diff --git a/advisories/unreviewed/2022/05/GHSA-2pr3-qrhm-jm7j/GHSA-2pr3-qrhm-jm7j.json b/advisories/unreviewed/2022/05/GHSA-2pr3-qrhm-jm7j/GHSA-2pr3-qrhm-jm7j.json index 96a775ce231..b9b68399861 100644 --- a/advisories/unreviewed/2022/05/GHSA-2pr3-qrhm-jm7j/GHSA-2pr3-qrhm-jm7j.json +++ b/advisories/unreviewed/2022/05/GHSA-2pr3-qrhm-jm7j/GHSA-2pr3-qrhm-jm7j.json @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-9199" }, + { + "type": "WEB", + "url": "https://github.com/jjanku/podofo/commit/ada821df68fb0bf673840ed525daf4ec709dbfd9" + }, + { + "type": "WEB", + "url": "https://github.com/mksdev/podofo/commit/1400a9aaf611299b9a56aa2abeb158918b9743c8" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CIC2EXSSMBT3MY2HY42IIY4BUQS2SVYB/" diff --git a/advisories/unreviewed/2023/07/GHSA-42mr-mfcr-7jqh/GHSA-42mr-mfcr-7jqh.json b/advisories/unreviewed/2023/07/GHSA-42mr-mfcr-7jqh/GHSA-42mr-mfcr-7jqh.json index 54bc40aa85b..71d5378d74f 100644 --- a/advisories/unreviewed/2023/07/GHSA-42mr-mfcr-7jqh/GHSA-42mr-mfcr-7jqh.json +++ b/advisories/unreviewed/2023/07/GHSA-42mr-mfcr-7jqh/GHSA-42mr-mfcr-7jqh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-42mr-mfcr-7jqh", - "modified": "2023-07-06T19:24:05Z", + "modified": "2023-10-27T21:30:20Z", "published": "2023-07-06T19:24:05Z", "aliases": [ "CVE-2022-43557" ], "details": "The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical access, specialized equipment and knowledge may be able to configure or disable the pump. No electronic protected health information (ePHI), protected health information (PHI) or personally identifiable information (PII) is stored in the pump.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1299", + "CWE-287" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-433q-36rv-j5jj/GHSA-433q-36rv-j5jj.json b/advisories/unreviewed/2023/07/GHSA-433q-36rv-j5jj/GHSA-433q-36rv-j5jj.json index 93a39b142f9..757d871161d 100644 --- a/advisories/unreviewed/2023/07/GHSA-433q-36rv-j5jj/GHSA-433q-36rv-j5jj.json +++ b/advisories/unreviewed/2023/07/GHSA-433q-36rv-j5jj/GHSA-433q-36rv-j5jj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-433q-36rv-j5jj", - "modified": "2023-10-27T00:30:18Z", + "modified": "2023-10-27T21:30:21Z", "published": "2023-07-06T19:24:11Z", "aliases": [ "CVE-2023-0053" diff --git a/advisories/unreviewed/2023/10/GHSA-2962-mm2g-265c/GHSA-2962-mm2g-265c.json b/advisories/unreviewed/2023/10/GHSA-2962-mm2g-265c/GHSA-2962-mm2g-265c.json new file mode 100644 index 00000000000..6382240ea5d --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-2962-mm2g-265c/GHSA-2962-mm2g-265c.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2962-mm2g-265c", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-40120" + ], + "details": "In multiple locations, there is a possible way to bypass user notification of foreground services due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40120" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/d26544e5a4fd554b790b4d0c5964d9e95d9e626b" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2023-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-2mqf-694r-32x9/GHSA-2mqf-694r-32x9.json b/advisories/unreviewed/2023/10/GHSA-2mqf-694r-32x9/GHSA-2mqf-694r-32x9.json new file mode 100644 index 00000000000..7623a206588 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-2mqf-694r-32x9/GHSA-2mqf-694r-32x9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mqf-694r-32x9", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-46208" + ], + "details": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.6 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46208" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/motors-car-dealership-classified-listings/wordpress-motors-car-dealer-classifieds-listing-plugin-1-4-6-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-2q2c-7wf9-f9c2/GHSA-2q2c-7wf9-f9c2.json b/advisories/unreviewed/2023/10/GHSA-2q2c-7wf9-f9c2/GHSA-2q2c-7wf9-f9c2.json new file mode 100644 index 00000000000..e1a124ff628 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-2q2c-7wf9-f9c2/GHSA-2q2c-7wf9-f9c2.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2q2c-7wf9-f9c2", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-5828" + ], + "details": "A vulnerability was found in Nanning Ontall Longxing Industrial Development Zone Project Construction and Installation Management System up to 20231026. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.aspx. The manipulation of the argument tbxUserName leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243727.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5828" + }, + { + "type": "WEB", + "url": "https://github.com/Echosssy/-SQL-injection/blob/main/%E5%8D%97%E5%AE%81%E5%B8%82%E5%AE%89%E6%8B%93%E8%BD%AF%E4%BB%B6%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8SQL%20injection.doc" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.243727" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.243727" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-3856-cjch-9cv8/GHSA-3856-cjch-9cv8.json b/advisories/unreviewed/2023/10/GHSA-3856-cjch-9cv8/GHSA-3856-cjch-9cv8.json new file mode 100644 index 00000000000..80b5a1d1ccb --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-3856-cjch-9cv8/GHSA-3856-cjch-9cv8.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3856-cjch-9cv8", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-40117" + ], + "details": "In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40117" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/ff86ff28cf82124f8e65833a2dd8c319aea08945" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/packages/apps/Settings/+/11815817de2f2d70fe842b108356a1bc75d44ffb" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2023-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-39v7-36rj-8jh4/GHSA-39v7-36rj-8jh4.json b/advisories/unreviewed/2023/10/GHSA-39v7-36rj-8jh4/GHSA-39v7-36rj-8jh4.json index 3bbb568276d..83184540b36 100644 --- a/advisories/unreviewed/2023/10/GHSA-39v7-36rj-8jh4/GHSA-39v7-36rj-8jh4.json +++ b/advisories/unreviewed/2023/10/GHSA-39v7-36rj-8jh4/GHSA-39v7-36rj-8jh4.