From 6200c3c556f24c4881b4ee32892afaba4fb5e9b0 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 2 Jan 2024 21:31:38 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-r6j6-xp6q-c876.json | 3 +- .../GHSA-9c8q-55w7-h67h.json | 4 +- .../GHSA-9qrw-74hf-7jc5.json | 2 +- .../GHSA-24wq-mq98-wpxw.json | 11 +++-- .../GHSA-28f3-rf96-2vvg.json | 2 +- .../GHSA-3f78-m5wq-gp55.json | 11 +++-- .../GHSA-454w-g337-r9mr.json | 2 +- .../GHSA-5c4q-4rqx-7fcj.json | 11 +++-- .../GHSA-5w24-985v-p9c2.json | 11 +++-- .../GHSA-6f93-6gw8-j4vp.json | 11 +++-- .../GHSA-7qcr-xmc4-f534.json | 11 +++-- .../GHSA-89ff-5hgp-6w8j.json | 11 +++-- .../GHSA-8fxj-9pc3-pv45.json | 11 +++-- .../GHSA-8w6w-7w4r-fv62.json | 11 +++-- .../GHSA-92jj-pmcg-vv48.json | 11 +++-- .../GHSA-c568-8x7p-64q6.json | 11 +++-- .../GHSA-f7j7-68hw-w26q.json | 2 +- .../GHSA-fmgf-v4r6-qv5c.json | 2 +- .../GHSA-g845-grc9-p9qg.json | 11 +++-- .../GHSA-j7x5-j8m5-25w4.json | 2 +- .../GHSA-j833-3wwq-9crw.json | 11 +++-- .../GHSA-jq2j-r76m-j65r.json | 2 +- .../GHSA-pw23-fcgc-jwxh.json | 2 +- .../GHSA-qq9v-mq32-4j57.json | 2 +- .../GHSA-qrgg-m4qr-fqhc.json | 11 +++-- .../GHSA-r89w-w5jp-rq8f.json | 2 +- .../GHSA-rvqp-hcp3-jq3c.json | 2 +- .../GHSA-v68g-q4qg-gx7q.json | 2 +- .../GHSA-vp7j-cfrc-8499.json | 11 +++-- .../GHSA-2f47-rm5c-8fr9.json | 38 +++++++++++++++ .../GHSA-4r33-2453-cxc5.json | 46 +++++++++++++++++++ .../GHSA-5rfq-95qv-rxwp.json | 35 ++++++++++++++ .../GHSA-89vh-9hfj-x469.json | 43 +++++++++++++++++ .../GHSA-fx3r-r9g3-mv57.json | 46 +++++++++++++++++++ .../GHSA-jjjw-x8pv-g64q.json | 43 +++++++++++++++++ .../GHSA-m6pc-42rj-wc4v.json | 46 +++++++++++++++++++ .../GHSA-mmc5-hgpc-m8q5.json | 46 +++++++++++++++++++ .../GHSA-p4x5-xm4x-p99c.json | 46 +++++++++++++++++++ .../GHSA-p5jr-rfj3-98f5.json | 35 ++++++++++++++ .../GHSA-w9r4-6f5q-p5h9.json | 46 +++++++++++++++++++ .../GHSA-x5gw-mqgf-fwh3.json | 46 +++++++++++++++++++ 41 files changed, 637 insertions(+), 75 deletions(-) create mode 100644 advisories/unreviewed/2024/01/GHSA-2f47-rm5c-8fr9/GHSA-2f47-rm5c-8fr9.json create mode 100644 advisories/unreviewed/2024/01/GHSA-4r33-2453-cxc5/GHSA-4r33-2453-cxc5.json create mode 100644 advisories/unreviewed/2024/01/GHSA-5rfq-95qv-rxwp/GHSA-5rfq-95qv-rxwp.json create mode 100644 advisories/unreviewed/2024/01/GHSA-89vh-9hfj-x469/GHSA-89vh-9hfj-x469.json create mode 100644 advisories/unreviewed/2024/01/GHSA-fx3r-r9g3-mv57/GHSA-fx3r-r9g3-mv57.json create mode 100644 advisories/unreviewed/2024/01/GHSA-jjjw-x8pv-g64q/GHSA-jjjw-x8pv-g64q.json create mode 100644 advisories/unreviewed/2024/01/GHSA-m6pc-42rj-wc4v/GHSA-m6pc-42rj-wc4v.json create mode 100644 advisories/unreviewed/2024/01/GHSA-mmc5-hgpc-m8q5/GHSA-mmc5-hgpc-m8q5.json create mode 100644 advisories/unreviewed/2024/01/GHSA-p4x5-xm4x-p99c/GHSA-p4x5-xm4x-p99c.json create mode 100644 advisories/unreviewed/2024/01/GHSA-p5jr-rfj3-98f5/GHSA-p5jr-rfj3-98f5.json create mode 100644 advisories/unreviewed/2024/01/GHSA-w9r4-6f5q-p5h9/GHSA-w9r4-6f5q-p5h9.json create mode 100644 advisories/unreviewed/2024/01/GHSA-x5gw-mqgf-fwh3/GHSA-x5gw-mqgf-fwh3.json diff --git a/advisories/unreviewed/2022/02/GHSA-r6j6-xp6q-c876/GHSA-r6j6-xp6q-c876.json b/advisories/unreviewed/2022/02/GHSA-r6j6-xp6q-c876/GHSA-r6j6-xp6q-c876.json index 0dd9c95a72a..b5edec37ee9 100644 --- a/advisories/unreviewed/2022/02/GHSA-r6j6-xp6q-c876/GHSA-r6j6-xp6q-c876.json +++ b/advisories/unreviewed/2022/02/GHSA-r6j6-xp6q-c876/GHSA-r6j6-xp6q-c876.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-203" + "CWE-203", + "CWE-204" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-9c8q-55w7-h67h/GHSA-9c8q-55w7-h67h.json b/advisories/unreviewed/2023/07/GHSA-9c8q-55w7-h67h/GHSA-9c8q-55w7-h67h.json index 40fe4f2b932..3c346d40dfd 100644 --- a/advisories/unreviewed/2023/07/GHSA-9c8q-55w7-h67h/GHSA-9c8q-55w7-h67h.json +++ b/advisories/unreviewed/2023/07/GHSA-9c8q-55w7-h67h/GHSA-9c8q-55w7-h67h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9c8q-55w7-h67h", - "modified": "2023-07-14T00:30:32Z", + "modified": "2024-01-02T21:30:23Z", "published": "2023-07-10T18:30:47Z", "aliases": [ "CVE-2021-42083" @@ -42,7 +42,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-07-10T16:15:47Z" diff --git a/advisories/unreviewed/2023/11/GHSA-9qrw-74hf-7jc5/GHSA-9qrw-74hf-7jc5.json