diff --git a/advisories/unreviewed/2024/08/GHSA-wrfv-q4v6-cw3x/GHSA-wrfv-q4v6-cw3x.json b/advisories/unreviewed/2024/08/GHSA-wrfv-q4v6-cw3x/GHSA-wrfv-q4v6-cw3x.json index b89948ddba4..508f975972b 100644 --- a/advisories/unreviewed/2024/08/GHSA-wrfv-q4v6-cw3x/GHSA-wrfv-q4v6-cw3x.json +++ b/advisories/unreviewed/2024/08/GHSA-wrfv-q4v6-cw3x/GHSA-wrfv-q4v6-cw3x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wrfv-q4v6-cw3x", - "modified": "2024-08-19T15:31:34Z", + "modified": "2024-10-11T15:30:32Z", "published": "2024-08-07T09:31:08Z", "aliases": [ "CVE-2024-42062" diff --git a/advisories/unreviewed/2024/10/GHSA-42m9-x54q-hrvm/GHSA-42m9-x54q-hrvm.json b/advisories/unreviewed/2024/10/GHSA-42m9-x54q-hrvm/GHSA-42m9-x54q-hrvm.json new file mode 100644 index 00000000000..55bc19a4b8e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-42m9-x54q-hrvm/GHSA-42m9-x54q-hrvm.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42m9-x54q-hrvm", + "modified": "2024-10-11T15:30:33Z", + "published": "2024-10-11T15:30:33Z", + "aliases": [ + "CVE-2024-9346" + ], + "details": "The Embed videos and respect privacy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'v' parameter in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9346" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/video-embed-privacy/trunk/preview/preview.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3162600%40video-embed-privacy&new=3162600%40video-embed-privacy&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/487e5add-726c-4cfc-b86e-bb4eeec168a3?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4vhv-rmg8-wc9v/GHSA-4vhv-rmg8-wc9v.json b/advisories/unreviewed/2024/10/GHSA-4vhv-rmg8-wc9v/GHSA-4vhv-rmg8-wc9v.json new file mode 100644 index 00000000000..3961c5b02ad --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4vhv-rmg8-wc9v/GHSA-4vhv-rmg8-wc9v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vhv-rmg8-wc9v", + "modified": "2024-10-11T15:30:33Z", + "published": "2024-10-11T15:30:33Z", + "aliases": [ + "CVE-2024-6657" + ], + "details": "A denial of service may be caused to a single peripheral device in a BLE network when multiple central \ndevices continuously connect and disconnect to the peripheral. A hard reset is required to recover the peripheral device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6657" + }, + { + "type": "WEB", + "url": "https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/069Vm00000E9IIbIAN?operationContext=S1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-821" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-537j-q568-qwrw/GHSA-537j-q568-qwrw.json b/advisories/unreviewed/2024/10/GHSA-537j-q568-qwrw/GHSA-537j-q568-qwrw.json new file mode 100644 index 00000000000..0e62159c81b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-537j-q568-qwrw/GHSA-537j-q568-qwrw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-537j-q568-qwrw", + "modified": "2024-10-11T15:30:33Z", + "published": "2024-10-11T15:30:33Z", + "aliases": [ + "CVE-2024-8755" + ], + "details": "Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects:\n\n\n\n\n\n Product \n\n\n\n\n\nAffected Versions \n\n\n\n\n\nLoadMaster \n\n\n\n\n\nFrom 7.2.55.0 to 7.2.60.1 (inclusive) \n\n\n\n\n\n  \n\n\n\n\n\nFrom 7.2.49.0 to 7.2.54.12 (inclusive) \n\n\n\n\n\n  \n\n\n\n\n\n7.2.48.12 and all prior versions \n\n\n\n\n\n\n\n\nMulti-Tenant Hypervisor \n\n\n\n\n\n7.1.35.12 and all prior versions \n\n\n\n\n\n\n\n\n\n\nECS\n\n\n\n\n\nAll prior versions to 7.2.60.1 (inclusive)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8755" + }, + { + "type": "WEB", + "url": "https://support.kemptechnologies.com/hc/en-us/articles/30297374715661-LoadMaster-Security-Vulnerability-CVE-2024-8755" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T15:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-53j3-c5gj-9m5j/GHSA-53j3-c5gj-9m5j.json b/advisories/unreviewed/2024/10/GHSA-53j3-c5gj-9m5j/GHSA-53j3-c5gj-9m5j.json new file mode 100644 index 00000000000..8ec5357dbe7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-53j3-c5gj-9m5j/GHSA-53j3-c5gj-9m5j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53j3-c5gj-9m5j", + "modified": "2024-10-11T15:30:33Z", + "published": "2024-10-11T15:30:33Z", + "aliases": [ + "CVE-2024-8531" + ], + "details": "CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could\ncompromise the Data Center Expert software when an upgrade bundle is manipulated to\ninclude arbitrary bash scripts that are executed as root.