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-3c9r-8wrp-84w3/GHSA-3c9r-8wrp-84w3.json b/advisories/unreviewed/2023/10/GHSA-3c9r-8wrp-84w3/GHSA-3c9r-8wrp-84w3.json new file mode 100644 index 00000000000..13ae7ebca83 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-3c9r-8wrp-84w3/GHSA-3c9r-8wrp-84w3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c9r-8wrp-84w3", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-40129" + ], + "details": "In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40129" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/c0151aa3ba76c785b32c7f9d16c98febe53017b1" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2023-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-3g2w-rhvj-j46g/GHSA-3g2w-rhvj-j46g.json b/advisories/unreviewed/2023/10/GHSA-3g2w-rhvj-j46g/GHSA-3g2w-rhvj-j46g.json new file mode 100644 index 00000000000..2f08a7ba113 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-3g2w-rhvj-j46g/GHSA-3g2w-rhvj-j46g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g2w-rhvj-j46g", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2022-3700" + ], + "details": "A Time of Check Time of Use (TOCTOU) vulnerability was reported in the Lenovo Vantage SystemUpdate Plugin version 2.0.0.212 and earlier that could allow a local attacker to delete arbitrary files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3700" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-94532" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-3j55-7hc5-m8vh/GHSA-3j55-7hc5-m8vh.json b/advisories/unreviewed/2023/10/GHSA-3j55-7hc5-m8vh/GHSA-3j55-7hc5-m8vh.json new file mode 100644 index 00000000000..6464a2d1e01 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-3j55-7hc5-m8vh/GHSA-3j55-7hc5-m8vh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j55-7hc5-m8vh", + "modified": "2023-10-27T21:30:24Z", + "published": "2023-10-27T21:30:24Z", + "aliases": [ + "CVE-2023-46510" + ], + "details": "An issue in ZIONCOM (Hong Kong) Technology Limited A7000R v.4.1cu.4154 allows an attacker to execute arbitrary code via the cig-bin/cstecgi.cgi to the settings/setPasswordCfg function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46510" + }, + { + "type": "WEB", + "url": "https://gist.github.com/ATonysan/58ace23d539981441bca16ce0f7585e2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-3m8h-rcx6-p525/GHSA-3m8h-rcx6-p525.json b/advisories/unreviewed/2023/10/GHSA-3m8h-rcx6-p525/GHSA-3m8h-rcx6-p525.json new file mode 100644 index 00000000000..962c159e930 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-3m8h-rcx6-p525/GHSA-3m8h-rcx6-p525.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3m8h-rcx6-p525", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-40135" + ], + "details": "In applyCustomDescription of SaveUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40135" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/08becc8c600f14c5529115cc1a1e0c97cd503f33" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2023-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-3qf9-64j6-3672/GHSA-3qf9-64j6-3672.json b/advisories/unreviewed/2023/10/GHSA-3qf9-64j6-3672/GHSA-3qf9-64j6-3672.json index 52f80abc599..53e58384220 100644 --- a/advisories/unreviewed/2023/10/GHSA-3qf9-64j6-3672/GHSA-3qf9-64j6-3672.json +++ b/advisories/unreviewed/2023/10/GHSA-3qf9-64j6-3672/GHSA-3qf9-64j6-3672.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1321", "CWE-79" ], "severity": null, diff --git a/advisories/unreviewed/2023/10/GHSA-3rv4-77xr-w6jx/GHSA-3rv4-77xr-w6jx.json b/advisories/unreviewed/2023/10/GHSA-3rv4-77xr-w6jx/GHSA-3rv4-77xr-w6jx.json new file mode 100644 index 00000000000..b40fb31d2df --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-3rv4-77xr-w6jx/GHSA-3rv4-77xr-w6jx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rv4-77xr-w6jx", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2022-3681" + ], + "details": "A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to successfully brute force the WPS pin, potentially allowing them unauthorized access to a wireless network.\n ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3681" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20230317174952/https://help.motorolanetwork.com/hc/en-us/articles/9933302506523" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-3xhx-7chp-7wq6/GHSA-3xhx-7chp-7wq6.json b/advisories/unreviewed/2023/10/GHSA-3xhx-7chp-7wq6/GHSA-3xhx-7chp-7wq6.json new file mode 100644 index 00000000000..f953f62446d --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-3xhx-7chp-7wq6/GHSA-3xhx-7chp-7wq6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xhx-7chp-7wq6", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-44480" + ], + "details": "Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setcasualleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44480" + }, + { + "type": "WEB", + "url": "https://fluidattacks.com/advisories/martin/" + }, + { + "type": "WEB", + "url": "https://projectworlds.in/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-47qj-rqv2-98f2/GHSA-47qj-rqv2-98f2.json b/advisories/unreviewed/2023/10/GHSA-47qj-rqv2-98f2/GHSA-47qj-rqv2-98f2.json new file mode 100644 index 00000000000..7835dbfd77c --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-47qj-rqv2-98f2/GHSA-47qj-rqv2-98f2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47qj-rqv2-98f2", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-46852" + ], + "details": "In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the \"get\" substring.