From 6e59ef9635b0481d696caa1007617446a79f7a9a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 29 Mar 2024 00:32:00 +0000 Subject: [PATCH] Publish Advisories GHSA-6m93-gmrj-jf29 GHSA-7xrf-xg7m-8rqp GHSA-pq5r-rp8m-p9vh GHSA-qc99-r4wh-c8h6 GHSA-rhp6-2jj3-53p2 GHSA-rjwj-693g-mq28 GHSA-rvqv-q989-mj4r GHSA-vpm2-jf87-f6fp GHSA-w8qj-646m-h2rw GHSA-wwmq-47hw-c7vw --- .../GHSA-6m93-gmrj-jf29.json | 10 +++- .../GHSA-7xrf-xg7m-8rqp.json | 43 +++++++++++++++++ .../GHSA-pq5r-rp8m-p9vh.json | 47 +++++++++++++++++++ .../GHSA-qc99-r4wh-c8h6.json | 39 +++++++++++++++ .../GHSA-rhp6-2jj3-53p2.json | 47 +++++++++++++++++++ .../GHSA-rjwj-693g-mq28.json | 39 +++++++++++++++ .../GHSA-rvqv-q989-mj4r.json | 35 ++++++++++++++ .../GHSA-vpm2-jf87-f6fp.json | 39 +++++++++++++++ .../GHSA-w8qj-646m-h2rw.json | 43 +++++++++++++++++ .../GHSA-wwmq-47hw-c7vw.json | 39 +++++++++++++++ 10 files changed, 380 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/03/GHSA-7xrf-xg7m-8rqp/GHSA-7xrf-xg7m-8rqp.json create mode 100644 advisories/unreviewed/2024/03/GHSA-pq5r-rp8m-p9vh/GHSA-pq5r-rp8m-p9vh.json create mode 100644 advisories/unreviewed/2024/03/GHSA-qc99-r4wh-c8h6/GHSA-qc99-r4wh-c8h6.json create mode 100644 advisories/unreviewed/2024/03/GHSA-rhp6-2jj3-53p2/GHSA-rhp6-2jj3-53p2.json create mode 100644 advisories/unreviewed/2024/03/GHSA-rjwj-693g-mq28/GHSA-rjwj-693g-mq28.json create mode 100644 advisories/unreviewed/2024/03/GHSA-rvqv-q989-mj4r/GHSA-rvqv-q989-mj4r.json create mode 100644 advisories/unreviewed/2024/03/GHSA-vpm2-jf87-f6fp/GHSA-vpm2-jf87-f6fp.json create mode 100644 advisories/unreviewed/2024/03/GHSA-w8qj-646m-h2rw/GHSA-w8qj-646m-h2rw.json create mode 100644 advisories/unreviewed/2024/03/GHSA-wwmq-47hw-c7vw/GHSA-wwmq-47hw-c7vw.json diff --git a/advisories/unreviewed/2024/01/GHSA-6m93-gmrj-jf29/GHSA-6m93-gmrj-jf29.json b/advisories/unreviewed/2024/01/GHSA-6m93-gmrj-jf29/GHSA-6m93-gmrj-jf29.json index 433f5164a1b..982e8007d00 100644 --- a/advisories/unreviewed/2024/01/GHSA-6m93-gmrj-jf29/GHSA-6m93-gmrj-jf29.json +++ b/advisories/unreviewed/2024/01/GHSA-6m93-gmrj-jf29/GHSA-6m93-gmrj-jf29.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6m93-gmrj-jf29", - "modified": "2024-01-29T18:31:48Z", + "modified": "2024-03-29T00:30:34Z", "published": "2024-01-25T21:32:15Z", "aliases": [ "CVE-2024-24399" @@ -21,9 +21,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24399" }, + { + "type": "WEB", + "url": "https://github.com/capture0x/leptoncms" + }, { "type": "WEB", "url": "https://github.com/capture0x/leptoncms/blob/main/README.md" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/176647/Lepton-CMS-7.0.0-Remote-Code-Execution.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-7xrf-xg7m-8rqp/GHSA-7xrf-xg7m-8rqp.json b/advisories/unreviewed/2024/03/GHSA-7xrf-xg7m-8rqp/GHSA-7xrf-xg7m-8rqp.json new file mode 100644 index 00000000000..67c659eee99 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7xrf-xg7m-8rqp/GHSA-7xrf-xg7m-8rqp.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xrf-xg7m-8rqp", + "modified": "2024-03-29T00:30:34Z", + "published": "2024-03-29T00:30:34Z", + "aliases": [ + "CVE-2024-28456" + ], + "details": "Cross Site Scripting vulnerability in Campcodes Online Marriage Registration System v.1.0 allows a remote attacker to execute arbitrary code via the text fields in the marriage registration request form.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28456" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1J3-mKlXpHYqOwlUyffRT-ibWa0joB3xC/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://pastebin.com/CYMDR4ss" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com/projects/php/online-marriage-registration-system" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T23:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-pq5r-rp8m-p9vh/GHSA-pq5r-rp8m-p9vh.json b/advisories/unreviewed/2024/03/GHSA-pq5r-rp8m-p9vh/GHSA-pq5r-rp8m-p9vh.json new file mode 100644 index 00000000000..24956320ed9 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-pq5r-rp8m-p9vh/GHSA-pq5r-rp8m-p9vh.