b/advisories/unreviewed/2023/11/GHSA-9qrw-74hf-7jc5/GHSA-9qrw-74hf-7jc5.json index d48f5cb6b45..19965f48248 100644 --- a/advisories/unreviewed/2023/11/GHSA-9qrw-74hf-7jc5/GHSA-9qrw-74hf-7jc5.json +++ b/advisories/unreviewed/2023/11/GHSA-9qrw-74hf-7jc5/GHSA-9qrw-74hf-7jc5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9qrw-74hf-7jc5", - "modified": "2023-11-07T21:30:24Z", + "modified": "2024-01-02T21:30:24Z", "published": "2023-11-07T21:30:24Z", "aliases": [ "CVE-2023-46676" diff --git a/advisories/unreviewed/2023/12/GHSA-24wq-mq98-wpxw/GHSA-24wq-mq98-wpxw.json b/advisories/unreviewed/2023/12/GHSA-24wq-mq98-wpxw/GHSA-24wq-mq98-wpxw.json index 60a7f4cedac..bbcccfaa872 100644 --- a/advisories/unreviewed/2023/12/GHSA-24wq-mq98-wpxw/GHSA-24wq-mq98-wpxw.json +++ b/advisories/unreviewed/2023/12/GHSA-24wq-mq98-wpxw/GHSA-24wq-mq98-wpxw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-24wq-mq98-wpxw", - "modified": "2023-12-26T09:30:20Z", + "modified": "2024-01-02T21:30:25Z", "published": "2023-12-26T09:30:20Z", "aliases": [ "CVE-2023-47215" ], "details": "Stored cross-site scripting vulnerability which is exploiting a behavior of the XSS Filter exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T08:15:10Z" diff --git a/advisories/unreviewed/2023/12/GHSA-28f3-rf96-2vvg/GHSA-28f3-rf96-2vvg.json b/advisories/unreviewed/2023/12/GHSA-28f3-rf96-2vvg/GHSA-28f3-rf96-2vvg.json index da6ab51ce56..bad88e6e857 100644 --- a/advisories/unreviewed/2023/12/GHSA-28f3-rf96-2vvg/GHSA-28f3-rf96-2vvg.json +++ b/advisories/unreviewed/2023/12/GHSA-28f3-rf96-2vvg/GHSA-28f3-rf96-2vvg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-28f3-rf96-2vvg", - "modified": "2023-12-22T00:30:32Z", + "modified": "2024-01-02T21:30:25Z", "published": "2023-12-22T00:30:32Z", "aliases": [ "CVE-2023-49687" diff --git a/advisories/unreviewed/2023/12/GHSA-3f78-m5wq-gp55/GHSA-3f78-m5wq-gp55.json b/advisories/unreviewed/2023/12/GHSA-3f78-m5wq-gp55/GHSA-3f78-m5wq-gp55.json index 3e50e827f8b..ccc1590bc29 100644 --- a/advisories/unreviewed/2023/12/GHSA-3f78-m5wq-gp55/GHSA-3f78-m5wq-gp55.json +++ b/advisories/unreviewed/2023/12/GHSA-3f78-m5wq-gp55/GHSA-3f78-m5wq-gp55.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3f78-m5wq-gp55", - "modified": "2023-12-22T06:30:26Z", + "modified": "2024-01-02T21:30:25Z", "published": "2023-12-22T06:30:26Z", "aliases": [ "CVE-2022-47532" ], "details": "FileRun 20220519 allows SQL Injection via the \"dir\" parameter in a /?module=users§ion=cpanel&page=list request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-22T04:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-454w-g337-r9mr/GHSA-454w-g337-r9mr.json b/advisories/unreviewed/2023/12/GHSA-454w-g337-r9mr/GHSA-454w-g337-r9mr.json index 0915ab96e27..c5ba56b19d6 100644 --- a/advisories/unreviewed/2023/12/GHSA-454w-g337-r9mr/GHSA-454w-g337-r9mr.json +++ b/advisories/unreviewed/2023/12/GHSA-454w-g337-r9mr/GHSA-454w-g337-r9mr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-454w-g337-r9mr", - "modified": "2023-12-22T00:30:32Z", + "modified": "2024-01-02T21:30:25Z", "published": "2023-12-22T00:30:32Z", "aliases": [ "CVE-2023-49684" diff --git a/advisories/unreviewed/2023/12/GHSA-5c4q-4rqx-7fcj/GHSA-5c4q-4rqx-7fcj.json b/advisories/unreviewed/2023/12/GHSA-5c4q-4rqx-7fcj/GHSA-5c4q-4rqx-7fcj.json index 3cce3c725ca..bfa8c0c3a74 100644 --- a/advisories/unreviewed/2023/12/GHSA-5c4q-4rqx-7fcj/GHSA-5c4q-4rqx-7fcj.json +++ b/advisories/unreviewed/2023/12/GHSA-5c4q-4rqx-7fcj/GHSA-5c4q-4rqx-7fcj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5c4q-4rqx-7fcj", - "modified": "2023-12-26T21:30:33Z", + "modified": "2024-01-02T21:30:25Z", "published": "2023-12-26T21:30:33Z", "aliases": [ "CVE-2023-5991" ], "details": "The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T19:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-5w24-985v-p9c2/GHSA-5w24-985v-p9c2.json b/advisories/unreviewed/2023/12/GHSA-5w24-985v-p9c2/GHSA-5w24-985v-p9c2.json index bb5a30ce312..238543cc72b 100644 --- a/advisories/unreviewed/2023/12/GHSA-5w24-985v-p9c2/GHSA-5w24-985v-p9c2.json +++ b/advisories/unreviewed/2023/12/GHSA-5w24-985v-p9c2/GHSA-5w24-985v-p9c2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5w24-985v-p9c2", - "modified": "2023-12-26T09:30:20Z", + "modified": "2024-01-02T21:30:25Z", "published": "2023-12-26T09:30:20Z", "aliases": [ "CVE-2023-49779" ], "details": "Stored cross-site scripting vulnerability exists in the anchor tag of GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T08:15:11Z" diff --git a/advisories/unreviewed/2023/12/GHSA-6f93-6gw8-j4vp/GHSA-6f93-6gw8-j4vp.json b/advisories/unreviewed/2023/12/GHSA-6f93-6gw8-j4vp/GHSA-6f93-6gw8-j4vp.json index 2e6da11c566..17c8f9dd9e2 100644 --- a/advisories/unreviewed/2023/12/GHSA-6f93-6gw8-j4vp/GHSA-6f93-6gw8-j4vp.json +++ b/advisories/unreviewed/2023/12/GHSA-6f93-6gw8-j4vp/GHSA-6f93-6gw8-j4vp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6f93-6gw8-j4vp", - "modified": "2023-12-26T09:30:20Z", + "modified": "2024-01-02T21:30:25Z", "published": "2023-12-26T09:30:20Z", "aliases": [ "CVE-2023-50339" ], "details": "Stored cross-site scripting vulnerability exists in the User Management (/admin/users) page of GROWI versions prior to v6.1.11. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T08:15:11Z" diff --git a/advisories/unreviewed/2023/12/GHSA-7qcr-xmc4-f534/GHSA-7qcr-xmc4-f534.json b/advisories/unreviewed/2023/12/GHSA-7qcr-xmc4-f534/GHSA-7qcr-xmc4-f534.json index f14d84f30ca..cb9044c835a 100644 --- a/advisories/unreviewed/2023/12/GHSA-7qcr-xmc4-f534/GHSA-7qcr-xmc4-f534.json +++ b/advisories/unreviewed/2023/12/GHSA-7qcr-xmc4-f534/GHSA-7qcr-xmc4-f534.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7qcr-xmc4-f534", - "modified": "2023-12-26T09:30:20Z", + "modified": "2024-01-02T21:30:25Z", "published": "2023-12-26T09:30:20Z", "aliases": [ "CVE-2023-49598" ], "details": "Stored cross-site scripting vulnerability exists in the event handlers of the pre tags in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T08:15:10Z" diff --git a/advisories/unreviewed/2023/12/GHSA-89ff-5hgp-6w8j/GHSA-89ff-5hgp-6w8j.json b/advisories/unreviewed/2023/12/GHSA-89ff-5hgp-6w8j/GHSA-89ff-5hgp-6w8j.json index 45da1263871..8f14bdb8684 100644 --- a/advisories/unreviewed/2023/12/GHSA-89ff-5hgp-6w8j/GHSA-89ff-5hgp-6w8j.json +++ b/advisories/unreviewed/2023/12/GHSA-89ff-5hgp-6w8j/GHSA-89ff-5hgp-6w8j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-89ff-5hgp-6w8j", - "modified": "2023-12-26T09:30:20Z", + "modified": "2024-01-02T21:30:25Z", "published": "2023-12-26T09:30:20Z", "aliases": [ "CVE-2023-50294" ], "details": "The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As a result, the Secret access key for external service may be obtained by an attacker who can access the App Settings page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T08:15:11Z" diff --git a/advisories/unreviewed/2023/12/GHSA-8fxj-9pc3-pv45/GHSA-8fxj-9pc3-pv45.json b/advisories/unreviewed/2023/12/GHSA-8fxj-9pc3-pv45/GHSA-8fxj-9pc3-pv45.json index 5234d10834a..e2600404871 100644 --- a/advisories/unreviewed/2023/12/GHSA-8fxj-9pc3-pv45/GHSA-8fxj-9pc3-pv45.json +++ b/advisories/unreviewed/2023/12/GHSA-8fxj-9pc3-pv45/GHSA-8fxj-9pc3-pv45.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8fxj-9pc3-pv45", - "modified": "2023-12-26T21:30:33Z", + "modified": "2024-01-02T21:30:25Z", "published": "2023-12-26T21:30:33Z", "aliases": [ "CVE-2023-6166" ], "details": "The Quiz Maker WordPress plugin before 6.4.9.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T19:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-8w6w-7w4r-fv62/GHSA-8w6w-7w4r-fv62.json b/advisories/unreviewed/2023/12/GHSA-8w6w-7w4r-fv62/GHSA-8w6w-7w4r-fv62.json index c4ad09c784c..8114e0be3a5 100644 --- a/advisories/unreviewed/2023/12/GHSA-8w6w-7w4r-fv62/GHSA-8w6w-7w4r-fv62.json +++ b/advisories/unreviewed/2023/12/GHSA-8w6w-7w4r-fv62/GHSA-8w6w-7w4r-fv62.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8w6w-7w4r-fv62", - "modified": "2023-12-26T21:30:33Z", + "modified": "2024-01-02T21:30:25Z", "published": "2023-12-26T21:30:33Z", "aliases": [ "CVE-2023-6250" ], "details": "The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthenticated users via a meta tag", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T19:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-92jj-pmcg-vv48/GHSA-92jj-pmcg-vv48.json b/advisories/unreviewed/2023/12/GHSA-92jj-pmcg-vv48/GHSA-92jj-pmcg-vv48.json index d6bd9c35e0d..3dafefe1a1c 100644 --- a/advisories/unreviewed/2023/12/GHSA-92jj-pmcg-vv48/GHSA-92jj-pmcg-vv48.json +++ b/advisories/unreviewed/2023/12/GHSA-92jj-pmcg-vv48/GHSA-92jj-pmcg-vv48.