Publish Advisories

GHSA-22p6-c9vr-pq5x
GHSA-53mw-3q46-v8vp
GHSA-5h7p-2q7c-v7w8
GHSA-g93h-34rm-55x7
GHSA-gcp5-jr9j-3744
GHSA-mwjr-jwf4-2g7p
GHSA-v38j-rpc7-4g25
This commit is contained in:
advisory-database[bot]
2024-06-02 15:32:11 +00:00
parent 16c6bd07d3
commit 6b3e02f021
7 changed files with 278 additions and 0 deletions
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-22p6-c9vr-pq5x",
"modified": "2024-06-02T15:30:37Z",
"published": "2024-06-02T15:30:37Z",
"aliases": [
"CVE-2024-36392"
],
"details": "MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36392"
},
{
"type": "WEB",
"url": "https://www.gov.il/en/Departments/faq/cve_advisories"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-02T14:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-53mw-3q46-v8vp",
"modified": "2024-06-02T15:30:37Z",
"published": "2024-06-02T15:30:37Z",
"aliases": [
"CVE-2024-36390"
],
"details": "MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36390"
},
{
"type": "WEB",
"url": "https://www.gov.il/en/Departments/faq/cve_advisories"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-02T14:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5h7p-2q7c-v7w8",
"modified": "2024-06-02T15:30:37Z",
"published": "2024-06-02T15:30:37Z",
"aliases": [
"CVE-2024-36391"
],
"details": "MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36391"
},
{
"type": "WEB",
"url": "https://www.gov.il/en/Departments/faq/cve_advisories"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-02T14:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g93h-34rm-55x7",
"modified": "2024-06-02T15:30:36Z",
"published": "2024-06-02T15:30:36Z",
"aliases": [
"CVE-2024-27776"
],
"details": "MileSight DeviceHub - \n\nCWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow Unauthenticated RCE",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27776"
},
{
"type": "WEB",
"url": "https://www.gov.il/en/Departments/faq/cve_advisories"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-02T13:15:08Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gcp5-jr9j-3744",
"modified": "2024-06-02T15:30:37Z",
"published": "2024-06-02T15:30:37Z",
"aliases": [
"CVE-2024-5588"
],
"details": "A vulnerability was found in itsourcecode Learning Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file processscore.php. The manipulation of the argument LessonID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266839.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5588"
},
{
"type": "WEB",
"url": "https://github.com/Lanxiy7th/lx_CVE_report-/issues/12"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.266839"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.266839"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.347576"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-02T15:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mwjr-jwf4-2g7p",
"modified": "2024-06-02T15:30:37Z",
"published": "2024-06-02T15:30:36Z",
"aliases": [
"CVE-2024-36389"
],
"details": "MileSight DeviceHub - \n\n\n\n\n\nCWE-330 Use of Insufficiently Random Values may allow Authentication Bypass",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36389"
},
{
"type": "WEB",
"url": "https://www.gov.il/en/Departments/faq/cve_advisories"
}
],
"database_specific": {
"cwe_ids": [
"CWE-330"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-02T14:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v38j-rpc7-4g25",
"modified": "2024-06-02T15:30:36Z",
"published": "2024-06-02T15:30:36Z",
"aliases": [
"CVE-2024-36388"
],
"details": "MileSight DeviceHub - \n\n\n\nCWE-305 Missing Authentication for Critical Function",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36388"
},
{
"type": "WEB",
"url": "https://www.gov.il/en/Departments/faq/cve_advisories"
}
],
"database_specific": {
"cwe_ids": [
"CWE-305"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-02T14:15:08Z"
}
}