diff --git a/advisories/unreviewed/2023/08/GHSA-chgx-7cw3-hr55/GHSA-chgx-7cw3-hr55.json b/advisories/unreviewed/2023/08/GHSA-chgx-7cw3-hr55/GHSA-chgx-7cw3-hr55.json index 6b9bd3ed357..e0b68f041e1 100644 --- a/advisories/unreviewed/2023/08/GHSA-chgx-7cw3-hr55/GHSA-chgx-7cw3-hr55.json +++ b/advisories/unreviewed/2023/08/GHSA-chgx-7cw3-hr55/GHSA-chgx-7cw3-hr55.json @@ -25,6 +25,18 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2023:7785" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7883" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7884" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7885" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-39418" diff --git a/advisories/unreviewed/2023/08/GHSA-jx3x-j983-74m3/GHSA-jx3x-j983-74m3.json b/advisories/unreviewed/2023/08/GHSA-jx3x-j983-74m3/GHSA-jx3x-j983-74m3.json index a6b0e683b8a..5744264a41e 100644 --- a/advisories/unreviewed/2023/08/GHSA-jx3x-j983-74m3/GHSA-jx3x-j983-74m3.json +++ b/advisories/unreviewed/2023/08/GHSA-jx3x-j983-74m3/GHSA-jx3x-j983-74m3.json @@ -81,6 +81,18 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2023:7785" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7883" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7884" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7885" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-39417" diff --git a/advisories/unreviewed/2023/12/GHSA-243r-xrw9-vfhw/GHSA-243r-xrw9-vfhw.json b/advisories/unreviewed/2023/12/GHSA-243r-xrw9-vfhw/GHSA-243r-xrw9-vfhw.json new file mode 100644 index 00000000000..965d968a526 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-243r-xrw9-vfhw/GHSA-243r-xrw9-vfhw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-243r-xrw9-vfhw", + "modified": "2023-12-20T15:30:20Z", + "published": "2023-12-20T15:30:20Z", + "aliases": [ + "CVE-2023-35876" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooCommerce Square: from n/a through 3.8.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35876" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-square/wordpress-woocommerce-square-plugin-3-8-1-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-2gcq-g27g-mx27/GHSA-2gcq-g27g-mx27.json b/advisories/unreviewed/2023/12/GHSA-2gcq-g27g-mx27/GHSA-2gcq-g27g-mx27.json new file mode 100644 index 00000000000..802e3755087 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-2gcq-g27g-mx27/GHSA-2gcq-g27g-mx27.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gcq-g27g-mx27", + "modified": "2023-12-20T15:30:19Z", + "published": "2023-12-20T15:30:19Z", + "aliases": [ + "CVE-2023-41796" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in WP Sunshine Sunshine Photo Cart: Free Client Galleries for Photographers.This issue affects Sunshine Photo Cart: Free Client Galleries for Photographers: from n/a before 3.0.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41796" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sunshine-photo-cart/wordpress-sunshine-photo-cart-plugin-2-9-25-order-manipulation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-3f9w-7983-qcmq/GHSA-3f9w-7983-qcmq.json b/advisories/unreviewed/2023/12/GHSA-3f9w-7983-qcmq/GHSA-3f9w-7983-qcmq.json index d985d4a2617..969cbeb4893 100644 --- a/advisories/unreviewed/2023/12/GHSA-3f9w-7983-qcmq/GHSA-3f9w-7983-qcmq.json +++ b/advisories/unreviewed/2023/12/GHSA-3f9w-7983-qcmq/GHSA-3f9w-7983-qcmq.json @@ -81,6 +81,18 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2023:7785" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7883" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7884" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7885" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-5868" diff --git a/advisories/unreviewed/2023/12/GHSA-3pqp-qx7r-vppf/GHSA-3pqp-qx7r-vppf.json b/advisories/unreviewed/2023/12/GHSA-3pqp-qx7r-vppf/GHSA-3pqp-qx7r-vppf.json index 47c8c385b6c..5e1291f9b12 100644 --- a/advisories/unreviewed/2023/12/GHSA-3pqp-qx7r-vppf/GHSA-3pqp-qx7r-vppf.json +++ b/advisories/unreviewed/2023/12/GHSA-3pqp-qx7r-vppf/GHSA-3pqp-qx7r-vppf.