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-92jj-pmcg-vv48", - "modified": "2023-12-26T21:30:33Z", + "modified": "2024-01-02T21:30:25Z", "published": "2023-12-26T21:30:33Z", "aliases": [ "CVE-2023-6155" ], "details": "The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticated attacker to perform a search for users of the system, ultimately leaking user email addresses.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-287" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T19:15:08Z" diff --git a/advisories/unreviewed/2023/12/GHSA-c568-8x7p-64q6/GHSA-c568-8x7p-64q6.json b/advisories/unreviewed/2023/12/GHSA-c568-8x7p-64q6/GHSA-c568-8x7p-64q6.json index 4aa87954c68..49fb8f9bf42 100644 --- a/advisories/unreviewed/2023/12/GHSA-c568-8x7p-64q6/GHSA-c568-8x7p-64q6.json +++ b/advisories/unreviewed/2023/12/GHSA-c568-8x7p-64q6/GHSA-c568-8x7p-64q6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c568-8x7p-64q6", - "modified": "2023-12-26T21:30:33Z", + "modified": "2024-01-02T21:30:25Z", "published": "2023-12-26T21:30:33Z", "aliases": [ "CVE-2023-5203" ], "details": "The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query parameters before using them in an SQL query, allowing unauthenticated attackers to extract sensitive data from the database via blind time based SQL injection techniques, or in some cases an error/union based technique.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T19:15:07Z" diff --git a/advisories/unreviewed/2023/12/GHSA-f7j7-68hw-w26q/GHSA-f7j7-68hw-w26q.json b/advisories/unreviewed/2023/12/GHSA-f7j7-68hw-w26q/GHSA-f7j7-68hw-w26q.json index c7db829e409..bd844ca8f1f 100644 --- a/advisories/unreviewed/2023/12/GHSA-f7j7-68hw-w26q/GHSA-f7j7-68hw-w26q.json +++ b/advisories/unreviewed/2023/12/GHSA-f7j7-68hw-w26q/GHSA-f7j7-68hw-w26q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f7j7-68hw-w26q", - "modified": "2023-12-21T15:30:32Z", + "modified": "2024-01-02T21:30:24Z", "published": "2023-12-21T15:30:32Z", "aliases": [ "CVE-2023-50822" diff --git a/advisories/unreviewed/2023/12/GHSA-fmgf-v4r6-qv5c/GHSA-fmgf-v4r6-qv5c.json b/advisories/unreviewed/2023/12/GHSA-fmgf-v4r6-qv5c/GHSA-fmgf-v4r6-qv5c.json index b7f0bea503e..309021ddf94 100644 --- a/advisories/unreviewed/2023/12/GHSA-fmgf-v4r6-qv5c/GHSA-fmgf-v4r6-qv5c.json +++ b/advisories/unreviewed/2023/12/GHSA-fmgf-v4r6-qv5c/GHSA-fmgf-v4r6-qv5c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fmgf-v4r6-qv5c", - "modified": "2023-12-22T00:30:31Z", + "modified": "2024-01-02T21:30:24Z", "published": "2023-12-22T00:30:31Z", "aliases": [ "CVE-2023-49678" diff --git a/advisories/unreviewed/2023/12/GHSA-g845-grc9-p9qg/GHSA-g845-grc9-p9qg.json b/advisories/unreviewed/2023/12/GHSA-g845-grc9-p9qg/GHSA-g845-grc9-p9qg.json index c8959e2454e..e8a6dd83597 100644 --- a/advisories/unreviewed/2023/12/GHSA-g845-grc9-p9qg/GHSA-g845-grc9-p9qg.json +++ b/advisories/unreviewed/2023/12/GHSA-g845-grc9-p9qg/GHSA-g845-grc9-p9qg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g845-grc9-p9qg", - "modified": "2023-12-26T09:30:20Z", + "modified": "2024-01-02T21:30:25Z", "published": "2023-12-26T09:30:20Z", "aliases": [ "CVE-2023-50175" ], "details": "Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page, the Markdown Settings (/admin/markdown) page, and the Customize (/admin/customize) page of GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T08:15:11Z" diff --git a/advisories/unreviewed/2023/12/GHSA-j7x5-j8m5-25w4/GHSA-j7x5-j8m5-25w4.json b/advisories/unreviewed/2023/12/GHSA-j7x5-j8m5-25w4/GHSA-j7x5-j8m5-25w4.json index c273ae6c9dd..6289f8f3e13 100644 --- a/advisories/unreviewed/2023/12/GHSA-j7x5-j8m5-25w4/GHSA-j7x5-j8m5-25w4.json +++ b/advisories/unreviewed/2023/12/GHSA-j7x5-j8m5-25w4/GHSA-j7x5-j8m5-25w4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j7x5-j8m5-25w4", - "modified": "2023-12-22T00:30:31Z", + "modified": "2024-01-02T21:30:24Z", "published": "2023-12-22T00:30:31Z", "aliases": [ "CVE-2023-49680" diff --git a/advisories/unreviewed/2023/12/GHSA-j833-3wwq-9crw/GHSA-j833-3wwq-9crw.json