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8531" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-282-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-282-01.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-347" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-57qh-vmjr-5jxg/GHSA-57qh-vmjr-5jxg.json b/advisories/unreviewed/2024/10/GHSA-57qh-vmjr-5jxg/GHSA-57qh-vmjr-5jxg.json new file mode 100644 index 00000000000..b80709f77b7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-57qh-vmjr-5jxg/GHSA-57qh-vmjr-5jxg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57qh-vmjr-5jxg", + "modified": "2024-10-11T15:30:32Z", + "published": "2024-10-11T15:30:32Z", + "aliases": [ + "CVE-2024-48987" + ], + "details": "Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48987" + }, + { + "type": "WEB", + "url": "https://github.com/snipe/snipe-it/releases/tag/v7.0.10" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-58jq-vjfq-8v45/GHSA-58jq-vjfq-8v45.json b/advisories/unreviewed/2024/10/GHSA-58jq-vjfq-8v45/GHSA-58jq-vjfq-8v45.json new file mode 100644 index 00000000000..f782013435e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-58jq-vjfq-8v45/GHSA-58jq-vjfq-8v45.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-58jq-vjfq-8v45", + "modified": "2024-10-11T15:30:32Z", + "published": "2024-10-11T15:30:32Z", + "aliases": [ + "CVE-2024-5005" + ], + "details": "An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2 It was possible for guest users to disclose project templates using the API.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5005" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2501461" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/462108" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-684" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5c6j-q7qx-jw7p/GHSA-5c6j-q7qx-jw7p.json b/advisories/unreviewed/2024/10/GHSA-5c6j-q7qx-jw7p/GHSA-5c6j-q7qx-jw7p.json new file mode 100644 index 00000000000..7994342f1ef --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5c6j-q7qx-jw7p/GHSA-5c6j-q7qx-jw7p.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c6j-q7qx-jw7p", + "modified": "2024-10-11T15:30:33Z", + "published": "2024-10-11T15:30:33Z", + "aliases": [ + "CVE-2024-9610" + ], + "details": "The Language Switcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.7.13. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9610" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/language-switcher/tags/3.7.13/includes/class-language-switcher-settings.php#L464" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3165172" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f117fffb-2bbb-4e95-b589-909972db1e5e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5gh7-7795-6ghv/GHSA-5gh7-7795-6ghv.json b/advisories/unreviewed/2024/10/GHSA-5gh7-7795-6ghv/GHSA-5gh7-7795-6ghv.json new file mode 100644 index 00000000000..59952cfb6d3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5gh7-7795-6ghv/GHSA-5gh7-7795-6ghv.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gh7-7795-6ghv", + "modified": "2024-10-11T15:30:32Z", + "published": "2024-10-11T15:30:32Z", + "aliases": [ + "CVE-2024-9221" + ], + "details": "The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 0.21.10. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9221" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/tainacan/tags/0.21.10/classes/theme-helper/template-tags.php#L1298" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/tainacan/tags/0.21.10/classes/theme-helper/template-tags.php#L1524" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3165873" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/85a8a7df-b472-4a81-b808-a413c158c1cf?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6f2w-qq5x-fpg9/GHSA-6f2w-qq5x-fpg9.json b/advisories/unreviewed/2024/10/GHSA-6f2w-qq5x-fpg9/GHSA-6f2w-qq5x-fpg9.json new file mode 100644 index 00000000000..2bfb41ad7a4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6f2w-qq5x-fpg9/GHSA-6f2w-qq5x-fpg9.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f2w-qq5x-fpg9", + "modified": "2024-10-11T15:30:33Z", + "published": "2024-10-11T15:30:33Z", + "aliases": [ + "CVE-2024-9586" + ], + "details": "The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'check_auth' and 'check_logout' functions in versions up to, and including, 1.1.8. This makes it possible for unauthenticated attackers to update plugin settings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9586" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/linkz-ai/tags/1.1.8/init.php#L142" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/linkz-ai/tags/1.1.8/init.php#L159" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b4b4ca5b-c806-4b68-acb8-6b63d6ca5728?