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://github.com/sergejey/majordomo/commit/3ec3ffb863ea3c2661ab27d398776c551f4daaac" }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176273/MajorDoMo-Remote-Code-Execution.html" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2023/Dec/19" diff --git a/advisories/unreviewed/2023/12/GHSA-4mhf-fx5f-f9p6/GHSA-4mhf-fx5f-f9p6.json b/advisories/unreviewed/2023/12/GHSA-4mhf-fx5f-f9p6/GHSA-4mhf-fx5f-f9p6.json new file mode 100644 index 00000000000..28f3cfc4d71 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-4mhf-fx5f-f9p6/GHSA-4mhf-fx5f-f9p6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mhf-fx5f-f9p6", + "modified": "2023-12-20T15:30:20Z", + "published": "2023-12-20T15:30:20Z", + "aliases": [ + "CVE-2023-51459" + ], + "details": "Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51459" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb23-72.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-58ff-vg67-843q/GHSA-58ff-vg67-843q.json b/advisories/unreviewed/2023/12/GHSA-58ff-vg67-843q/GHSA-58ff-vg67-843q.json new file mode 100644 index 00000000000..6d5078b760a --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-58ff-vg67-843q/GHSA-58ff-vg67-843q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58ff-vg67-843q", + "modified": "2023-12-20T15:30:20Z", + "published": "2023-12-20T15:30:20Z", + "aliases": [ + "CVE-2023-28782" + ], + "details": "Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28782" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/gravityforms/wordpress-gravity-forms-plugin-2-7-3-unauthenticated-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T15:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-5gp7-j4r7-g66f/GHSA-5gp7-j4r7-g66f.json b/advisories/unreviewed/2023/12/GHSA-5gp7-j4r7-g66f/GHSA-5gp7-j4r7-g66f.json index 093568ed250..b761afb6b73 100644 --- a/advisories/unreviewed/2023/12/GHSA-5gp7-j4r7-g66f/GHSA-5gp7-j4r7-g66f.json +++ b/advisories/unreviewed/2023/12/GHSA-5gp7-j4r7-g66f/GHSA-5gp7-j4r7-g66f.json @@ -81,6 +81,18 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2023:7785" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7883" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7884" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7885" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-5870" diff --git a/advisories/unreviewed/2023/12/GHSA-6cxr-f776-wfqv/GHSA-6cxr-f776-wfqv.json b/advisories/unreviewed/2023/12/GHSA-6cxr-f776-wfqv/GHSA-6cxr-f776-wfqv.json new file mode 100644 index 00000000000..372e517b4ef --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-6cxr-f776-wfqv/GHSA-6cxr-f776-wfqv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cxr-f776-wfqv", + "modified": "2023-12-20T15:30:20Z", + "published": "2023-12-20T15:30:20Z", + "aliases": [ + "CVE-2023-32590" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category.This issue affects Subscribe to Category: from n/a through 2.7.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32590" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/subscribe-to-category/wordpress-subscribe-to-category-plugin-2-7-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-87fg-9x5w-j3rm/GHSA-87fg-9x5w-j3rm.json b/advisories/unreviewed/2023/12/GHSA-87fg-9x5w-j3rm/GHSA-87fg-9x5w-j3rm.json new file mode 100644 index 00000000000..bb9a803c08e --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-87fg-9x5w-j3rm/GHSA-87fg-9x5w-j3rm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87fg-9x5w-j3rm", + "modified": "2023-12-20T15:30:19Z", + "published": "2023-12-20T15:30:19Z", + "aliases": [ + "CVE-2023-38519" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MainWP MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance.This issue affects MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance: from n/a through 4.4.3.