Publish Advisories

GHSA-45c3-c4c3-8rqg
GHSA-p46g-8c3q-89p2
GHSA-v9q5-9crp-92f9
GHSA-wwfj-h843-3hrq
This commit is contained in:
advisory-database[bot]
2023-09-25 21:42:55 +00:00
parent 1862776d67
commit 6aa5f6e453
4 changed files with 26 additions and 14 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-45c3-c4c3-8rqg",
"modified": "2023-09-22T17:08:32Z",
"modified": "2023-09-25T21:41:37Z",
"published": "2023-09-22T00:30:29Z",
"aliases": [
"CVE-2023-31716"
@@ -9,7 +9,10 @@
"summary": "FUXA vulnerable to Local File Inclusion",
"details": "FUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
{
@@ -55,7 +58,7 @@
"cwe_ids": [
],
"severity": "MODERATE",
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2023-09-22T17:08:32Z",
"nvd_published_at": null
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p46g-8c3q-89p2",
"modified": "2023-09-22T20:00:24Z",
"modified": "2023-09-25T21:42:11Z",
"published": "2023-09-22T00:30:29Z",
"aliases": [
"CVE-2023-31719"
@@ -9,7 +9,10 @@
"summary": "FUXA SQL Injection vulnerability",
"details": "FUXA <= 1.1.12 is vulnerable to SQL Injection via `/api/signin`.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
{
@@ -57,9 +60,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2023-09-22T20:00:24Z",
"nvd_published_at": null
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v9q5-9crp-92f9",
"modified": "2023-09-22T20:00:27Z",
"modified": "2023-09-25T21:41:49Z",
"published": "2023-09-22T00:30:29Z",
"aliases": [
"CVE-2023-31717"
@@ -9,7 +9,10 @@
"summary": "FUXA SQL Injection vulnerability",
"details": "A SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the database.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
{
@@ -57,9 +60,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2023-09-22T20:00:27Z",
"nvd_published_at": null
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wwfj-h843-3hrq",
"modified": "2023-09-22T20:00:26Z",
"modified": "2023-09-25T21:42:01Z",
"published": "2023-09-22T00:30:29Z",
"aliases": [
"CVE-2023-31718"
@@ -9,7 +9,10 @@
"summary": "FUXA local file inclusion vulnerability",
"details": "FUXA <= 1.1.12 is vulnerable to Local File Inclusion via `/api/download`.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
{
@@ -59,7 +62,7 @@
"cwe_ids": [
],
"severity": "MODERATE",
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2023-09-22T20:00:26Z",
"nvd_published_at": null