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46852" + }, + { + "type": "WEB", + "url": "https://github.com/memcached/memcached/commit/76a6c363c18cfe7b6a1524ae64202ac9db330767" + }, + { + "type": "WEB", + "url": "https://github.com/memcached/memcached/compare/1.6.21...1.6.22" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-4j6r-mf7f-44jq/GHSA-4j6r-mf7f-44jq.json b/advisories/unreviewed/2023/10/GHSA-4j6r-mf7f-44jq/GHSA-4j6r-mf7f-44jq.json index c9e10717d58..7950f7380d3 100644 --- a/advisories/unreviewed/2023/10/GHSA-4j6r-mf7f-44jq/GHSA-4j6r-mf7f-44jq.json +++ b/advisories/unreviewed/2023/10/GHSA-4j6r-mf7f-44jq/GHSA-4j6r-mf7f-44jq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4j6r-mf7f-44jq", - "modified": "2023-10-21T09:30:25Z", + "modified": "2023-10-27T21:30:22Z", "published": "2023-10-21T09:30:25Z", "aliases": [ "CVE-2023-46054" ], "details": "Cross Site Scripting (XSS) vulnerability in WBCE CMS v.1.6.1 and before allows a remote attacker to escalate privileges via a crafted script to the website_footer parameter in the admin/settings/save.php component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-4mwj-qxcc-x2p8/GHSA-4mwj-qxcc-x2p8.json b/advisories/unreviewed/2023/10/GHSA-4mwj-qxcc-x2p8/GHSA-4mwj-qxcc-x2p8.json index de590c1afb0..8530510fa05 100644 --- a/advisories/unreviewed/2023/10/GHSA-4mwj-qxcc-x2p8/GHSA-4mwj-qxcc-x2p8.json +++ b/advisories/unreviewed/2023/10/GHSA-4mwj-qxcc-x2p8/GHSA-4mwj-qxcc-x2p8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4mwj-qxcc-x2p8", - "modified": "2023-10-23T21:30:58Z", + "modified": "2023-10-27T21:30:22Z", "published": "2023-10-23T21:30:58Z", "aliases": [ "CVE-2023-27149" ], "details": "A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Label input parameter when updating a custom list.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-549w-5fgc-66mp/GHSA-549w-5fgc-66mp.json b/advisories/unreviewed/2023/10/GHSA-549w-5fgc-66mp/GHSA-549w-5fgc-66mp.json new file mode 100644 index 00000000000..4e8dd020337 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-549w-5fgc-66mp/GHSA-549w-5fgc-66mp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-549w-5fgc-66mp", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-46509" + ], + "details": "An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46509" + }, + { + "type": "WEB", + "url": "https://gist.github.com/ATonysan/d6f72e9eb90407d64bed4566aa80afb1#file-cve-2023-46509" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json b/advisories/unreviewed/2023/10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json index 9141c3d51cb..bfd9942b871 100644 --- a/advisories/unreviewed/2023/10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json +++ b/advisories/unreviewed/2023/10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://blog.leakix.net/2023/10/vinchin-backup-rce-chain/" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/31" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-5gjm-5h8m-h8w7/GHSA-5gjm-5h8m-h8w7.json b/advisories/unreviewed/2023/10/GHSA-5gjm-5h8m-h8w7/GHSA-5gjm-5h8m-h8w7.json new file mode 100644 index 00000000000..67b577234d4 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-5gjm-5h8m-h8w7/GHSA-5gjm-5h8m-h8w7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gjm-5h8m-h8w7", + "modified": "2023-10-27T21:30:22Z", + "published": "2023-10-27T21:30:22Z", + "aliases": [ + "CVE-2023-46290" + ], + "details": "\nDue to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into FactoryTalk® Services Platform . This vulnerability can only be exploited if the authorized user did not previously log in into the FactoryTalk® Services Platform web service.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46290" + }, + { + "type": "WEB", + "url": "https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1141165" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-62qc-qx92-4rhq/GHSA-62qc-qx92-4rhq.json b/advisories/unreviewed/2023/10/GHSA-62qc-qx92-4rhq/GHSA-62qc-qx92-4rhq.json new file mode 100644 index 00000000000..204adb31165 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-62qc-qx92-4rhq/GHSA-62qc-qx92-4rhq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62qc-qx92-4rhq", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-40140" + ], + "details": "In android_view_InputDevice_create of android_view_InputDevice.cpp, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40140" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/2d88a5c481df8986dbba2e02c5bf82f105b36243" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2023-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-63h9-pmmv-4m65/GHSA-63h9-pmmv-4m65.json b/advisories/unreviewed/2023/10/GHSA-63h9-pmmv-4m65/GHSA-63h9-pmmv-4m65.json new file mode 100644 index 00000000000..e3bd35feb4f --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-63h9-pmmv-4m65/GHSA-63h9-pmmv-4m65.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63h9-pmmv-4m65", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-40136" + ], + "details": "In setHeader of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40136" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/08becc8c600f14c5529115cc1a1e0c97cd503f33" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2023-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-7hqq-m574-qjp2/GHSA-7hqq-m574-qjp2.json b/advisories/unreviewed/2023/10/GHSA-7hqq-m574-qjp2/GHSA-7hqq-m574-qjp2.json new file mode 100644 index 00000000000..222d8ae6726 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-7hqq-m574-qjp2/GHSA-7hqq-m574-qjp2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hqq-m574-qjp2", + "modified": "2023-10-27T21:30:22Z", + "published": "2023-10-27T21:30:22Z", + "aliases": [ + "CVE-2023-27858" + ], + "details": "\nRockwell Automation Arena Simulation contains an arbitrary code execution vulnerability that could potentially allow a malicious user to commit unauthorized code to the software by using an uninitialized pointer in the application.  The threat-actor could then execute malicious code on the system affecting the confidentiality, integrity, and availability of the product.  The user would need to open a malicious file provided to them by the attacker for the code to execute.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27858" + }, + { + "type": "WEB", + "url": "https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1141145" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-824" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-7m88-4p79-28r9/GHSA-7m88-4p79-28r9.json b/advisories/unreviewed/2023/10/GHSA-7m88-4p79-28r9/GHSA-7m88-4p79-28r9.json new file mode 100644 index 00000000000..9ab644714d5 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-7m88-4p79-28r9/GHSA-7m88-4p79-28r9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m88-4p79-28r9", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2022-34834" + ], + "details": "An issue was discovered in VERMEG AgileReporter 21.3. Attackers can gain privileges via an XSS payload in an Add Comment action to the Activity log.