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38519" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mainwp/wordpress-mainwp-plugin-4-4-3-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-8h29-r9wc-2xj4/GHSA-8h29-r9wc-2xj4.json b/advisories/unreviewed/2023/12/GHSA-8h29-r9wc-2xj4/GHSA-8h29-r9wc-2xj4.json new file mode 100644 index 00000000000..ce1006808ae --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-8h29-r9wc-2xj4/GHSA-8h29-r9wc-2xj4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h29-r9wc-2xj4", + "modified": "2023-12-20T15:30:19Z", + "published": "2023-12-20T15:30:19Z", + "aliases": [ + "CVE-2023-51458" + ], + "details": "Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51458" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb23-72.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-92g9-mv36-r4j5/GHSA-92g9-mv36-r4j5.json b/advisories/unreviewed/2023/12/GHSA-92g9-mv36-r4j5/GHSA-92g9-mv36-r4j5.json new file mode 100644 index 00000000000..f77c47dd3fe --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-92g9-mv36-r4j5/GHSA-92g9-mv36-r4j5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92g9-mv36-r4j5", + "modified": "2023-12-20T15:30:19Z", + "published": "2023-12-20T15:30:19Z", + "aliases": [ + "CVE-2023-46147" + ], + "details": "Deserialization of Untrusted Data vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46147" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/themify-ultra/wordpress-themify-ultra-theme-7-3-3-authenticated-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-9625-p7pg-3cxg/GHSA-9625-p7pg-3cxg.json b/advisories/unreviewed/2023/12/GHSA-9625-p7pg-3cxg/GHSA-9625-p7pg-3cxg.json index acecba98f87..b87a3c9932a 100644 --- a/advisories/unreviewed/2023/12/GHSA-9625-p7pg-3cxg/GHSA-9625-p7pg-3cxg.json +++ b/advisories/unreviewed/2023/12/GHSA-9625-p7pg-3cxg/GHSA-9625-p7pg-3cxg.json @@ -113,6 +113,18 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2023:7878" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7883" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7884" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7885" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-5869" diff --git a/advisories/unreviewed/2023/12/GHSA-9fmf-6xvc-qw23/GHSA-9fmf-6xvc-qw23.json b/advisories/unreviewed/2023/12/GHSA-9fmf-6xvc-qw23/GHSA-9fmf-6xvc-qw23.json new file mode 100644 index 00000000000..ea317100897 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-9fmf-6xvc-qw23/GHSA-9fmf-6xvc-qw23.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fmf-6xvc-qw23", + "modified": "2023-12-20T15:30:19Z", + "published": "2023-12-20T15:30:19Z", + "aliases": [ + "CVE-2023-40555" + ], + "details": "Deserialization of Untrusted Data vulnerability in UX-themes Flatsome | Multi-Purpose Responsive WooCommerce Theme.This issue affects Flatsome | Multi-Purpose Responsive WooCommerce Theme: from n/a through 3.17.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40555" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/flatsome/wordpress-flatsome-theme-3-17-5-unauthenticated-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-9rvm-xpxj-3chj/GHSA-9rvm-xpxj-3chj.json b/advisories/unreviewed/2023/12/GHSA-9rvm-xpxj-3chj/GHSA-9rvm-xpxj-3chj.json new file mode 100644 index 00000000000..a0a77a22630 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-9rvm-xpxj-3chj/GHSA-9rvm-xpxj-3chj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rvm-xpxj-3chj", + "modified": "2023-12-20T15:30:20Z", + "published": "2023-12-20T15:30:20Z", + "aliases": [ + "CVE-2023-36520" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in MarketingFire Editorial Calendar.This issue affects Editorial Calendar: from n/a through 3.7.12.