b/advisories/unreviewed/2023/12/GHSA-j833-3wwq-9crw/GHSA-j833-3wwq-9crw.json index 657d4770a50..485f9ed3dde 100644 --- a/advisories/unreviewed/2023/12/GHSA-j833-3wwq-9crw/GHSA-j833-3wwq-9crw.json +++ b/advisories/unreviewed/2023/12/GHSA-j833-3wwq-9crw/GHSA-j833-3wwq-9crw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j833-3wwq-9crw", - "modified": "2023-12-26T09:30:20Z", + "modified": "2024-01-02T21:30:25Z", "published": "2023-12-26T09:30:20Z", "aliases": [ "CVE-2023-49119" ], "details": "Stored cross-site scripting vulnerability via the img tags exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T08:15:10Z" diff --git a/advisories/unreviewed/2023/12/GHSA-jq2j-r76m-j65r/GHSA-jq2j-r76m-j65r.json b/advisories/unreviewed/2023/12/GHSA-jq2j-r76m-j65r/GHSA-jq2j-r76m-j65r.json index 1a4267a6b8e..5fbe9f76366 100644 --- a/advisories/unreviewed/2023/12/GHSA-jq2j-r76m-j65r/GHSA-jq2j-r76m-j65r.json +++ b/advisories/unreviewed/2023/12/GHSA-jq2j-r76m-j65r/GHSA-jq2j-r76m-j65r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jq2j-r76m-j65r", - "modified": "2023-12-22T00:30:31Z", + "modified": "2024-01-02T21:30:24Z", "published": "2023-12-22T00:30:31Z", "aliases": [ "CVE-2023-49682" diff --git a/advisories/unreviewed/2023/12/GHSA-pw23-fcgc-jwxh/GHSA-pw23-fcgc-jwxh.json b/advisories/unreviewed/2023/12/GHSA-pw23-fcgc-jwxh/GHSA-pw23-fcgc-jwxh.json index 53967f084ef..523e6b7006a 100644 --- a/advisories/unreviewed/2023/12/GHSA-pw23-fcgc-jwxh/GHSA-pw23-fcgc-jwxh.json +++ b/advisories/unreviewed/2023/12/GHSA-pw23-fcgc-jwxh/GHSA-pw23-fcgc-jwxh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pw23-fcgc-jwxh", - "modified": "2023-12-22T00:30:32Z", + "modified": "2024-01-02T21:30:25Z", "published": "2023-12-22T00:30:32Z", "aliases": [ "CVE-2023-49690" diff --git a/advisories/unreviewed/2023/12/GHSA-qq9v-mq32-4j57/GHSA-qq9v-mq32-4j57.json b/advisories/unreviewed/2023/12/GHSA-qq9v-mq32-4j57/GHSA-qq9v-mq32-4j57.json index af7a75d29f6..b063a1283eb 100644 --- a/advisories/unreviewed/2023/12/GHSA-qq9v-mq32-4j57/GHSA-qq9v-mq32-4j57.json +++ b/advisories/unreviewed/2023/12/GHSA-qq9v-mq32-4j57/GHSA-qq9v-mq32-4j57.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qq9v-mq32-4j57", - "modified": "2023-12-22T00:30:32Z", + "modified": "2024-01-02T21:30:25Z", "published": "2023-12-22T00:30:32Z", "aliases": [ "CVE-2023-49686" diff --git a/advisories/unreviewed/2023/12/GHSA-qrgg-m4qr-fqhc/GHSA-qrgg-m4qr-fqhc.json b/advisories/unreviewed/2023/12/GHSA-qrgg-m4qr-fqhc/GHSA-qrgg-m4qr-fqhc.json index 61a7ab02696..eb4a5349a97 100644 --- a/advisories/unreviewed/2023/12/GHSA-qrgg-m4qr-fqhc/GHSA-qrgg-m4qr-fqhc.json +++ b/advisories/unreviewed/2023/12/GHSA-qrgg-m4qr-fqhc/GHSA-qrgg-m4qr-fqhc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qrgg-m4qr-fqhc", - "modified": "2023-12-26T09:30:20Z", + "modified": "2024-01-02T21:30:25Z", "published": "2023-12-26T09:30:20Z", "aliases": [ "CVE-2023-49807" ], "details": "Stored cross-site scripting vulnerability when processing the MathJax exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T08:15:11Z" diff --git a/advisories/unreviewed/2023/12/GHSA-r89w-w5jp-rq8f/GHSA-r89w-w5jp-rq8f.json b/advisories/unreviewed/2023/12/GHSA-r89w-w5jp-rq8f/GHSA-r89w-w5jp-rq8f.json index 3b93bc8c75e..20c336ef2e5 100644 --- a/advisories/unreviewed/2023/12/GHSA-r89w-w5jp-rq8f/GHSA-r89w-w5jp-rq8f.json +++ b/advisories/unreviewed/2023/12/GHSA-r89w-w5jp-rq8f/GHSA-r89w-w5jp-rq8f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r89w-w5jp-rq8f", - "modified": "2023-12-22T00:30:31Z", + "modified": "2024-01-02T21:30:24Z", "published": "2023-12-22T00:30:31Z", "aliases": [ "CVE-2023-49679" diff --git a/advisories/unreviewed/2023/12/GHSA-rvqp-hcp3-jq3c/GHSA-rvqp-hcp3-jq3c.json b/advisories/unreviewed/2023/12/GHSA-rvqp-hcp3-jq3c/GHSA-rvqp-hcp3-jq3c.json index b6d9e50f517..4949ed18dfc 100644 --- a/advisories/unreviewed/2023/12/GHSA-rvqp-hcp3-jq3c/GHSA-rvqp-hcp3-jq3c.json +++ b/advisories/unreviewed/2023/12/GHSA-rvqp-hcp3-jq3c/GHSA-rvqp-hcp3-jq3c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rvqp-hcp3-jq3c", - "modified": "2023-12-27T21:31:00Z", + "modified": "2024-01-02T21:30:24Z", "published": "2023-12-22T00:30:32Z", "aliases": [ "CVE-2023-49683" diff --git