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34834" + }, + { + "type": "WEB", + "url": "https://crashpark.weebly.com/blog/2-stored-xss-in-agilereporter-213-by-vermeg" + }, + { + "type": "WEB", + "url": "https://www.vermeg.com/agile-reporter/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-8qjc-4xcq-65rh/GHSA-8qjc-4xcq-65rh.json b/advisories/unreviewed/2023/10/GHSA-8qjc-4xcq-65rh/GHSA-8qjc-4xcq-65rh.json new file mode 100644 index 00000000000..ae1bead2112 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-8qjc-4xcq-65rh/GHSA-8qjc-4xcq-65rh.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qjc-4xcq-65rh", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-5829" + ], + "details": "A vulnerability was found in code-projects Admission Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file student_avatar.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243728.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5829" + }, + { + "type": "WEB", + "url": "https://github.com/lxxcute/Bug/blob/main/Admission%20Management%20System%20has%20a%20file%20upload%20(RCE)%20vulnerability.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.243728" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.243728" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-8wgv-6377-h5p6/GHSA-8wgv-6377-h5p6.json b/advisories/unreviewed/2023/10/GHSA-8wgv-6377-h5p6/GHSA-8wgv-6377-h5p6.json index a3714f1beb9..50192f72a2d 100644 --- a/advisories/unreviewed/2023/10/GHSA-8wgv-6377-h5p6/GHSA-8wgv-6377-h5p6.json +++ b/advisories/unreviewed/2023/10/GHSA-8wgv-6377-h5p6/GHSA-8wgv-6377-h5p6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8wgv-6377-h5p6", - "modified": "2023-10-22T00:30:17Z", + "modified": "2023-10-27T21:30:22Z", "published": "2023-10-22T00:30:17Z", "aliases": [ "CVE-2023-46078" diff --git a/advisories/unreviewed/2023/10/GHSA-9j42-4j78-g4mh/GHSA-9j42-4j78-g4mh.json b/advisories/unreviewed/2023/10/GHSA-9j42-4j78-g4mh/GHSA-9j42-4j78-g4mh.json new file mode 100644 index 00000000000..a92749a3fc3 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-9j42-4j78-g4mh/GHSA-9j42-4j78-g4mh.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9j42-4j78-g4mh", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-46407" + ], + "details": "FFmpeg prior to commit bf814 was discovered to contain an out of bounds read via the dist->alphabet_size variable in the read_vlc_prefix() function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46407" + }, + { + "type": "WEB", + "url": "https://github.com/FFmpeg/FFmpeg/commit/bf814387f42e9b0dea9d75c03db4723c88e7d962" + }, + { + "type": "WEB", + "url": "https://patchwork.ffmpeg.org/project/ffmpeg/patch/20231013014959.536776-1-leo.izen@gmail.com/" + }, + { + "type": "WEB", + "url": "https://patchwork.ffmpeg.org/project/ffmpeg/patch/20231015004924.597746-1-leo.izen@gmail.com/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-9jm2-h589-xc6m/GHSA-9jm2-h589-xc6m.json b/advisories/unreviewed/2023/10/GHSA-9jm2-h589-xc6m/GHSA-9jm2-h589-xc6m.json new file mode 100644 index 00000000000..17aa3ae4574 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-9jm2-h589-xc6m/GHSA-9jm2-h589-xc6m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jm2-h589-xc6m", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-40116" + ], + "details": "In onTaskAppeared of PipTaskOrganizer.java, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40116" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/18c3b194642f3949d09e48c21da5658fa04994c8" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2023-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-9m2m-543r-gv6g/GHSA-9m2m-543r-gv6g.json b/advisories/unreviewed/2023/10/GHSA-9m2m-543r-gv6g/GHSA-9m2m-543r-gv6g.json new file mode 100644 index 00000000000..706c7072a57 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-9m2m-543r-gv6g/GHSA-9m2m-543r-gv6g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m2m-543r-gv6g", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2022-3611" + ], + "details": "An information disclosure vulnerability has been identified in the Lenovo App Store which may allow some applications to gain unauthorized access to sensitive user data used by other unrelated applications.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3611" + }, + { + "type": "WEB", + "url": "https://iknow.lenovo.com.cn/detail/205280.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-9mvw-c7r6-xcpq/GHSA-9mvw-c7r6-xcpq.json b/advisories/unreviewed/2023/10/GHSA-9mvw-c7r6-xcpq/GHSA-9mvw-c7r6-xcpq.json new file mode 100644 index 00000000000..9dc09e43383 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-9mvw-c7r6-xcpq/GHSA-9mvw-c7r6-xcpq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mvw-c7r6-xcpq", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-40137" + ], + "details": "In multiple functions of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40137" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/08becc8c600f14c5529115cc1a1e0c97cd503f33" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2023-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-9qr5-85g4-f6rq/GHSA-9qr5-85g4-f6rq.json b/advisories/unreviewed/2023/10/GHSA-9qr5-85g4-f6rq/GHSA-9qr5-85g4-f6rq.json new file mode 100644 index 00000000000..7acf63ddb14 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-9qr5-85g4-f6rq/GHSA-9qr5-85g4-f6rq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qr5-85g4-f6rq", + "modified": "2023-10-27T21:30:22Z", + "published": "2023-10-27T21:30:22Z", + "aliases": [ + "CVE-2022-34886" + ], + "details": "A remote code execution vulnerability was found in the firmware used in some Lenovo printers, which can be caused by a remote user pushing an illegal string to the server-side interface via a script, resulting in a stack overflow.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34886" + }, + { + "type": "WEB", + "url": "https://iknow.lenovo.com.cn/detail/205041.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-c5qj-vxvj-r553/GHSA-c5qj-vxvj-r553.json b/advisories/unreviewed/2023/10/GHSA-c5qj-vxvj-r553/GHSA-c5qj-vxvj-r553.json new file mode 100644 index 00000000000..f3487924a42 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-c5qj-vxvj-r553/GHSA-c5qj-vxvj-r553.