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq5r-rp8m-p9vh", + "modified": "2024-03-29T00:30:35Z", + "published": "2024-03-29T00:30:35Z", + "aliases": [ + "CVE-2024-29489" + ], + "details": "Jerryscript 2.4.0 has SEGV at ./jerry-core/ecma/base/ecma-helpers.c:238:58 in ecma_get_object_type.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29489" + }, + { + "type": "WEB", + "url": "https://github.com/jerryscript-project/jerryscript/issues/5101" + }, + { + "type": "WEB", + "url": "https://github.com/jerryscript-project/jerryscript/pull/5129" + }, + { + "type": "WEB", + "url": "https://github.com/jerryscript-project/jerryscript/commit/cefd391772529c8a9531d7b3c244d78d38be47c6" + }, + { + "type": "WEB", + "url": "https://gist.github.com/gandalf4a/9826a897ae1e3c8d1c7e71a1ec71d415" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T23:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qc99-r4wh-c8h6/GHSA-qc99-r4wh-c8h6.json b/advisories/unreviewed/2024/03/GHSA-qc99-r4wh-c8h6/GHSA-qc99-r4wh-c8h6.json new file mode 100644 index 00000000000..59dbf89968d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qc99-r4wh-c8h6/GHSA-qc99-r4wh-c8h6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc99-r4wh-c8h6", + "modified": "2024-03-29T00:30:34Z", + "published": "2024-03-29T00:30:34Z", + "aliases": [ + "CVE-2024-29316" + ], + "details": "NodeBB 3.6.7 is vulnerable to Incorrect Access Control.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29316" + }, + { + "type": "WEB", + "url": "https://medium.com/%40krityamkarma858041/broken-access-control-nodebb-v3-6-7-eebc59c24deb" + }, + { + "type": "WEB", + "url": "https://nodebb.org/bounty" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T23:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rhp6-2jj3-53p2/GHSA-rhp6-2jj3-53p2.json b/advisories/unreviewed/2024/03/GHSA-rhp6-2jj3-53p2/GHSA-rhp6-2jj3-53p2.json new file mode 100644 index 00000000000..91fe1e25a08 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rhp6-2jj3-53p2/GHSA-rhp6-2jj3-53p2.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhp6-2jj3-53p2", + "modified": "2024-03-29T00:30:34Z", + "published": "2024-03-29T00:30:34Z", + "aliases": [ + "CVE-2024-28714" + ], + "details": "SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28714" + }, + { + "type": "WEB", + "url": "https://gitee.com/ZhongBangKeJi/crmeb_java" + }, + { + "type": "WEB", + "url": "https://github.com/JiangXiaoBaiJia/cve2/blob/main/1.md" + }, + { + "type": "WEB", + "url": "https://github.com/JiangXiaoBaiJia/cve2/blob/main/a.png" + }, + { + "type": "WEB", + "url": "http://crmebjava.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T23:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rjwj-693g-mq28/GHSA-rjwj-693g-mq28.json b/advisories/unreviewed/2024/03/GHSA-rjwj-693g-mq28/GHSA-rjwj-693g-mq28.json new file mode 100644 index 00000000000..8806ecf44e7 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rjwj-693g-mq28/GHSA-rjwj-693g-mq28.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjwj-693g-mq28", + "modified": "2024-03-29T00:30:34Z", + "published": "2024-03-29T00:30:34Z", + "aliases": [ + "CVE-2023-50969" + ], + "details": "Thales Imperva SecureSphere WAF 14.7.0.40 allows remote attackers to bypass WAF rules via a crafted POST request, a different vulnerability than CVE-2021-45468.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50969" + }, + { + "type": "WEB", + "url": "https://docs.imperva.com/bundle/v14.7-waf-administration-guide/page/9282.htm" + }, + { + "type": "WEB", + "url": "https://www.hoyahaxa.com/2024/03/imperva-waf-bypass-cve-2023-50969.