a/advisories/unreviewed/2023/12/GHSA-v68g-q4qg-gx7q/GHSA-v68g-q4qg-gx7q.json b/advisories/unreviewed/2023/12/GHSA-v68g-q4qg-gx7q/GHSA-v68g-q4qg-gx7q.json index 65b43e74781..53edfb23f8f 100644 --- a/advisories/unreviewed/2023/12/GHSA-v68g-q4qg-gx7q/GHSA-v68g-q4qg-gx7q.json +++ b/advisories/unreviewed/2023/12/GHSA-v68g-q4qg-gx7q/GHSA-v68g-q4qg-gx7q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v68g-q4qg-gx7q", - "modified": "2023-12-22T00:30:32Z", + "modified": "2024-01-02T21:30:25Z", "published": "2023-12-22T00:30:32Z", "aliases": [ "CVE-2023-49685" diff --git a/advisories/unreviewed/2023/12/GHSA-vp7j-cfrc-8499/GHSA-vp7j-cfrc-8499.json b/advisories/unreviewed/2023/12/GHSA-vp7j-cfrc-8499/GHSA-vp7j-cfrc-8499.json index 3cd18300576..a26129df239 100644 --- a/advisories/unreviewed/2023/12/GHSA-vp7j-cfrc-8499/GHSA-vp7j-cfrc-8499.json +++ b/advisories/unreviewed/2023/12/GHSA-vp7j-cfrc-8499/GHSA-vp7j-cfrc-8499.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vp7j-cfrc-8499", - "modified": "2023-12-26T21:30:33Z", + "modified": "2024-01-02T21:30:25Z", "published": "2023-12-26T21:30:33Z", "aliases": [ "CVE-2023-5980" ], "details": "The BSK Forms Blacklist WordPress plugin before 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-26T19:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-2f47-rm5c-8fr9/GHSA-2f47-rm5c-8fr9.json b/advisories/unreviewed/2024/01/GHSA-2f47-rm5c-8fr9/GHSA-2f47-rm5c-8fr9.json new file mode 100644 index 00000000000..a6c62fc6055 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2f47-rm5c-8fr9/GHSA-2f47-rm5c-8fr9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f47-rm5c-8fr9", + "modified": "2024-01-02T21:30:25Z", + "published": "2024-01-02T21:30:25Z", + "aliases": [ + "CVE-2023-48419" + ], + "details": "An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege \n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48419" + }, + { + "type": "WEB", + "url": "https://support.google.com/product-documentation/answer/14273332?hl=en&ref_topic=12974021&sjid=4533873659772963473-NA#zippy=%2Cspeakers" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4r33-2453-cxc5/GHSA-4r33-2453-cxc5.json b/advisories/unreviewed/2024/01/GHSA-4r33-2453-cxc5/GHSA-4r33-2453-cxc5.json new file mode 100644 index 00000000000..38c184ae40a --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-4r33-2453-cxc5/GHSA-4r33-2453-cxc5.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r33-2453-cxc5", + "modified": "2024-01-02T21:30:26Z", + "published": "2024-01-02T21:30:26Z", + "aliases": [ + "CVE-2024-0194" + ], + "details": "A vulnerability, which was classified as critical, has been found in CodeAstro Internet Banking System up to 1.0. This issue affects some unknown processing of the file pages_account.php of the component Profile Picture Handler. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249509 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0194" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/147yg6oMHoJ1WvhH-TT0-GXDjKyNCSoeX/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249509" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249509" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5rfq-95qv-rxwp/GHSA-5rfq-95qv-rxwp.json b/advisories/unreviewed/2024/01/GHSA-5rfq-95qv-rxwp/GHSA-5rfq-95qv-rxwp.json new file mode 100644 index 00000000000..246a93be21d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5rfq-95qv-rxwp/GHSA-5rfq-95qv-rxwp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rfq-95qv-rxwp", + "modified": "2024-01-02T21:30:26Z", + "published": "2024-01-02T21:30:26Z", + "aliases": [ + "CVE-2023-45893" + ], + "details": "An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45893" + }, + { + "type": "WEB", + "url": "https://github.com/Oracle-Security/CVEs/blob/main/FloorsightSoftware/CVE-2023-45893.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-89vh-9hfj-x469/GHSA-89vh-9hfj-x469.json b/advisories/unreviewed/2024/01/GHSA-89vh-9hfj-x469/GHSA-89vh-9hfj-x469.json new file mode 100644 index 00000000000..86ed55461b7 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-89vh-9hfj-x469/GHSA-89vh-9hfj-x469.