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5qj-vxvj-r553", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-46211" + ], + "details": "Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder plugin <= 3.19.14 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46211" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ultimate_vc_addons/wordpress-ultimate-addons-for-wpbakery-page-builder-plugin-3-19-14-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-cqgr-82mv-j79r/GHSA-cqgr-82mv-j79r.json b/advisories/unreviewed/2023/10/GHSA-cqgr-82mv-j79r/GHSA-cqgr-82mv-j79r.json new file mode 100644 index 00000000000..388d2a33db6 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-cqgr-82mv-j79r/GHSA-cqgr-82mv-j79r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqgr-82mv-j79r", + "modified": "2023-10-27T21:30:22Z", + "published": "2023-10-27T21:30:22Z", + "aliases": [ + "CVE-2023-27854" + ], + "details": "\nAn arbitrary code execution vulnerability was reported to Rockwell Automation in Arena Simulation that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffer overflow.  The threat-actor could then execute malicious code on the system affecting the confidentiality, integrity, and availability of the product.  The user would need to open a malicious file provided to them by the attacker for the code to execute.\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27854" + }, + { + "type": "WEB", + "url": "https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1141145" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-f43r-fv98-jc2w/GHSA-f43r-fv98-jc2w.json b/advisories/unreviewed/2023/10/GHSA-f43r-fv98-jc2w/GHSA-f43r-fv98-jc2w.json new file mode 100644 index 00000000000..d6f634cd4e2 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-f43r-fv98-jc2w/GHSA-f43r-fv98-jc2w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f43r-fv98-jc2w", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-46209" + ], + "details": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in G5Theme Grid Plus – Unlimited grid plugin <= 1.3.2 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46209" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/grid-plus/wordpress-grid-plus-plugin-1-3-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-fcv4-fw97-74j9/GHSA-fcv4-fw97-74j9.json b/advisories/unreviewed/2023/10/GHSA-fcv4-fw97-74j9/GHSA-fcv4-fw97-74j9.json new file mode 100644 index 00000000000..d9ad818ea2c --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-fcv4-fw97-74j9/GHSA-fcv4-fw97-74j9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcv4-fw97-74j9", + "modified": "2023-10-27T21:30:22Z", + "published": "2023-10-27T21:30:22Z", + "aliases": [ + "CVE-2022-34887" + ], + "details": "Standard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers without having to authenticate with the administrator password.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34887" + }, + { + "type": "WEB", + "url": "https://iknow.lenovo.com.cn/detail/205041.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-fgc2-w43g-3rcw/GHSA-fgc2-w43g-3rcw.json b/advisories/unreviewed/2023/10/GHSA-fgc2-w43g-3rcw/GHSA-fgc2-w43g-3rcw.json new file mode 100644 index 00000000000..f6498a30672 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-fgc2-w43g-3rcw/GHSA-fgc2-w43g-3rcw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgc2-w43g-3rcw", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2022-3701" + ], + "details": "\nA privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlier that could allow a local attacker to execute arbitrary code with elevated privileges.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3701" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-94532" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-fp6c-qc7r-8hw9/GHSA-fp6c-qc7r-8hw9.json b/advisories/unreviewed/2023/10/GHSA-fp6c-qc7r-8hw9/GHSA-fp6c-qc7r-8hw9.json new file mode 100644 index 00000000000..87e38760a58 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-fp6c-qc7r-8hw9/GHSA-fp6c-qc7r-8hw9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp6c-qc7r-8hw9", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2022-3702" + ], + "details": "\nA denial of service vulnerability was reported in Lenovo Vantage HardwareScan Plugin version 1.3.0.5 and earlier that could allow a local attacker to delete contents of an arbitrary directory under certain conditions.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3702" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-94532" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-fq8c-93h2-hrr9/GHSA-fq8c-93h2-hrr9.json b/advisories/unreviewed/2023/10/GHSA-fq8c-93h2-hrr9/GHSA-fq8c-93h2-hrr9.json index e46c09a2ed2..ee21bb7bcff 100644 --- a/advisories/unreviewed/2023/10/GHSA-fq8c-93h2-hrr9/GHSA-fq8c-93h2-hrr9.json +++ b/advisories/unreviewed/2023/10/GHSA-fq8c-93h2-hrr9/GHSA-fq8c-93h2-hrr9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fq8c-93h2-hrr9", - "modified": "2023-10-20T09:30:29Z", + "modified": "2023-10-27T21:30:22Z", "published": "2023-10-20T09:30:29Z", "aliases": [ "CVE-2023-5109" diff --git a/advisories/unreviewed/2023/10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json b/advisories/unreviewed/2023/10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json index cf84b5b8d76..dfb9316ab6e 100644 --- a/advisories/unreviewed/2023/10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json +++ b/advisories/unreviewed/2023/10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://blog.leakix.net/2023/10/vinchin-backup-rce-chain/" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2023/Oct/31" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-h235-jq43-x2pf/GHSA-h235-jq43-x2pf.json b/advisories/unreviewed/2023/10/GHSA-h235-jq43-x2pf/GHSA-h235-jq43-x2pf.json new file mode 100644 index 00000000000..aafe4bc9e9b --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-h235-jq43-x2pf/GHSA-h235-jq43-x2pf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h235-jq43-x2pf", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2022-34833" + ], + "details": "An issue was discovered in VERMEG AgileReporter 21.3. An admin can enter an XSS payload in the Analysis component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34833" + }, + { + "type": "WEB", + "url": "https://crashpark.weebly.com/blog/1-stored-xss-in-agilereporter-213-by-vermeg" + }, + { + "type": "WEB", + "url": "https://www.vermeg.com/agile-reporter/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-h7m2-v987-3v73/GHSA-h7m2-v987-3v73.json b/advisories/unreviewed/2023/10/GHSA-h7m2-v987-3v73/GHSA-h7m2-v987-3v73.json new file mode 100644 index 00000000000..6306b48eb8a --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-h7m2-v987-3v73/GHSA-h7m2-v987-3v73.