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36520" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/editorial-calendar/wordpress-editorial-calendar-plugin-3-7-12-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-f4vg-65v7-7gvm/GHSA-f4vg-65v7-7gvm.json b/advisories/unreviewed/2023/12/GHSA-f4vg-65v7-7gvm/GHSA-f4vg-65v7-7gvm.json index 58529f51451..f7cecc093a8 100644 --- a/advisories/unreviewed/2023/12/GHSA-f4vg-65v7-7gvm/GHSA-f4vg-65v7-7gvm.json +++ b/advisories/unreviewed/2023/12/GHSA-f4vg-65v7-7gvm/GHSA-f4vg-65v7-7gvm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f4vg-65v7-7gvm", - "modified": "2023-12-15T00:31:04Z", + "modified": "2023-12-20T15:30:18Z", "published": "2023-12-15T00:31:04Z", "aliases": [ "CVE-2023-48049" ], "details": "A SQL injection vulnerability in Cybrosys Techno Solutions Website Blog Search (aka website_search_blog) v. 13.0 through 13.0.1.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the name parameter in controllers/main.py component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-12-15T00:15:42Z" diff --git a/advisories/unreviewed/2023/12/GHSA-fwrj-5c8f-f8h2/GHSA-fwrj-5c8f-f8h2.json b/advisories/unreviewed/2023/12/GHSA-fwrj-5c8f-f8h2/GHSA-fwrj-5c8f-f8h2.json index b3a94808e10..5797dc6db2a 100644 --- a/advisories/unreviewed/2023/12/GHSA-fwrj-5c8f-f8h2/GHSA-fwrj-5c8f-f8h2.json +++ b/advisories/unreviewed/2023/12/GHSA-fwrj-5c8f-f8h2/GHSA-fwrj-5c8f-f8h2.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6478" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7886" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6478" diff --git a/advisories/unreviewed/2023/12/GHSA-g3jr-x8v9-67fh/GHSA-g3jr-x8v9-67fh.json b/advisories/unreviewed/2023/12/GHSA-g3jr-x8v9-67fh/GHSA-g3jr-x8v9-67fh.json new file mode 100644 index 00000000000..9bc225a23e5 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-g3jr-x8v9-67fh/GHSA-g3jr-x8v9-67fh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3jr-x8v9-67fh", + "modified": "2023-12-20T15:30:19Z", + "published": "2023-12-20T15:30:19Z", + "aliases": [ + "CVE-2023-47236" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum iPages Flipbook For WordPress.This issue affects iPages Flipbook For WordPress: from n/a through 1.4.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47236" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ipages-flipbook/wordpress-ipages-flipbook-for-wordpress-plugin-1-4-8-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-hpcv-jfrw-gw6r/GHSA-hpcv-jfrw-gw6r.json b/advisories/unreviewed/2023/12/GHSA-hpcv-jfrw-gw6r/GHSA-hpcv-jfrw-gw6r.json new file mode 100644 index 00000000000..07027d834b5 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-hpcv-jfrw-gw6r/GHSA-hpcv-jfrw-gw6r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpcv-jfrw-gw6r", + "modified": "2023-12-20T15:30:20Z", + "published": "2023-12-20T15:30:20Z", + "aliases": [ + "CVE-2023-51462" + ], + "details": "Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51462" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb23-72.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-j4m7-86jc-4qp8/GHSA-j4m7-86jc-4qp8.json b/advisories/unreviewed/2023/12/GHSA-j4m7-86jc-4qp8/GHSA-j4m7-86jc-4qp8.json new file mode 100644 index 00000000000..fe16e3a2cd7 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-j4m7-86jc-4qp8/GHSA-j4m7-86jc-4qp8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4m7-86jc-4qp8", + "modified": "2023-12-20T15:30:20Z", + "published": "2023-12-20T15:30:20Z", + "aliases": [ + "CVE-2023-51461" + ], + "details": "Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51461" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb23-72.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-p9w3-8m39-9587/GHSA-p9w3-8m39-9587.json b/advisories/unreviewed/2023/12/GHSA-p9w3-8m39-9587/GHSA-p9w3-8m39-9587.json new file mode 100644 index 00000000000..96df7fdc3fc --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-p9w3-8m39-9587/GHSA-p9w3-8m39-9587.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9w3-8m39-9587", + "modified": "2023-12-20T15:30:19Z", + "published": "2023-12-20T15:30:19Z", + "aliases": [ + "CVE-2023-37871" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: from n/a through 2.5.