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89vh-9hfj-x469", + "modified": "2024-01-02T21:30:26Z", + "published": "2024-01-02T21:30:26Z", + "aliases": [ + "CVE-2023-47458" + ], + "details": "An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47458" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Mr-F0reigner/b05487f5ca52d17e214fffd6e1e0312a" + }, + { + "type": "WEB", + "url": "https://gitee.com/smallc/SpringBlade" + }, + { + "type": "WEB", + "url": "http://springblade.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-fx3r-r9g3-mv57/GHSA-fx3r-r9g3-mv57.json b/advisories/unreviewed/2024/01/GHSA-fx3r-r9g3-mv57/GHSA-fx3r-r9g3-mv57.json new file mode 100644 index 00000000000..ecae33fe48b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fx3r-r9g3-mv57/GHSA-fx3r-r9g3-mv57.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx3r-r9g3-mv57", + "modified": "2024-01-02T21:30:25Z", + "published": "2024-01-02T21:30:25Z", + "aliases": [ + "CVE-2024-0190" + ], + "details": "A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0 and classified as problematic. This issue affects some unknown processing of the file add_quiz.php of the component Quiz Handler. The manipulation of the argument Quiz Title/Quiz Description with the input leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249503.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0190" + }, + { + "type": "WEB", + "url": "https://mega.nz/file/HANhAKyT#lGcBglLDU3LDdfJsri3vYgnwn5amW8gvdOxbbYjAwJw" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249503" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249503" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jjjw-x8pv-g64q/GHSA-jjjw-x8pv-g64q.json b/advisories/unreviewed/2024/01/GHSA-jjjw-x8pv-g64q/GHSA-jjjw-x8pv-g64q.json new file mode 100644 index 00000000000..65b5bd1bd95 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jjjw-x8pv-g64q/GHSA-jjjw-x8pv-g64q.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjjw-x8pv-g64q", + "modified": "2024-01-02T21:30:26Z", + "published": "2024-01-02T21:30:26Z", + "aliases": [ + "CVE-2023-45561" + ], + "details": "An issue in A-WORLD OIRASE BEER_waiting Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45561" + }, + { + "type": "WEB", + "url": "https://github.com/syz913/CVE-reports/blob/main/CVE-2023-45561.md" + }, + { + "type": "WEB", + "url": "http://a-world.com" + }, + { + "type": "WEB", + "url": "http://oirase.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-m6pc-42rj-wc4v/GHSA-m6pc-42rj-wc4v.json b/advisories/unreviewed/2024/01/GHSA-m6pc-42rj-wc4v/GHSA-m6pc-42rj-wc4v.json new file mode 100644 index 00000000000..b8f19147ef0 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-m6pc-42rj-wc4v/GHSA-m6pc-42rj-wc4v.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6pc-42rj-wc4v", + "modified": "2024-01-02T21:30:26Z", + "published": "2024-01-02T21:30:26Z", + "aliases": [ + "CVE-2024-0195" + ], + "details": "A vulnerability, which was classified as critical, was found in spider-flow 0.4.3. Affected is the function FunctionService.saveFunction of the file src/main/java/org/spiderflow/controller/FunctionController.java. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-249510 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0195" + }, + { + "type": "WEB", + "url": "https://github.com/laoquanshi/puppy/blob/main/spider-flow%20code%20injection%20causes%20rce.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249510" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249510" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-mmc5-hgpc-m8q5/GHSA-mmc5-hgpc-m8q5.json b/advisories/unreviewed/2024/01/GHSA-mmc5-hgpc-m8q5/GHSA-mmc5-hgpc-m8q5.json new file mode 100644 index 00000000000..fd7c576cdd0 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-mmc5-hgpc-m8q5/GHSA-mmc5-hgpc-m8q5.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmc5-hgpc-m8q5", + "modified": "2024-01-02T21:30:25Z", + "published": "2024-01-02T21:30:25Z", + "aliases": [ + "CVE-2023-7192" + ], + "details": "A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kernel. This issue may allow a local attacker with CAP_NET_ADMIN privileges to cause a denial of service (DoS) attack due to a refcount overflow.