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6vwq-gg49-hj9w/GHSA-6vwq-gg49-hj9w.json b/advisories/unreviewed/2024/10/GHSA-6vwq-gg49-hj9w/GHSA-6vwq-gg49-hj9w.json new file mode 100644 index 00000000000..082db62c656 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6vwq-gg49-hj9w/GHSA-6vwq-gg49-hj9w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vwq-gg49-hj9w", + "modified": "2024-10-11T15:30:32Z", + "published": "2024-10-11T15:30:32Z", + "aliases": [ + "CVE-2024-45316" + ], + "details": "The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to delete arbitrary folders and files, potentially leading to local privilege escalation attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45316" + }, + { + "type": "WEB", + "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0017" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7cmx-277j-7rf8/GHSA-7cmx-277j-7rf8.json b/advisories/unreviewed/2024/10/GHSA-7cmx-277j-7rf8/GHSA-7cmx-277j-7rf8.json new file mode 100644 index 00000000000..8b0a3dfcb96 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7cmx-277j-7rf8/GHSA-7cmx-277j-7rf8.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cmx-277j-7rf8", + "modified": "2024-10-11T15:30:33Z", + "published": "2024-10-11T15:30:32Z", + "aliases": [ + "CVE-2024-9234" + ], + "details": "The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the install_and_activate_plugin_from_external() function (install-active-plugin REST API endpoint) in all versions up to, and including, 2.1.0. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins, or utilize the functionality to upload arbitrary files spoofed like plugins.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9234" + }, + { + "type": "WEB", + "url": "https://github.com/WordPressBugBounty/plugins-gutenkit-blocks-addon/blob/dc3738bb821cf1d93a11379b8695793fa5e1b9e6/gutenkit-blocks-addon/includes/Admin/Api/ActivePluginData.php#L76" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/gutenkit-blocks-addon/tags/2.1.0/includes/Admin/Api/ActivePluginData.php?rev=3159783#L76" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/gutenkit-blocks-addon/tags/2.1.1/includes/Admin/Api/ActivePluginData.php?rev=3164886" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e44c5dc0-6bf6-417a-9383-b345ff57ac32?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7f2m-jpcp-wjgr/GHSA-7f2m-jpcp-wjgr.json b/advisories/unreviewed/2024/10/GHSA-7f2m-jpcp-wjgr/GHSA-7f2m-jpcp-wjgr.json new file mode 100644 index 00000000000..b772588df8a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7f2m-jpcp-wjgr/GHSA-7f2m-jpcp-wjgr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f2m-jpcp-wjgr", + "modified": "2024-10-11T15:30:32Z", + "published": "2024-10-11T15:30:32Z", + "aliases": [ + "CVE-2024-45317" + ], + "details": "A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated attacker to cause the SMA1000 server-side application to make requests to an unintended IP address.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45317" + }, + { + "type": "WEB", + "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0017" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7hcw-752h-p5pp/GHSA-7hcw-752h-p5pp.json b/advisories/unreviewed/2024/10/GHSA-7hcw-752h-p5pp/GHSA-7hcw-752h-p5pp.json new file mode 100644 index 00000000000..8a37210e05d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7hcw-752h-p5pp/GHSA-7hcw-752h-p5pp.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hcw-752h-p5pp", + "modified": "2024-10-11T15:30:33Z", + "published": "2024-10-11T15:30:33Z", + "aliases": [ + "CVE-2024-9855" + ], + "details": "A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been declared as critical. Affected by this vulnerability is the function uploadFile of the file /admin/SysModule/upload/ajaxmodel/upload/uploadfilepath/sysmodule_1 of the component Module Plug-In Handler. The manipulation of the argument file leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The affected product is known with different names like 07FLYCMS, 07FLY-CMS, and 07FlyCRM. It was not possible to reach out to the vendor before assigning a CVE due to a not working mail address.