From 643261cbfceacbd9c5d3fc59b1c086d3672a89ea Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 27 Dec 2024 06:32:06 +0000 Subject: [PATCH] Publish Advisories GHSA-424r-4x2h-9rv9 GHSA-44f8-jm5j-7x8w GHSA-4p8j-vhjm-6pvw GHSA-4pwr-w5vw-hxjv GHSA-5jw5-2rj7-x547 GHSA-9mgx-552f-59p6 GHSA-grhh-r4jj-8jh7 GHSA-h4j7-x8cq-c6wq GHSA-j2hp-7hfp-x96x GHSA-j376-8r6p-32f7 GHSA-m7mh-v3gj-99xr GHSA-m7pm-65hr-r8px GHSA-qx95-cwh6-9mvq GHSA-w95c-7994-ghpr GHSA-wvc7-xrqm-jhp5 --- .../GHSA-424r-4x2h-9rv9.json | 56 +++++++++++++++++++ .../GHSA-44f8-jm5j-7x8w.json | 56 +++++++++++++++++++ .../GHSA-4p8j-vhjm-6pvw.json | 37 ++++++++++++ .../GHSA-4pwr-w5vw-hxjv.json | 29 ++++++++++ .../GHSA-5jw5-2rj7-x547.json | 29 ++++++++++ .../GHSA-9mgx-552f-59p6.json | 39 +++++++++++++ .../GHSA-grhh-r4jj-8jh7.json | 45 +++++++++++++++ .../GHSA-h4j7-x8cq-c6wq.json | 56 +++++++++++++++++++ .../GHSA-j2hp-7hfp-x96x.json | 56 +++++++++++++++++++ .../GHSA-j376-8r6p-32f7.json | 29 ++++++++++ .../GHSA-m7mh-v3gj-99xr.json | 29 ++++++++++ .../GHSA-m7pm-65hr-r8px.json | 29 ++++++++++ .../GHSA-qx95-cwh6-9mvq.json | 37 ++++++++++++ .../GHSA-w95c-7994-ghpr.json | 41 ++++++++++++++ .../GHSA-wvc7-xrqm-jhp5.json | 52 +++++++++++++++++ 15 files changed, 620 insertions(+) create mode 100644 advisories/unreviewed/2024/12/GHSA-424r-4x2h-9rv9/GHSA-424r-4x2h-9rv9.json create mode 100644 advisories/unreviewed/2024/12/GHSA-44f8-jm5j-7x8w/GHSA-44f8-jm5j-7x8w.json create mode 100644 advisories/unreviewed/2024/12/GHSA-4p8j-vhjm-6pvw/GHSA-4p8j-vhjm-6pvw.json create mode 100644 advisories/unreviewed/2024/12/GHSA-4pwr-w5vw-hxjv/GHSA-4pwr-w5vw-hxjv.json create mode 100644 advisories/unreviewed/2024/12/GHSA-5jw5-2rj7-x547/GHSA-5jw5-2rj7-x547.json create mode 100644 advisories/unreviewed/2024/12/GHSA-9mgx-552f-59p6/GHSA-9mgx-552f-59p6.json create mode 100644 advisories/unreviewed/2024/12/GHSA-grhh-r4jj-8jh7/GHSA-grhh-r4jj-8jh7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-h4j7-x8cq-c6wq/GHSA-h4j7-x8cq-c6wq.json create mode 100644 advisories/unreviewed/2024/12/GHSA-j2hp-7hfp-x96x/GHSA-j2hp-7hfp-x96x.json create mode 100644 advisories/unreviewed/2024/12/GHSA-j376-8r6p-32f7/GHSA-j376-8r6p-32f7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-m7mh-v3gj-99xr/GHSA-m7mh-v3gj-99xr.json create mode 100644 advisories/unreviewed/2024/12/GHSA-m7pm-65hr-r8px/GHSA-m7pm-65hr-r8px.json create mode 100644 advisories/unreviewed/2024/12/GHSA-qx95-cwh6-9mvq/GHSA-qx95-cwh6-9mvq.json create mode 100644 advisories/unreviewed/2024/12/GHSA-w95c-7994-ghpr/GHSA-w95c-7994-ghpr.json create mode 100644 advisories/unreviewed/2024/12/GHSA-wvc7-xrqm-jhp5/GHSA-wvc7-xrqm-jhp5.json diff --git a/advisories/unreviewed/2024/12/GHSA-424r-4x2h-9rv9/GHSA-424r-4x2h-9rv9.json b/advisories/unreviewed/2024/12/GHSA-424r-4x2h-9rv9/GHSA-424r-4x2h-9rv9.json new file mode 100644 index 00000000000..1fcaa6f72e1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-424r-4x2h-9rv9/GHSA-424r-4x2h-9rv9.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-424r-4x2h-9rv9", + "modified": "2024-12-27T06:30:48Z", + "published": "2024-12-27T06:30:48Z", + "aliases": [ + "CVE-2024-12981" + ], + "details": "A vulnerability was found in CodeAstro Car Rental System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /bookingconfirm.php. The manipulation of the argument driver_id_from_dropdown leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12981" + }, + { + "type": "WEB", + "url": "https://github.com/CharilYang/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://codeastro.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289357" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289357" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.469156" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T06:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-44f8-jm5j-7x8w/GHSA-44f8-jm5j-7x8w.json b/advisories/unreviewed/2024/12/GHSA-44f8-jm5j-7x8w/GHSA-44f8-jm5j-7x8w.json new file mode 100644 index 00000000000..d5b27d9f7c1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-44f8-jm5j-7x8w/GHSA-44f8-jm5j-7x8w.