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37871" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-gateway-gocardless/wordpress-woocommerce-gocardless-gateway-plugin-2-5-6-unauthenticated-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-phff-83c6-vv57/GHSA-phff-83c6-vv57.json b/advisories/unreviewed/2023/12/GHSA-phff-83c6-vv57/GHSA-phff-83c6-vv57.json new file mode 100644 index 00000000000..f1546aec7a9 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-phff-83c6-vv57/GHSA-phff-83c6-vv57.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phff-83c6-vv57", + "modified": "2023-12-20T15:30:20Z", + "published": "2023-12-20T15:30:20Z", + "aliases": [ + "CVE-2023-40010" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in realmag777 HUSKY – Products Filter for WooCommerce Professional.This issue affects HUSKY – Products Filter for WooCommerce Professional: from n/a through 1.3.4.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40010" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-products-filter/wordpress-husky-plugin-1-3-4-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-q3v4-6rrg-2883/GHSA-q3v4-6rrg-2883.json b/advisories/unreviewed/2023/12/GHSA-q3v4-6rrg-2883/GHSA-q3v4-6rrg-2883.json new file mode 100644 index 00000000000..6d3fedf8a6f --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-q3v4-6rrg-2883/GHSA-q3v4-6rrg-2883.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3v4-6rrg-2883", + "modified": "2023-12-20T15:30:20Z", + "published": "2023-12-20T15:30:20Z", + "aliases": [ + "CVE-2023-35895" + ], + "details": "IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 259116.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35895" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/259116" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7099762" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-qf25-72qj-2prr/GHSA-qf25-72qj-2prr.json b/advisories/unreviewed/2023/12/GHSA-qf25-72qj-2prr/GHSA-qf25-72qj-2prr.json new file mode 100644 index 00000000000..efe7a875f9d --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-qf25-72qj-2prr/GHSA-qf25-72qj-2prr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qf25-72qj-2prr", + "modified": "2023-12-20T15:30:19Z", + "published": "2023-12-20T15:30:19Z", + "aliases": [ + "CVE-2023-38513" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in Jordy Meow Photo Engine (Media Organizer & Lightroom).This issue affects Photo Engine (Media Organizer & Lightroom): from n/a through 6.2.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38513" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wplr-sync/wordpress-photo-engine-plugin-6-2-5-insecure-direct-object-references-idor?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-rqvh-hrwh-vv6f/GHSA-rqvh-hrwh-vv6f.json b/advisories/unreviewed/2023/12/GHSA-rqvh-hrwh-vv6f/GHSA-rqvh-hrwh-vv6f.json new file mode 100644 index 00000000000..ef187889983 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-rqvh-hrwh-vv6f/GHSA-rqvh-hrwh-vv6f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqvh-hrwh-vv6f", + "modified": "2023-12-20T15:30:20Z", + "published": "2023-12-20T15:30:20Z", + "aliases": [ + "CVE-2023-47852" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Link Whisper Link Whisper Free.This issue affects Link Whisper Free: from n/a through 0.6.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47852" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/link-whisper/wordpress-link-whisper-free-plugin-0-6-5-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-v9h7-v369-359m/GHSA-v9h7-v369-359m.json b/advisories/unreviewed/2023/12/GHSA-v9h7-v369-359m/GHSA-v9h7-v369-359m.json new file mode 100644 index 00000000000..9f431fe1ee9 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-v9h7-v369-359m/GHSA-v9h7-v369-359m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9h7-v369-359m", + "modified": "2023-12-20T15:30:19Z", + "published": "2023-12-20T15:30:19Z", + "aliases": [ + "CVE-2023-46311" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team Comments – wpDiscuz.This issue affects Comments – wpDiscuz: from n/a through 7.6.