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9855" + }, + { + "type": "WEB", + "url": "https://github.com/DeepMountains/zzz/blob/main/CVE6-1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.280051" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.280051" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.419222" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7pgr-32fx-c6x9/GHSA-7pgr-32fx-c6x9.json b/advisories/unreviewed/2024/10/GHSA-7pgr-32fx-c6x9/GHSA-7pgr-32fx-c6x9.json new file mode 100644 index 00000000000..3e4844d3714 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7pgr-32fx-c6x9/GHSA-7pgr-32fx-c6x9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pgr-32fx-c6x9", + "modified": "2024-10-11T15:30:32Z", + "published": "2024-10-11T15:30:32Z", + "aliases": [ + "CVE-2024-6971" + ], + "details": "A path traversal vulnerability exists in the parisneo/lollms-webui repository, specifically in the `lollms_file_system.py` file. The functions `add_rag_database`, `toggle_mount_rag_database`, and `vectorize_folder` do not implement security measures such as `sanitize_path_from_endpoint` or `sanitize_path`. This allows an attacker to perform vectorize operations on `.sqlite` files in any directory on the victim's computer, potentially installing multiple packages and causing a crash.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6971" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/fbfe7cd0-99fb-4305-bd07-8b573364109e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8cm3-4qfx-pwvc/GHSA-8cm3-4qfx-pwvc.json b/advisories/unreviewed/2024/10/GHSA-8cm3-4qfx-pwvc/GHSA-8cm3-4qfx-pwvc.json new file mode 100644 index 00000000000..839f151484a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8cm3-4qfx-pwvc/GHSA-8cm3-4qfx-pwvc.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cm3-4qfx-pwvc", + "modified": "2024-10-11T15:30:33Z", + "published": "2024-10-11T15:30:33Z", + "aliases": [ + "CVE-2024-9707" + ], + "details": "The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9707" + }, + { + "type": "WEB", + "url": "https://github.com/WordPressBugBounty/plugins-hunk-companion/blob/5a3cedc7b3d35d407b210e691c53c6cb400e4051/hunk-companion/import/app/app.php#L46" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3166501%40hunk-companion&new=3166501%40hunk-companion&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/hunk-companion" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9c101fca-037c-4bed-9dc7-baa021a8b59c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9wv6-mfj4-8v37/GHSA-9wv6-mfj4-8v37.json b/advisories/unreviewed/2024/10/GHSA-9wv6-mfj4-8v37/GHSA-9wv6-mfj4-8v37.json new file mode 100644 index 00000000000..f451d9b6e25 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9wv6-mfj4-8v37/GHSA-9wv6-mfj4-8v37.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wv6-mfj4-8v37", + "modified": "2024-10-11T15:30:33Z", + "published": "2024-10-11T15:30:33Z", + "aliases": [ + "CVE-2024-9507" + ], + "details": "The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 2.15.2 due to improper input validation within the iconUpload function. This makes it possible for authenticated attackers, with Administrator-level access and above, to leverage a PHP filter chain attack and read the contents of arbitrary files on the server, which can contain sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9507" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/bit-form/trunk/includes/Admin/AdminAjax.php#L1210" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3165686" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3165686/bit-form/trunk/includes/Admin/AdminAjax.php" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/bit-form/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/aa46842f-ed07-4f72-aedb-aa27baecd79c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cxqf-3r2f-3mfc/GHSA-cxqf-3r2f-3mfc.json b/advisories/unreviewed/2024/10/GHSA-cxqf-3r2f-3mfc/GHSA-cxqf-3r2f-3mfc.json new file mode 100644 index 00000000000..7de12646223 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cxqf-3r2f-3mfc/GHSA-cxqf-3r2f-3mfc.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxqf-3r2f-3mfc", + "modified": "2024-10-11T15:30:33Z", + "published": "2024-10-11T15:30:32Z", + "aliases": [ + "CVE-2024-9232" + ], + "details": "The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.9.