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44f8-jm5j-7x8w", + "modified": "2024-12-27T06:30:46Z", + "published": "2024-12-27T06:30:46Z", + "aliases": [ + "CVE-2024-12978" + ], + "details": "A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as critical. This vulnerability affects the function add_req of the file /_parse/_all_edits.php. The manipulation of the argument jid/limit leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12978" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/UnrealdDei/cve/blob/main/sql7.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289354" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289354" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.469145" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T04:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4p8j-vhjm-6pvw/GHSA-4p8j-vhjm-6pvw.json b/advisories/unreviewed/2024/12/GHSA-4p8j-vhjm-6pvw/GHSA-4p8j-vhjm-6pvw.json new file mode 100644 index 00000000000..be255b4fdc0 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4p8j-vhjm-6pvw/GHSA-4p8j-vhjm-6pvw.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p8j-vhjm-6pvw", + "modified": "2024-12-27T06:30:47Z", + "published": "2024-12-27T06:30:47Z", + "aliases": [ + "CVE-2024-56519" + ], + "details": "An issue was discovered in TCPDF before 6.8.0. setSVGStyles does not sanitize the SVG font-family attribute.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56519" + }, + { + "type": "WEB", + "url": "https://github.com/tecnickcom/TCPDF/commit/c9f41cbb84880bdb4fc3e0a9d287214d1ac4d7f4" + }, + { + "type": "WEB", + "url": "https://github.com/tecnickcom/TCPDF/compare/6.7.8...6.8.0" + }, + { + "type": "WEB", + "url": "https://tcpdf.org" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4pwr-w5vw-hxjv/GHSA-4pwr-w5vw-hxjv.json b/advisories/unreviewed/2024/12/GHSA-4pwr-w5vw-hxjv/GHSA-4pwr-w5vw-hxjv.json new file mode 100644 index 00000000000..74557b19b25 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4pwr-w5vw-hxjv/GHSA-4pwr-w5vw-hxjv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pwr-w5vw-hxjv", + "modified": "2024-12-27T06:30:48Z", + "published": "2024-12-27T06:30:48Z", + "aliases": [ + "CVE-2024-11645" + ], + "details": "The float block WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11645" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/7771a76b-bc8c-426f-a125-5bd74ccf2845" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T06:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-5jw5-2rj7-x547/GHSA-5jw5-2rj7-x547.json b/advisories/unreviewed/2024/12/GHSA-5jw5-2rj7-x547/GHSA-5jw5-2rj7-x547.json new file mode 100644 index 00000000000..18d60d5ed0f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-5jw5-2rj7-x547/GHSA-5jw5-2rj7-x547.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jw5-2rj7-x547", + "modified": "2024-12-27T06:30:48Z", + "published": "2024-12-27T06:30:48Z", + "aliases": [ + "CVE-2024-11921" + ], + "details": "The GiveWP WordPress plugin before 3.19.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11921" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/5f196294-5ba9-45b6-a27c-ab1702cc001f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T06:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-9mgx-552f-59p6/GHSA-9mgx-552f-59p6.json b/advisories/unreviewed/2024/12/GHSA-9mgx-552f-59p6/GHSA-9mgx-552f-59p6.json new file mode 100644 index 00000000000..88ee6ea2020 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-9mgx-552f-59p6/GHSA-9mgx-552f-59p6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mgx-552f-59p6", + "modified": "2024-12-27T06:30:47Z", + "published": "2024-12-27T06:30:47Z", + "aliases": [ + "CVE-2024-56521" + ], + "details": "An issue was discovered in TCPDF before 6.8.0. If libcurl is used, CURLOPT_SSL_VERIFYHOST and CURLOPT_SSL_VERIFYPEER are set unsafely.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56521" + }, + { + "type": "WEB", + "url": "https://github.com/tecnickcom/TCPDF/commit/aab43ab0a824e956276141a28a24c7c0be20f554" + }, + { + "type": "WEB", + "url": "https://github.com/tecnickcom/TCPDF/compare/6.7.8...6.8.0" + }, + { + "type": "WEB", + "url": "https://tcpdf.org" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-grhh-r4jj-8jh7/GHSA-grhh-r4jj-8jh7.json b/advisories/unreviewed/2024/12/GHSA-grhh-r4jj-8jh7/GHSA-grhh-r4jj-8jh7.json new file mode 100644 index 00000000000..d3ba4b83a61 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-grhh-r4jj-8jh7/GHSA-grhh-r4jj-8jh7.