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7m2-v987-3v73", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-40123" + ], + "details": "In updateActionViews of PipMenuView.java, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40123" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/7212a4bec2d2f1a74fa54a12a04255d6a183baa9" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2023-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-h9p2-g8w7-8363/GHSA-h9p2-g8w7-8363.json b/advisories/unreviewed/2023/10/GHSA-h9p2-g8w7-8363/GHSA-h9p2-g8w7-8363.json new file mode 100644 index 00000000000..06d32e0a098 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-h9p2-g8w7-8363/GHSA-h9p2-g8w7-8363.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9p2-g8w7-8363", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-40125" + ], + "details": "In onCreate of ApnEditor.java, there is a possible way for a Guest user to change the APN due to a permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40125" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/packages/apps/Settings/+/63d464c3fa5c7b9900448fef3844790756e557eb" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2023-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-j7wf-qmpf-6v3c/GHSA-j7wf-qmpf-6v3c.json b/advisories/unreviewed/2023/10/GHSA-j7wf-qmpf-6v3c/GHSA-j7wf-qmpf-6v3c.json new file mode 100644 index 00000000000..0d27b4d8855 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-j7wf-qmpf-6v3c/GHSA-j7wf-qmpf-6v3c.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7wf-qmpf-6v3c", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-40131" + ], + "details": "In GpuService of GpuService.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40131" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/native/+/0cda11569dd256ff3220b4fe44f861f8081d7116" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2023-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-j89v-wm7x-4434/GHSA-j89v-wm7x-4434.json b/advisories/unreviewed/2023/10/GHSA-j89v-wm7x-4434/GHSA-j89v-wm7x-4434.json new file mode 100644 index 00000000000..f0fb722e264 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-j89v-wm7x-4434/GHSA-j89v-wm7x-4434.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j89v-wm7x-4434", + "modified": "2023-10-27T21:30:24Z", + "published": "2023-10-27T21:30:24Z", + "aliases": [ + "CVE-2023-5830" + ], + "details": "A vulnerability classified as critical has been found in ColumbiaSoft Document Locator. This affects an unknown part of the file /api/authentication/login of the component WebTools. The manipulation of the argument Server leads to improper authentication. It is possible to initiate the attack remotely. Upgrading to version 7.2 SP4 and 2021.1 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-243729 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5830" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.243729" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.243729" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-jr2m-hrp3-3wj4/GHSA-jr2m-hrp3-3wj4.json b/advisories/unreviewed/2023/10/GHSA-jr2m-hrp3-3wj4/GHSA-jr2m-hrp3-3wj4.json new file mode 100644 index 00000000000..82e053dfd5d --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-jr2m-hrp3-3wj4/GHSA-jr2m-hrp3-3wj4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr2m-hrp3-3wj4", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-46853" + ], + "details": "In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \\n is used instead of \\r\\n.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46853" + }, + { + "type": "WEB", + "url": "https://github.com/memcached/memcached/commit/6987918e9a3094ec4fc8976f01f769f624d790fa" + }, + { + "type": "WEB", + "url": "https://github.com/memcached/memcached/compare/1.6.21...1.6.22" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-mc6f-pv36-prr2/GHSA-mc6f-pv36-prr2.json b/advisories/unreviewed/2023/10/GHSA-mc6f-pv36-prr2/GHSA-mc6f-pv36-prr2.json new file mode 100644 index 00000000000..4beb17a2bb2 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-mc6f-pv36-prr2/GHSA-mc6f-pv36-prr2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc6f-pv36-prr2", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-32738" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alkaweb Eonet Manual User Approve plugin <= 2.1.3 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32738" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/eonet-manual-user-approve/wordpress-eonet-manual-user-approve-plugin-2-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-mm89-gccr-q279/GHSA-mm89-gccr-q279.json b/advisories/unreviewed/2023/10/GHSA-mm89-gccr-q279/GHSA-mm89-gccr-q279.json new file mode 100644 index 00000000000..2edc3171216 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-mm89-gccr-q279/GHSA-mm89-gccr-q279.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm89-gccr-q279", + "modified": "2023-10-27T21:30:22Z", + "published": "2023-10-27T21:30:22Z", + "aliases": [ + "CVE-2022-3429" + ], + "details": "A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malformed strings to an open port, triggering a denial of service that causes a display error and prevents the printer from functioning properly.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3429" + }, + { + "type": "WEB", + "url": "https://iknow.lenovo.com.cn/detail/205041.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-pc6g-crww-hwrf/GHSA-pc6g-crww-hwrf.json b/advisories/unreviewed/2023/10/GHSA-pc6g-crww-hwrf/GHSA-pc6g-crww-hwrf.json new file mode 100644 index 00000000000..b67c383ee11 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-pc6g-crww-hwrf/GHSA-pc6g-crww-hwrf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc6g-crww-hwrf", + "modified": "2023-10-27T21:30:22Z", + "published": "2023-10-27T21:30:22Z", + "aliases": [ + "CVE-2023-46289" + ], + "details": "\nRockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would become unavailable and require a restart to recover resulting in a denial-of-service condition.