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T23:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rvqv-q989-mj4r/GHSA-rvqv-q989-mj4r.json b/advisories/unreviewed/2024/03/GHSA-rvqv-q989-mj4r/GHSA-rvqv-q989-mj4r.json new file mode 100644 index 00000000000..912c7751512 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rvqv-q989-mj4r/GHSA-rvqv-q989-mj4r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvqv-q989-mj4r", + "modified": "2024-03-29T00:30:34Z", + "published": "2024-03-29T00:30:34Z", + "aliases": [ + "CVE-2023-25341" + ], + "details": "A Directory Traversal vulnerability in ladle dev server 2.5.1 and earlier allows an attacker on the same network to read files accessible to the user via GET requests.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25341" + }, + { + "type": "WEB", + "url": "https://www.runjak.codes/posts/2024-03-21-ladle-cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T22:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vpm2-jf87-f6fp/GHSA-vpm2-jf87-f6fp.json b/advisories/unreviewed/2024/03/GHSA-vpm2-jf87-f6fp/GHSA-vpm2-jf87-f6fp.json new file mode 100644 index 00000000000..9f4a0c34c7d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vpm2-jf87-f6fp/GHSA-vpm2-jf87-f6fp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpm2-jf87-f6fp", + "modified": "2024-03-29T00:30:34Z", + "published": "2024-03-29T00:30:34Z", + "aliases": [ + "CVE-2024-24407" + ], + "details": "SQL Injection vulnerability in Best Courier management system v.1.0 allows a remote attacker to obtain sensitive information via print_pdets.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24407" + }, + { + "type": "WEB", + "url": "https://github.com/modian-un/CVE/blob/main/Barangay%20Population%20Monitoring%20System.md" + }, + { + "type": "WEB", + "url": "https://github.com/modian-un/CVE/blob/main/Best%20courier%20management%20system.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T23:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-w8qj-646m-h2rw/GHSA-w8qj-646m-h2rw.json b/advisories/unreviewed/2024/03/GHSA-w8qj-646m-h2rw/GHSA-w8qj-646m-h2rw.json new file mode 100644 index 00000000000..2677434b7fd --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-w8qj-646m-h2rw/GHSA-w8qj-646m-h2rw.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8qj-646m-h2rw", + "modified": "2024-03-29T00:30:34Z", + "published": "2024-03-29T00:30:34Z", + "aliases": [ + "CVE-2021-31156" + ], + "details": "Allied Telesis AT-S115 1.2.0 devices before 1.00.024 with Boot Loader 1.00.006 allow Directory Traversal to achieve partial access to data.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31156" + }, + { + "type": "WEB", + "url": "https://gist.github.com/NitescuLucian/69cf22d17bf190325118304be04828e8" + }, + { + "type": "WEB", + "url": "https://www.alliedtelesis.com/en/documents/software-release-notes-s115-v120" + }, + { + "type": "WEB", + "url": "https://www.alliedtelesis.com/sites/default/files/documents/release-notes/ats115v120srna.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T23:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-wwmq-47hw-c7vw/GHSA-wwmq-47hw-c7vw.json b/advisories/unreviewed/2024/03/GHSA-wwmq-47hw-c7vw/GHSA-wwmq-47hw-c7vw.json new file mode 100644 index 00000000000..d3f22bea529 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-wwmq-47hw-c7vw/GHSA-wwmq-47hw-c7vw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwmq-47hw-c7vw", + "modified": "2024-03-29T00:30:34Z", + "published": "2024-03-29T00:30:34Z", + "aliases": [ + "CVE-2023-33528" + ], + "details": "halo v1.6.0 is vulnerable to Cross Site Scripting (XSS).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33528" + }, + { + "type": "WEB", + "url": "https://gist.github.com/alert-moyan/be0bd087d85c1416829b8e9659e8b66c" + }, + { + "type": "WEB", + "url": "https://github.com/halo-dev/halo/releases/tag/v1.6.0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T23:15:46Z" + } +} \ No newline at end of file