04e9d3fdf72be8 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 20 Nov 2023 06:31:42 +0000 Subject: [PATCH] Publish Advisories GHSA-39xr-x89f-x723 GHSA-xw85-vh2x-vg5q GHSA-xx79-4755-jq22 --- .../GHSA-39xr-x89f-x723.json | 47 +++++++++++++++++++ .../GHSA-xw85-vh2x-vg5q.json | 47 +++++++++++++++++++ .../GHSA-xx79-4755-jq22.json | 4 ++ 3 files changed, 98 insertions(+) create mode 100644 advisories/unreviewed/2023/11/GHSA-39xr-x89f-x723/GHSA-39xr-x89f-x723.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xw85-vh2x-vg5q/GHSA-xw85-vh2x-vg5q.json diff --git a/advisories/unreviewed/2023/11/GHSA-39xr-x89f-x723/GHSA-39xr-x89f-x723.json b/advisories/unreviewed/2023/11/GHSA-39xr-x89f-x723/GHSA-39xr-x89f-x723.json new file mode 100644 index 00000000000..09175010f52 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-39xr-x89f-x723/GHSA-39xr-x89f-x723.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39xr-x89f-x723", + "modified": "2023-11-20T06:30:31Z", + "published": "2023-11-20T06:30:31Z", + "aliases": [ + "CVE-2023-46700" + ], + "details": "SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary SQL command by sending a crafted request, and obtain or alter information stored in the database.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46700" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN15005948/" + }, + { + "type": "WEB", + "url": "https://www.luxsoft.eu/" + }, + { + "type": "WEB", + "url": "https://www.luxsoft.eu/?download" + }, + { + "type": "WEB", + "url": "https://www.luxsoft.eu/lcforum/viewtopic.php?id=476" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-20T05:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xw85-vh2x-vg5q/GHSA-xw85-vh2x-vg5q.json b/advisories/unreviewed/2023/11/GHSA-xw85-vh2x-vg5q/GHSA-xw85-vh2x-vg5q.json new file mode 100644 index 00000000000..5fb373941c2 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xw85-vh2x-vg5q/GHSA-xw85-vh2x-vg5q.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw85-vh2x-vg5q", + "modified": "2023-11-20T06:30:31Z", + "published": "2023-11-20T06:30:31Z", + "aliases": [ + "CVE-2023-47175" + ], + "details": "Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the product.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47175" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN15005948/" + }, + { + "type": "WEB", + "url": "https://www.luxsoft.eu/" + }, + { + "type": "WEB", + "url": "https://www.luxsoft.eu/?download" + }, + { + "type": "WEB", + "url": "https://www.luxsoft.eu/lcforum/viewtopic.php?id=476" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-20T05:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xx79-4755-jq22/GHSA-xx79-4755-jq22.json b/advisories/unreviewed/2023/11/GHSA-xx79-4755-jq22/GHSA-xx79-4755-jq22.json index 61342c25b32..ddb98a22a00 100644 --- a/advisories/unreviewed/2023/11/GHSA-xx79-4755-jq22/GHSA-xx79-4755-jq22.json +++ b/advisories/unreviewed/2023/11/GHSA-xx79-4755-jq22/GHSA-xx79-4755-jq22.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://gitlab.com/wireshark/wireshark/-/issues/19369" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5559" + }, { "type": "WEB", "url": "https://www.wireshark.org/security/wnpa-sec-2023-28.html"