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9232" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/download-plugins-dashboard/tags/1.9.1/includes/settings/class-alg-download-plugins-settings.php#L336" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3165289/#file5" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c3ea04ba-b609-49cd-aae8-68f5b51df154?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f45p-45cp-4m9x/GHSA-f45p-45cp-4m9x.json b/advisories/unreviewed/2024/10/GHSA-f45p-45cp-4m9x/GHSA-f45p-45cp-4m9x.json new file mode 100644 index 00000000000..da79bdd161b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f45p-45cp-4m9x/GHSA-f45p-45cp-4m9x.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f45p-45cp-4m9x", + "modified": "2024-10-11T15:30:33Z", + "published": "2024-10-11T15:30:33Z", + "aliases": [ + "CVE-2024-9436" + ], + "details": "The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.5.14. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9436" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/revisionary/tags/3.5.14/admin/class-list-table-archive.php#L780" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/revisionary/tags/3.5.14/admin/class-list-table_rvy.php#L717" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3165210" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/982bc924-1dcd-47b5-b15a-4ff0ad123ad1?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fh2j-rw8g-c7f3/GHSA-fh2j-rw8g-c7f3.json b/advisories/unreviewed/2024/10/GHSA-fh2j-rw8g-c7f3/GHSA-fh2j-rw8g-c7f3.json new file mode 100644 index 00000000000..d3fbbee231d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fh2j-rw8g-c7f3/GHSA-fh2j-rw8g-c7f3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh2j-rw8g-c7f3", + "modified": "2024-10-11T15:30:32Z", + "published": "2024-10-11T15:30:32Z", + "aliases": [ + "CVE-2024-8970" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8970" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2724948" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/490916" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fjh3-q35h-49hf/GHSA-fjh3-q35h-49hf.json b/advisories/unreviewed/2024/10/GHSA-fjh3-q35h-49hf/GHSA-fjh3-q35h-49hf.json new file mode 100644 index 00000000000..31f89c5af8a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fjh3-q35h-49hf/GHSA-fjh3-q35h-49hf.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjh3-q35h-49hf", + "modified": "2024-10-11T15:30:32Z", + "published": "2024-10-11T15:30:32Z", + "aliases": [ + "CVE-2024-9051" + ], + "details": "The WP Ultimate Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpupg-grid-with-filters shortcode in all versions up to, and including, 3.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9051" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-ultimate-post-grid/trunk/includes/public/class-wpupg-blocks.php#L142" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-ultimate-post-grid/trunk/includes/public/class-wpupg-shortcode.php#L55" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3166429" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wp-ultimate-post-grid/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f3154a7a-b8b3-490b-9822-b3a92d1b4fef?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h3xr-p2v4-jv9v/GHSA-h3xr-p2v4-jv9v.json b/advisories/unreviewed/2024/10/GHSA-h3xr-p2v4-jv9v/GHSA-h3xr-p2v4-jv9v.json new file mode 100644 index 00000000000..98859860c7c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h3xr-p2v4-jv9v/GHSA-h3xr-p2v4-jv9v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3xr-p2v4-jv9v", + "modified": "2024-10-11T15:30:32Z", + "published": "2024-10-11T15:30:32Z", + "aliases": [ + "CVE-2024-45315" + ], + "details": "The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to create arbitrary folders and files, potentially leading to local Denial of Service (DoS) attack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45315" + }, + { + "type": "WEB", + "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0017" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hm3j-qgpw-pj98/GHSA-hm3j-qgpw-pj98.json b/advisories/unreviewed/2024/10/GHSA-hm3j-qgpw-pj98/GHSA-hm3j-qgpw-pj98.json index 19a7b519e2b..2f31a7b427c 100644 --- a/advisories/unreviewed/2024/10/GHSA-hm3j-qgpw-pj98/GHSA-hm3j-qgpw-pj98.json +++ b/advisories/unreviewed/2024/10/GHSA-hm3j-qgpw-pj98/GHSA-hm3j-qgpw-pj98.