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7192" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-7192" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2256279" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=ac4893980bbe79ce383daf9a0885666a30fe4c83" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-402" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-p4x5-xm4x-p99c/GHSA-p4x5-xm4x-p99c.json b/advisories/unreviewed/2024/01/GHSA-p4x5-xm4x-p99c/GHSA-p4x5-xm4x-p99c.json new file mode 100644 index 00000000000..7bc7240d19e --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-p4x5-xm4x-p99c/GHSA-p4x5-xm4x-p99c.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4x5-xm4x-p99c", + "modified": "2024-01-02T21:30:26Z", + "published": "2024-01-02T21:30:26Z", + "aliases": [ + "CVE-2024-0192" + ], + "details": "A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file downloadable.php of the component Add Downloadable. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249505 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0192" + }, + { + "type": "WEB", + "url": "https://mega.nz/file/2RNnjDTR#nDT4E74juKhdO3eWTv8VjDD2dDcNUzyAk2UR3psM8rM" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249505" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249505" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T20:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-p5jr-rfj3-98f5/GHSA-p5jr-rfj3-98f5.json b/advisories/unreviewed/2024/01/GHSA-p5jr-rfj3-98f5/GHSA-p5jr-rfj3-98f5.json new file mode 100644 index 00000000000..e43d9eead36 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-p5jr-rfj3-98f5/GHSA-p5jr-rfj3-98f5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5jr-rfj3-98f5", + "modified": "2024-01-02T21:30:26Z", + "published": "2024-01-02T21:30:26Z", + "aliases": [ + "CVE-2023-45892" + ], + "details": "An issue discovered in the Order and Invoice pages in Floorsight Insights Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45892" + }, + { + "type": "WEB", + "url": "https://github.com/Oracle-Security/CVEs/blob/main/FloorsightSoftware/CVE-2023-45892.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-w9r4-6f5q-p5h9/GHSA-w9r4-6f5q-p5h9.json b/advisories/unreviewed/2024/01/GHSA-w9r4-6f5q-p5h9/GHSA-w9r4-6f5q-p5h9.json new file mode 100644 index 00000000000..bc8d9851fd2 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-w9r4-6f5q-p5h9/GHSA-w9r4-6f5q-p5h9.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9r4-6f5q-p5h9", + "modified": "2024-01-02T21:30:26Z", + "published": "2024-01-02T21:30:26Z", + "aliases": [ + "CVE-2024-0191" + ], + "details": "A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/uploads/. The manipulation leads to file and directory information exposure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249504.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0191" + }, + { + "type": "WEB", + "url": "https://mega.nz/file/uZt00bIA#uqwP2WkWK5kbKOUbRrgbZY4_-4enuhFw5O9LtJ_cclY" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249504" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249504" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-538" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T20:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-x5gw-mqgf-fwh3/GHSA-x5gw-mqgf-fwh3.json b/advisories/unreviewed/2024/01/GHSA-x5gw-mqgf-fwh3/GHSA-x5gw-mqgf-fwh3.json new file mode 100644 index 00000000000..3c585fd0ba1 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-x5gw-mqgf-fwh3/GHSA-x5gw-mqgf-fwh3.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5gw-mqgf-fwh3", + "modified": "2024-01-02T21:30:25Z", + "published": "2024-01-02T21:30:25Z", + "aliases": [ + "CVE-2022-3010" + ], + "details": "The Priva TopControl Suite contains predictable credentials for the SSH service, based on the Serial number. Which makes it possible for an attacker to calculate the login credentials for the Priva TopControll suite.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3010" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/CVE-2022-3010" + }, + { + "type": "WEB", + "url": "https://csirt.divd.nl/DIVD-2022-00035" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-22-356-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1391" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T19:15:09Z" + } +} \ No newline at end of file