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grhh-r4jj-8jh7", + "modified": "2024-12-27T06:30:47Z", + "published": "2024-12-27T06:30:47Z", + "aliases": [ + "CVE-2024-56520" + ], + "details": "An issue was discovered in tc-lib-pdf-font before 2.6.4, as used in TCPDF before 6.8.0 and other products. Fonts are mishandled, e.g., FontBBox for Type 1 and TrueType fonts is misparsed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56520" + }, + { + "type": "WEB", + "url": "https://github.com/tecnickcom/TCPDF/commit/a0a02efe487cc39bd5223359e916dbeafb5cd6fe" + }, + { + "type": "WEB", + "url": "https://github.com/tecnickcom/tc-lib-pdf-font/commit/30012e333ae611c514ec2dc7cb370bbf4da4e677" + }, + { + "type": "WEB", + "url": "https://github.com/tecnickcom/TCPDF/compare/6.7.8...6.8.0" + }, + { + "type": "WEB", + "url": "https://github.com/tecnickcom/tc-lib-pdf-font/compare/2.6.2...2.6.4" + }, + { + "type": "WEB", + "url": "https://tcpdf.org" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-h4j7-x8cq-c6wq/GHSA-h4j7-x8cq-c6wq.json b/advisories/unreviewed/2024/12/GHSA-h4j7-x8cq-c6wq/GHSA-h4j7-x8cq-c6wq.json new file mode 100644 index 00000000000..262cd3571ca --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-h4j7-x8cq-c6wq/GHSA-h4j7-x8cq-c6wq.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4j7-x8cq-c6wq", + "modified": "2024-12-27T06:30:47Z", + "published": "2024-12-27T06:30:47Z", + "aliases": [ + "CVE-2024-12979" + ], + "details": "A vulnerability was found in code-projects Job Recruitment 1.0 and classified as problematic. This issue affects the function cn_update of the file /_parse/_all_edits.php. The manipulation of the argument cname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12979" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/705298066/cve/blob/main/xss-1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289355" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289355" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.469180" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j2hp-7hfp-x96x/GHSA-j2hp-7hfp-x96x.json b/advisories/unreviewed/2024/12/GHSA-j2hp-7hfp-x96x/GHSA-j2hp-7hfp-x96x.json new file mode 100644 index 00000000000..f6a5aadc46f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j2hp-7hfp-x96x/GHSA-j2hp-7hfp-x96x.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2hp-7hfp-x96x", + "modified": "2024-12-27T06:30:47Z", + "published": "2024-12-27T06:30:47Z", + "aliases": [ + "CVE-2024-12980" + ], + "details": "A vulnerability was found in code-projects Job Recruitment 1.0. It has been classified as problematic. Affected is the function fln_update of the file /_parse/_all_edits.php. The manipulation of the argument fname/lname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12980" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/705298066/cve/blob/main/xss-2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289356" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289356" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.469181" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T05:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-j376-8r6p-32f7/GHSA-j376-8r6p-32f7.json b/advisories/unreviewed/2024/12/GHSA-j376-8r6p-32f7/GHSA-j376-8r6p-32f7.json new file mode 100644 index 00000000000..f586784f124 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-j376-8r6p-32f7/GHSA-j376-8r6p-32f7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j376-8r6p-32f7", + "modified": "2024-12-27T06:30:48Z", + "published": "2024-12-27T06:30:48Z", + "aliases": [ + "CVE-2024-11842" + ], + "details": "The DN Shipping by Weight for WooCommerce WordPress plugin before 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11842" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/2545f054-b6ca-4ee5-ac6f-f42193db21b1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T06:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m7mh-v3gj-99xr/GHSA-m7mh-v3gj-99xr.json b/advisories/unreviewed/2024/12/GHSA-m7mh-v3gj-99xr/GHSA-m7mh-v3gj-99xr.json new file mode 100644 index 00000000000..2a1bc07904b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m7mh-v3gj-99xr/GHSA-m7mh-v3gj-99xr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7mh-v3gj-99xr", + "modified": "2024-12-27T06:30:48Z", + "published": "2024-12-27T06:30:48Z", + "aliases": [ + "CVE-2024-11644" + ], + "details": "The WP-SVG WordPress plugin through 0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11644" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/5b6a80f1-369c-4dd2-877e-60b724084819" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T06:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-m7pm-65hr-r8px/GHSA-m7pm-65hr-r8px.json b/advisories/unreviewed/2024/12/GHSA-m7pm-65hr-r8px/GHSA-m7pm-65hr-r8px.json new file mode 100644 index 00000000000..8dcd81135e3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-m7pm-65hr-r8px/GHSA-m7pm-65hr-r8px.