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hm3j-qgpw-pj98", - "modified": "2024-10-09T18:31:42Z", + "modified": "2024-10-11T15:30:32Z", "published": "2024-10-09T15:32:18Z", "aliases": [ "CVE-2024-9680" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-51" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-52" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-j926-cg89-w6qr/GHSA-j926-cg89-w6qr.json b/advisories/unreviewed/2024/10/GHSA-j926-cg89-w6qr/GHSA-j926-cg89-w6qr.json new file mode 100644 index 00000000000..218764e3b57 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j926-cg89-w6qr/GHSA-j926-cg89-w6qr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j926-cg89-w6qr", + "modified": "2024-10-11T15:30:33Z", + "published": "2024-10-11T15:30:33Z", + "aliases": [ + "CVE-2024-8530" + ], + "details": "CWE-306: Missing Authentication for Critical Function vulnerability exists that could\ncause exposure of private data when an already generated “logcaptures” archive is accessed\ndirectly by HTTPS.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8530" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-282-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-282-01.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mpxq-m5x3-qf7f/GHSA-mpxq-m5x3-qf7f.json b/advisories/unreviewed/2024/10/GHSA-mpxq-m5x3-qf7f/GHSA-mpxq-m5x3-qf7f.json new file mode 100644 index 00000000000..069e2d19364 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mpxq-m5x3-qf7f/GHSA-mpxq-m5x3-qf7f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpxq-m5x3-qf7f", + "modified": "2024-10-11T15:30:33Z", + "published": "2024-10-11T15:30:33Z", + "aliases": [ + "CVE-2024-9587" + ], + "details": "The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_linkz' function in versions up to, and including, 1.1.8. This makes it possible for authenticated attackers with contributor-level privileges or above, to update plugin settings.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9587" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/linkz-ai/tags/1.1.8/init.php#L252" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b1faa178-e4b1-4d2e-85f1-b852fbf3ab17?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mv4q-7rj8-x4fv/GHSA-mv4q-7rj8-x4fv.json b/advisories/unreviewed/2024/10/GHSA-mv4q-7rj8-x4fv/GHSA-mv4q-7rj8-x4fv.json new file mode 100644 index 00000000000..851038aa21d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mv4q-7rj8-x4fv/GHSA-mv4q-7rj8-x4fv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv4q-7rj8-x4fv", + "modified": "2024-10-11T15:30:32Z", + "published": "2024-10-11T15:30:32Z", + "aliases": [ + "CVE-2024-8913" + ], + "details": "The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.11 via the render function in modules/widgets/tp_accordion.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8913" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3165763/the-plus-addons-for-elementor-page-builder" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/46126f88-416a-4430-8596-12f72cd2c1e7?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p9m3-293j-mh24/GHSA-p9m3-293j-mh24.json b/advisories/unreviewed/2024/10/GHSA-p9m3-293j-mh24/GHSA-p9m3-293j-mh24.json new file mode 100644 index 00000000000..9eed9697a91 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-p9m3-293j-mh24/GHSA-p9m3-293j-mh24.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9m3-293j-mh24", + "modified": "2024-10-11T15:30:33Z", + "published": "2024-10-11T15:30:33Z", + "aliases": [ + "CVE-2024-9002" + ], + "details": "CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized\naccess, loss of confidentiality, integrity, and availability of the workstation when non-admin\nauthenticated user tries to perform privilege escalation by tampering with the binaries", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9002" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-282-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-282-03.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p9ph-pjpv-vgx7/GHSA-p9ph-pjpv-vgx7.json b/advisories/unreviewed/2024/10/GHSA-p9ph-pjpv-vgx7/GHSA-p9ph-pjpv-vgx7.json new file mode 100644 index 00000000000..8f3f1538422 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-p9ph-pjpv-vgx7/GHSA-p9ph-pjpv-vgx7.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9ph-pjpv-vgx7", + "modified": "2024-10-11T15:30:32Z", + "published": "2024-10-11T15:30:32Z", + "aliases": [ + "CVE-2024-9211" + ], + "details": "The FULL – Cliente plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.1.22. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9211" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/full-customer/tags/3.1.22/app/views/admin/config.php#L274" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/full-customer/tags/3.1.22/app/views/admin/connection.php#L110" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/full-customer/tags/3.1.22/app/views/admin/templates/endpoints/cloud.php#L7" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/full-customer/tags/3.1.23/app/views/admin/config.php#L274" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/full-customer/tags/3.1.23/app/views/admin/connection.php#L110" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/full-customer/tags/3.1.23/app/views/admin/templates/endpoints/cloud.php#L7" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f62a486a-137b-48e5-b276-44438958e811?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pj3m-fgm6-v75m/GHSA-pj3m-fgm6-v75m.json b/advisories/unreviewed/2024/10/GHSA-pj3m-fgm6-v75m/GHSA-pj3m-fgm6-v75m.json new file mode 100644 index 00000000000..92cd9e1561c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pj3m-fgm6-v75m/GHSA-pj3m-fgm6-v75m.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj3m-fgm6-v75m", + "modified": "2024-10-11T15:30:33Z", + "published": "2024-10-11T15:30:33Z", + "aliases": [ + "CVE-2024-9856" + ], + "details": "A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been rated as problematic. Affected by this issue is some unknown functionality of the component System Settings Page. The manipulation of the argument Login Interface Copyright leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The affected product is known with different names like 07FLYCMS, 07FLY-CMS, and 07FlyCRM. It was not possible to reach out to the vendor before assigning a CVE due to a not working mail address.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9856" + }, + { + "type": "WEB", + "url": "https://github.com/DeepMountains/zzz/blob/main/CVE6-2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.280052" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.280052" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.419223" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pppg-cpfq-h7wr/GHSA-pppg-cpfq-h7wr.json b/advisories/unreviewed/2024/10/GHSA-pppg-cpfq-h7wr/GHSA-pppg-cpfq-h7wr.json new file mode 100644 index 00000000000..83eb6bf3329 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pppg-cpfq-h7wr/GHSA-pppg-cpfq-h7wr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pppg-cpfq-h7wr", + "modified": "2024-10-11T15:30:32Z", + "published": "2024-10-11T15:30:32Z", + "aliases": [ + "CVE-2024-21534" + ], + "details": "Versions of the package jsonpath-plus before 10.0.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node.\n\n**Note:**\n\nThe unsafe behavior is still available after applying the fix but it is not turned on by default.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21534" + }, + { + "type": "WEB", + "url": "https://github.com/JSONPath-Plus/JSONPath/commit/6b2f1b4c234292c75912b790bf7e2d7339d4ccd3" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-7945884" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r9p4-3vqv-3mmq/GHSA-r9p4-3vqv-3mmq.json b/advisories/unreviewed/2024/10/GHSA-r9p4-3vqv-3mmq/GHSA-r9p4-3vqv-3mmq.json new file mode 100644 index 00000000000..18ce6e1dbb4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r9p4-3vqv-3mmq/GHSA-r9p4-3vqv-3mmq.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9p4-3vqv-3mmq", + "modified": "2024-10-11T15:30:33Z", + "published": "2024-10-11T15:30:33Z", + "aliases": [ + "CVE-2024-9543" + ], + "details": "The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skipto' shortcode in all versions up to, and including, 11.9.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9543" + }, + { + "type": "WEB", + "url": "https://blubrry.com/support/powerpress-documentation/skip-to-position-in-player" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/powerpress/tags/11.9.17/powerpress-player.php#L1748" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/powerpress/tags/11.9.17/powerpress.php#L4094" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3166085/powerpress" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6b33c180-10b4-4550-8c24-72c9e53664a5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rq67-2vj3-3r6g/GHSA-rq67-2vj3-3r6g.json b/advisories/unreviewed/2024/10/GHSA-rq67-2vj3-3r6g/GHSA-rq67-2vj3-3r6g.json new file mode 100644 index 00000000000..87e0873890c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rq67-2vj3-3r6g/GHSA-rq67-2vj3-3r6g.