Publish Advisories

GHSA-6m93-gmrj-jf29
GHSA-7xrf-xg7m-8rqp
GHSA-pq5r-rp8m-p9vh
GHSA-qc99-r4wh-c8h6
GHSA-rhp6-2jj3-53p2
GHSA-rjwj-693g-mq28
GHSA-rvqv-q989-mj4r
GHSA-vpm2-jf87-f6fp
GHSA-w8qj-646m-h2rw
GHSA-wwmq-47hw-c7vw
This commit is contained in:
advisory-database[bot]
2024-03-29 00:32:00 +00:00
parent e0468b66c8
commit 6e59ef9635
10 changed files with 380 additions and 1 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6m93-gmrj-jf29",
"modified": "2024-01-29T18:31:48Z",
"modified": "2024-03-29T00:30:34Z",
"published": "2024-01-25T21:32:15Z",
"aliases": [
"CVE-2024-24399"
@@ -21,9 +21,17 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24399"
},
{
"type": "WEB",
"url": "https://github.com/capture0x/leptoncms"
},
{
"type": "WEB",
"url": "https://github.com/capture0x/leptoncms/blob/main/README.md"
},
{
"type": "WEB",
"url": "https://packetstormsecurity.com/files/176647/Lepton-CMS-7.0.0-Remote-Code-Execution.html"
}
],
"database_specific": {
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7xrf-xg7m-8rqp",
"modified": "2024-03-29T00:30:34Z",
"published": "2024-03-29T00:30:34Z",
"aliases": [
"CVE-2024-28456"
],
"details": "Cross Site Scripting vulnerability in Campcodes Online Marriage Registration System v.1.0 allows a remote attacker to execute arbitrary code via the text fields in the marriage registration request form.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28456"
},
{
"type": "WEB",
"url": "https://drive.google.com/file/d/1J3-mKlXpHYqOwlUyffRT-ibWa0joB3xC/view?usp=sharing"
},
{
"type": "WEB",
"url": "https://pastebin.com/CYMDR4ss"
},
{
"type": "WEB",
"url": "https://www.campcodes.com/projects/php/online-marriage-registration-system"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-28T23:15:46Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pq5r-rp8m-p9vh",
"modified": "2024-03-29T00:30:35Z",
"published": "2024-03-29T00:30:35Z",
"aliases": [
"CVE-2024-29489"
],
"details": "Jerryscript 2.4.0 has SEGV at ./jerry-core/ecma/base/ecma-helpers.c:238:58 in ecma_get_object_type.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29489"
},
{
"type": "WEB",
"url": "https://github.com/jerryscript-project/jerryscript/issues/5101"
},
{
"type": "WEB",
"url": "https://github.com/jerryscript-project/jerryscript/pull/5129"
},
{
"type": "WEB",
"url": "https://github.com/jerryscript-project/jerryscript/commit/cefd391772529c8a9531d7b3c244d78d38be47c6"
},
{
"type": "WEB",
"url": "https://gist.github.com/gandalf4a/9826a897ae1e3c8d1c7e71a1ec71d415"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-28T23:15:46Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qc99-r4wh-c8h6",
"modified": "2024-03-29T00:30:34Z",
"published": "2024-03-29T00:30:34Z",
"aliases": [
"CVE-2024-29316"
],
"details": "NodeBB 3.6.7 is vulnerable to Incorrect Access Control.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29316"
},
{
"type": "WEB",
"url": "https://medium.com/%40krityamkarma858041/broken-access-control-nodebb-v3-6-7-eebc59c24deb"
},
{
"type": "WEB",
"url": "https://nodebb.org/bounty"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-28T23:15:46Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rhp6-2jj3-53p2",
"modified": "2024-03-29T00:30:34Z",
"published": "2024-03-29T00:30:34Z",
"aliases": [
"CVE-2024-28714"
],
"details": "SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28714"
},
{
"type": "WEB",
"url": "https://gitee.com/ZhongBangKeJi/crmeb_java"
},
{
"type": "WEB",
"url": "https://github.com/JiangXiaoBaiJia/cve2/blob/main/1.md"
},
{
"type": "WEB",
"url": "https://github.com/JiangXiaoBaiJia/cve2/blob/main/a.png"
},
{
"type": "WEB",
"url": "http://crmebjava.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-28T23:15:46Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rjwj-693g-mq28",
"modified": "2024-03-29T00:30:34Z",
"published": "2024-03-29T00:30:34Z",
"aliases": [
"CVE-2023-50969"
],
"details": "Thales Imperva SecureSphere WAF 14.7.0.40 allows remote attackers to bypass WAF rules via a crafted POST request, a different vulnerability than CVE-2021-45468.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50969"
},
{
"type": "WEB",
"url": "https://docs.imperva.com/bundle/v14.7-waf-administration-guide/page/9282.htm"
},
{
"type": "WEB",
"url": "https://www.hoyahaxa.com/2024/03/imperva-waf-bypass-cve-2023-50969.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-28T23:15:46Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rvqv-q989-mj4r",
"modified": "2024-03-29T00:30:34Z",
"published": "2024-03-29T00:30:34Z",
"aliases": [
"CVE-2023-25341"
],
"details": "A Directory Traversal vulnerability in ladle dev server 2.5.1 and earlier allows an attacker on the same network to read files accessible to the user via GET requests.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25341"
},
{
"type": "WEB",
"url": "https://www.runjak.codes/posts/2024-03-21-ladle-cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-28T22:15:09Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vpm2-jf87-f6fp",
"modified": "2024-03-29T00:30:34Z",
"published": "2024-03-29T00:30:34Z",
"aliases": [
"CVE-2024-24407"
],
"details": "SQL Injection vulnerability in Best Courier management system v.1.0 allows a remote attacker to obtain sensitive information via print_pdets.php component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24407"
},
{
"type": "WEB",
"url": "https://github.com/modian-un/CVE/blob/main/Barangay%20Population%20Monitoring%20System.md"
},
{
"type": "WEB",
"url": "https://github.com/modian-un/CVE/blob/main/Best%20courier%20management%20system.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-28T23:15:46Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w8qj-646m-h2rw",
"modified": "2024-03-29T00:30:34Z",
"published": "2024-03-29T00:30:34Z",
"aliases": [
"CVE-2021-31156"
],
"details": "Allied Telesis AT-S115 1.2.0 devices before 1.00.024 with Boot Loader 1.00.006 allow Directory Traversal to achieve partial access to data.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31156"
},
{
"type": "WEB",
"url": "https://gist.github.com/NitescuLucian/69cf22d17bf190325118304be04828e8"
},
{
"type": "WEB",
"url": "https://www.alliedtelesis.com/en/documents/software-release-notes-s115-v120"
},
{
"type": "WEB",
"url": "https://www.alliedtelesis.com/sites/default/files/documents/release-notes/ats115v120srna.pdf"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-28T23:15:45Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wwmq-47hw-c7vw",
"modified": "2024-03-29T00:30:34Z",
"published": "2024-03-29T00:30:34Z",
"aliases": [
"CVE-2023-33528"
],
"details": "halo v1.6.0 is vulnerable to Cross Site Scripting (XSS).",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33528"
},
{
"type": "WEB",
"url": "https://gist.github.com/alert-moyan/be0bd087d85c1416829b8e9659e8b66c"
},
{
"type": "WEB",
"url": "https://github.com/halo-dev/halo/releases/tag/v1.6.0"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-28T23:15:46Z"
}
}