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7pm-65hr-r8px", + "modified": "2024-12-27T06:30:47Z", + "published": "2024-12-27T06:30:47Z", + "aliases": [ + "CVE-2024-11605" + ], + "details": "The wp-publications WordPress plugin through 1.2 does not escape filenames before outputting them back in the page, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11605" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/91c5ee70-2ff5-46cd-a0f5-54987fc2e060" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T06:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-qx95-cwh6-9mvq/GHSA-qx95-cwh6-9mvq.json b/advisories/unreviewed/2024/12/GHSA-qx95-cwh6-9mvq/GHSA-qx95-cwh6-9mvq.json new file mode 100644 index 00000000000..330abbbb86f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-qx95-cwh6-9mvq/GHSA-qx95-cwh6-9mvq.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qx95-cwh6-9mvq", + "modified": "2024-12-27T06:30:48Z", + "published": "2024-12-27T06:30:48Z", + "aliases": [ + "CVE-2024-56527" + ], + "details": "An issue was discovered in TCPDF before 6.8.0. The Error function lacks an htmlspecialchars call for the error message.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56527" + }, + { + "type": "WEB", + "url": "https://github.com/tecnickcom/TCPDF/commit/11778aaa2d9e30a9ae1c1ee97ff349344f0ad6e1" + }, + { + "type": "WEB", + "url": "https://github.com/tecnickcom/TCPDF/compare/6.7.8...6.8.0" + }, + { + "type": "WEB", + "url": "https://tcpdf.org" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T06:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-w95c-7994-ghpr/GHSA-w95c-7994-ghpr.json b/advisories/unreviewed/2024/12/GHSA-w95c-7994-ghpr/GHSA-w95c-7994-ghpr.json new file mode 100644 index 00000000000..bf9073503a7 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-w95c-7994-ghpr/GHSA-w95c-7994-ghpr.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w95c-7994-ghpr", + "modified": "2024-12-27T06:30:48Z", + "published": "2024-12-27T06:30:48Z", + "aliases": [ + "CVE-2024-56522" + ], + "details": "An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a constant-time function to compare TCPDF tag hashes.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56522" + }, + { + "type": "WEB", + "url": "https://github.com/tecnickcom/TCPDF/commit/d54b97cec33f4f1a5ad81119a82085cad93cec89" + }, + { + "type": "WEB", + "url": "https://github.com/tecnickcom/TCPDF/compare/6.7.8...6.8.0" + }, + { + "type": "WEB", + "url": "https://tcpdf.org" + }, + { + "type": "WEB", + "url": "https://www.php.net/manual/en/types.comparisons.php" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T05:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-wvc7-xrqm-jhp5/GHSA-wvc7-xrqm-jhp5.json b/advisories/unreviewed/2024/12/GHSA-wvc7-xrqm-jhp5/GHSA-wvc7-xrqm-jhp5.json new file mode 100644 index 00000000000..0f11e3600c3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-wvc7-xrqm-jhp5/GHSA-wvc7-xrqm-jhp5.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvc7-xrqm-jhp5", + "modified": "2024-12-27T06:30:48Z", + "published": "2024-12-27T06:30:48Z", + "aliases": [ + "CVE-2024-12982" + ], + "details": "A vulnerability was found in PHPGurukul Blood Bank & Donor Management System 2.4. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /bbdms/admin/update-contactinfo.php. The manipulation of the argument Address leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12982" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289358" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289358" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.469202" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-27T06:15:23Z" + } +} \ No newline at end of file