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46311" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpdiscuz/wordpress-wpdiscuz-plugin-7-6-3-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-vfp7-j67w-fgqq/GHSA-vfp7-j67w-fgqq.json b/advisories/unreviewed/2023/12/GHSA-vfp7-j67w-fgqq/GHSA-vfp7-j67w-fgqq.json new file mode 100644 index 00000000000..2f6e693c2be --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-vfp7-j67w-fgqq/GHSA-vfp7-j67w-fgqq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfp7-j67w-fgqq", + "modified": "2023-12-20T15:30:19Z", + "published": "2023-12-20T15:30:19Z", + "aliases": [ + "CVE-2023-51457" + ], + "details": "Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51457" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb23-72.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-vj47-xvv7-vcr5/GHSA-vj47-xvv7-vcr5.json b/advisories/unreviewed/2023/12/GHSA-vj47-xvv7-vcr5/GHSA-vj47-xvv7-vcr5.json new file mode 100644 index 00000000000..49fb2375ca7 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-vj47-xvv7-vcr5/GHSA-vj47-xvv7-vcr5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vj47-xvv7-vcr5", + "modified": "2023-12-20T15:30:19Z", + "published": "2023-12-20T15:30:19Z", + "aliases": [ + "CVE-2023-47507" + ], + "details": "Deserialization of Untrusted Data vulnerability in Master Slider Master Slider Pro.This issue affects Master Slider Pro: from n/a through 3.6.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47507" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/masterslider/wordpress-master-slider-pro-plugin-3-6-5-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-w8m5-hwqp-jg84/GHSA-w8m5-hwqp-jg84.json b/advisories/unreviewed/2023/12/GHSA-w8m5-hwqp-jg84/GHSA-w8m5-hwqp-jg84.json new file mode 100644 index 00000000000..4e6f30bcb4d --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-w8m5-hwqp-jg84/GHSA-w8m5-hwqp-jg84.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8m5-hwqp-jg84", + "modified": "2023-12-20T15:30:20Z", + "published": "2023-12-20T15:30:20Z", + "aliases": [ + "CVE-2023-51460" + ], + "details": "Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51460" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/experience-manager/apsb23-72.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-xghf-952v-933j/GHSA-xghf-952v-933j.json b/advisories/unreviewed/2023/12/GHSA-xghf-952v-933j/GHSA-xghf-952v-933j.json new file mode 100644 index 00000000000..51f387dfb40 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-xghf-952v-933j/GHSA-xghf-952v-933j.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xghf-952v-933j", + "modified": "2023-12-20T15:30:20Z", + "published": "2023-12-20T15:30:20Z", + "aliases": [ + "CVE-2023-6784" + ], + "details": "\nA malicious user could potentially use the Sitefinity system for the distribution of phishing emails.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6784" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/Sitefinity-Security-Advisory-for-Addressing-Security-Vulnerability-CVE-2023-6784-December-2023" + }, + { + "type": "WEB", + "url": "https://www.progress.com/sitefinity-cms" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-20T14:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-xp6x-8hgv-x5w5/GHSA-xp6x-8hgv-x5w5.json b/advisories/unreviewed/2023/12/GHSA-xp6x-8hgv-x5w5/GHSA-xp6x-8hgv-x5w5.json index f2b38a3e297..5bcedee24d6 100644 --- a/advisories/unreviewed/2023/12/GHSA-xp6x-8hgv-x5w5/GHSA-xp6x-8hgv-x5w5.json +++ b/advisories/unreviewed/2023/12/GHSA-xp6x-8hgv-x5w5/GHSA-xp6x-8hgv-x5w5.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6377" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:7886" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6377"