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46289" + }, + { + "type": "WEB", + "url": "https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1141167" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-phrf-fj83-fcfv/GHSA-phrf-fj83-fcfv.json b/advisories/unreviewed/2023/10/GHSA-phrf-fj83-fcfv/GHSA-phrf-fj83-fcfv.json new file mode 100644 index 00000000000..c629624b95f --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-phrf-fj83-fcfv/GHSA-phrf-fj83-fcfv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phrf-fj83-fcfv", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-35794" + ], + "details": "An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed without authentication. Specifically, there is no session cookie validation on the Access Controller; instead, there is only Basic Authentication to the SSH console.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35794" + }, + { + "type": "WEB", + "url": "https://github.com/Dodge-MPTC/CVE-2023-35794-WebSSH-Hijacking" + }, + { + "type": "WEB", + "url": "https://www.cassianetworks.com/products/iot-access-controller/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-pjgc-q78w-v6ph/GHSA-pjgc-q78w-v6ph.json b/advisories/unreviewed/2023/10/GHSA-pjgc-q78w-v6ph/GHSA-pjgc-q78w-v6ph.json new file mode 100644 index 00000000000..5459ed26095 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-pjgc-q78w-v6ph/GHSA-pjgc-q78w-v6ph.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjgc-q78w-v6ph", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-40128" + ], + "details": "In several functions of xmlregexp.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40128" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/external/libxml2/+/1ccf89b87a3969edd56956e2d447f896037c8be7" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2023-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-q499-4369-cpxq/GHSA-q499-4369-cpxq.json b/advisories/unreviewed/2023/10/GHSA-q499-4369-cpxq/GHSA-q499-4369-cpxq.json new file mode 100644 index 00000000000..3396717dbed --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-q499-4369-cpxq/GHSA-q499-4369-cpxq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q499-4369-cpxq", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-40133" + ], + "details": "In multiple locations of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40133" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/08becc8c600f14c5529115cc1a1e0c97cd503f33" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2023-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-qh48-5646-82cv/GHSA-qh48-5646-82cv.json b/advisories/unreviewed/2023/10/GHSA-qh48-5646-82cv/GHSA-qh48-5646-82cv.json new file mode 100644 index 00000000000..631bc16a8a6 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-qh48-5646-82cv/GHSA-qh48-5646-82cv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qh48-5646-82cv", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-40130" + ], + "details": "In onBindingDied of CallRedirectionProcessor.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege and background activity launch with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40130" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/packages/services/Telecomm/+/5b335401d1c8de7d1c85f4a0cf353f7f9fc30218" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2023-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-r2hq-xr24-chr5/GHSA-r2hq-xr24-chr5.json b/advisories/unreviewed/2023/10/GHSA-r2hq-xr24-chr5/GHSA-r2hq-xr24-chr5.json index 17b3e75336d..3fec89339d1 100644 --- a/advisories/unreviewed/2023/10/GHSA-r2hq-xr24-chr5/GHSA-r2hq-xr24-chr5.json +++ b/advisories/unreviewed/2023/10/GHSA-r2hq-xr24-chr5/GHSA-r2hq-xr24-chr5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r2hq-xr24-chr5", - "modified": "2023-10-23T21:30:58Z", + "modified": "2023-10-27T21:30:22Z", "published": "2023-10-23T21:30:58Z", "aliases": [ "CVE-2023-27148" ], "details": "A stored cross-site scripting (XSS) vulnerability in the Admin panel in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Role Name parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-r3xw-5c7m-743g/GHSA-r3xw-5c7m-743g.json b/advisories/unreviewed/2023/10/GHSA-r3xw-5c7m-743g/GHSA-r3xw-5c7m-743g.json new file mode 100644 index 00000000000..4d8120506b9 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-r3xw-5c7m-743g/GHSA-r3xw-5c7m-743g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3xw-5c7m-743g", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-40138" + ], + "details": "In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40138" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/08becc8c600f14c5529115cc1a1e0c97cd503f33" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2023-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-r6fm-r8h7-c67g/GHSA-r6fm-r8h7-c67g.json b/advisories/unreviewed/2023/10/GHSA-r6fm-r8h7-c67g/GHSA-r6fm-r8h7-c67g.json index 5201e9b07be..f697c1744b7 100644 --- a/advisories/unreviewed/2023/10/GHSA-r6fm-r8h7-c67g/GHSA-r6fm-r8h7-c67g.json +++ b/advisories/unreviewed/2023/10/GHSA-r6fm-r8h7-c67g/GHSA-r6fm-r8h7-c67g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r6fm-r8h7-c67g", - "modified": "2023-10-21T21:30:25Z", + "modified": "2023-10-27T21:30:22Z", "published": "2023-10-21T21:30:25Z", "aliases": [ "CVE-2023-46067" diff --git a/advisories/unreviewed/2023/10/GHSA-r7w9-77p6-9q6m/GHSA-r7w9-77p6-9q6m.json b/advisories/unreviewed/2023/10/GHSA-r7w9-77p6-9q6m/GHSA-r7w9-77p6-9q6m.json index a9bf8512117..a753552e77b 100644 --- a/advisories/unreviewed/2023/10/GHSA-r7w9-77p6-9q6m/GHSA-r7w9-77p6-9q6m.json +++ b/advisories/unreviewed/2023/10/GHSA-r7w9-77p6-9q6m/GHSA-r7w9-77p6-9q6m.json @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43898" }, + { + "type": "WEB", + "url": "https://github.com/nothings/stb/issues/1452" + }, + { + "type": "WEB", + "url": "https://github.com/nothings/stb/pull/1454" + }, { "type": "WEB", "url": "https://github.com/peccc/null-stb" diff --git a/advisories/unreviewed/2023/10/GHSA-v2pp-7v4j-xg4g/GHSA-v2pp-7v4j-xg4g.json b/advisories/unreviewed/2023/10/GHSA-v2pp-7v4j-xg4g/GHSA-v2pp-7v4j-xg4g.json new file mode 100644 index 00000000000..50132deb3db --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-v2pp-7v4j-xg4g/GHSA-v2pp-7v4j-xg4g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2pp-7v4j-xg4g", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2022-34832" + ], + "details": "An issue was discovered in VERMEG AgileReporter 21.3. XXE can occur via an XML document to the Analysis component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34832" + }, + { + "type": "WEB", + "url": "https://crashpark.weebly.com/blog/xxe-in-agilereporter-213-by-vermeg" + }, + { + "type": "WEB", + "url": "https://www.vermeg.com/agile-reporter/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-vg5x-5wm4-7r4x/GHSA-vg5x-5wm4-7r4x.json b/advisories/unreviewed/2023/10/GHSA-vg5x-5wm4-7r4x/GHSA-vg5x-5wm4-7r4x.json new file mode 100644 index 00000000000..a03318c5114 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-vg5x-5wm4-7r4x/GHSA-vg5x-5wm4-7r4x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg5x-5wm4-7r4x", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-40134" + ], + "details": "In isFullScreen of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40134" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/08becc8c600f14c5529115cc1a1e0c97cd503f33" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2023-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-vvc5-h94x-p72m/GHSA-vvc5-h94x-p72m.json b/advisories/unreviewed/2023/10/GHSA-vvc5-h94x-p72m/GHSA-vvc5-h94x-p72m.json new file mode 100644 index 00000000000..faf7b025151 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-vvc5-h94x-p72m/GHSA-vvc5-h94x-p72m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvc5-h94x-p72m", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-40121" + ], + "details": "In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40121" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/3287ac2d2565dc96bf6177967f8e3aed33954253" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2023-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-vx25-5r7c-m73f/GHSA-vx25-5r7c-m73f.json b/advisories/unreviewed/2023/10/GHSA-vx25-5r7c-m73f/GHSA-vx25-5r7c-m73f.json index b7be93a6a25..f30a5b09312 100644 --- a/advisories/unreviewed/2023/10/GHSA-vx25-5r7c-m73f/GHSA-vx25-5r7c-m73f.json +++ b/advisories/unreviewed/2023/10/GHSA-vx25-5r7c-m73f/GHSA-vx25-5r7c-m73f.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-190" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-w42r-qhq4-9fc9/GHSA-w42r-qhq4-9fc9.json b/advisories/unreviewed/2023/10/GHSA-w42r-qhq4-9fc9/GHSA-w42r-qhq4-9fc9.json index 8856aef3c5a..d5cf48b1a18 100644 --- a/advisories/unreviewed/2023/10/GHSA-w42r-qhq4-9fc9/GHSA-w42r-qhq4-9fc9.json +++ b/advisories/unreviewed/2023/10/GHSA-w42r-qhq4-9fc9/GHSA-w42r-qhq4-9fc9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w42r-qhq4-9fc9", - "modified": "2023-10-20T09:30:28Z", + "modified": "2023-10-27T21:30:22Z", "published": "2023-10-20T09:30:28Z", "aliases": [ "CVE-2022-3342" diff --git a/advisories/unreviewed/2023/10/GHSA-w695-r3qx-vgwq/GHSA-w695-r3qx-vgwq.json b/advisories/unreviewed/2023/10/GHSA-w695-r3qx-vgwq/GHSA-w695-r3qx-vgwq.json new file mode 100644 index 00000000000..f58169b479f --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-w695-r3qx-vgwq/GHSA-w695-r3qx-vgwq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w695-r3qx-vgwq", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-40127" + ], + "details": "In multiple locations, there is a possible way to access screenshots due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40127" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/747431250612507e8289ae8eb1a56303e79ab678" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2023-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-whhh-xg23-hxcw/GHSA-whhh-xg23-hxcw.json b/advisories/unreviewed/2023/10/GHSA-whhh-xg23-hxcw/GHSA-whhh-xg23-hxcw.json new file mode 100644 index 00000000000..bd1e59a630f --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-whhh-xg23-hxcw/GHSA-whhh-xg23-hxcw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whhh-xg23-hxcw", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-40139" + ], + "details": "In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40139" + }, + { + "type": "WEB", + "url": "https://android.googlesource.com/platform/frameworks/base/+/08becc8c600f14c5529115cc1a1e0c97cd503f33" + }, + { + "type": "WEB", + "url": "https://source.android.com/security/bulletin/2023-10-01" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-wj66-97v8-j738/GHSA-wj66-97v8-j738.json b/advisories/unreviewed/2023/10/GHSA-wj66-97v8-j738/GHSA-wj66-97v8-j738.json new file mode 100644 index 00000000000..2f7fab0ee9a --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-wj66-97v8-j738/GHSA-wj66-97v8-j738.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj66-97v8-j738", + "modified": "2023-10-27T21:30:22Z", + "published": "2023-10-27T21:30:22Z", + "aliases": [ + "CVE-2023-4967" + ], + "details": "Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4967" + }, + { + "type": "WEB", + "url": "https://support.citrix.com/article/CTX579459/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-xrwj-6h7r-w997/GHSA-xrwj-6h7r-w997.json b/advisories/unreviewed/2023/10/GHSA-xrwj-6h7r-w997/GHSA-xrwj-6h7r-w997.json new file mode 100644 index 00000000000..6114fcdeae2 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-xrwj-6h7r-w997/GHSA-xrwj-6h7r-w997.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrwj-6h7r-w997", + "modified": "2023-10-27T21:30:23Z", + "published": "2023-10-27T21:30:23Z", + "aliases": [ + "CVE-2023-46200" + ], + "details": "Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Stephen Darlington, Wandle Software Limited Smart App Banner plugin <= 1.1.3 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46200" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/smart-app-banner/wordpress-smart-app-banner-plugin-1-1-3-cross-site-scripting-xss?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file