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq67-2vj3-3r6g", + "modified": "2024-10-11T15:30:33Z", + "published": "2024-10-11T15:30:33Z", + "aliases": [ + "CVE-2024-9611" + ], + "details": "The Increase upload file size & Maximum Execution Time limit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9611" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/increase-upload-file-size-maximum-execution-time-limit/trunk/library_default_puvox.php?rev=2589469#L8560" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3166370%40increase-upload-file-size-maximum-execution-time-limit&new=3166370%40increase-upload-file-size-maximum-execution-time-limit" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1c432dbe-8542-41de-966a-b2699d1685ce?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w7hg-wgqh-73cr/GHSA-w7hg-wgqh-73cr.json b/advisories/unreviewed/2024/10/GHSA-w7hg-wgqh-73cr/GHSA-w7hg-wgqh-73cr.json new file mode 100644 index 00000000000..de075f298bd --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w7hg-wgqh-73cr/GHSA-w7hg-wgqh-73cr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7hg-wgqh-73cr", + "modified": "2024-10-11T15:30:33Z", + "published": "2024-10-11T15:30:33Z", + "aliases": [ + "CVE-2024-9538" + ], + "details": "The ShopLentor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.8 via the 'render' function in includes/addons/wl_faq.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft Elementor template data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9538" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3164057/woolentor-addons" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6b36938e-5333-4331-9bb1-34465fe03f2f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-x4j4-pcg4-rpww/GHSA-x4j4-pcg4-rpww.json b/advisories/unreviewed/2024/10/GHSA-x4j4-pcg4-rpww/GHSA-x4j4-pcg4-rpww.json new file mode 100644 index 00000000000..b4bbcbc41dc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-x4j4-pcg4-rpww/GHSA-x4j4-pcg4-rpww.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4j4-pcg4-rpww", + "modified": "2024-10-11T15:30:33Z", + "published": "2024-10-11T15:30:33Z", + "aliases": [ + "CVE-2024-9616" + ], + "details": "The BlockMeister – Block Pattern Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.1.10. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9616" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/blockmeister/tags/3.1.10/includes/JSON_File_Uploader.php#L31" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/blockmeister/tags/3.1.10/includes/Pattern_Builder/Admin/BlockMeister_Pattern_List_Table.php#L272" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/blockmeister/tags/3.1.11/includes/JSON_File_Uploader.php?rev=3165925#L31" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3165925%40blockmeister&new=3165925%40blockmeister&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/584d4517-1152-42fa-9ea9-a9e9ed8996fa?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xc4q-wvjc-4v56/GHSA-xc4q-wvjc-4v56.json b/advisories/unreviewed/2024/10/GHSA-xc4q-wvjc-4v56/GHSA-xc4q-wvjc-4v56.json new file mode 100644 index 00000000000..e330ad2e2e9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xc4q-wvjc-4v56/GHSA-xc4q-wvjc-4v56.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xc4q-wvjc-4v56", + "modified": "2024-10-11T15:30:32Z", + "published": "2024-10-11T15:30:32Z", + "aliases": [ + "CVE-2024-9164" + ], + "details": "An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9164" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2711204" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/493946" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xr7h-8r7p-xpv9/GHSA-xr7h-8r7p-xpv9.json b/advisories/unreviewed/2024/10/GHSA-xr7h-8r7p-xpv9/GHSA-xr7h-8r7p-xpv9.json new file mode 100644 index 00000000000..28e80cdcef9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xr7h-8r7p-xpv9/GHSA-xr7h-8r7p-xpv9.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr7h-8r7p-xpv9", + "modified": "2024-10-11T15:30:32Z", + "published": "2024-10-11T15:30:32Z", + "aliases": [ + "CVE-2023-42133" + ], + "details": "PAX Android based POS devices allow for escalation of privilege via improperly configured scripts.\n\nAn attacker must have shell access with system account privileges in order to exploit this vulnerability.\nA patch addressing this issue was included in firmware version PayDroid_8.1.0_Sagittarius_V11.1.61_20240226.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42133" + }, + { + "type": "WEB", + "url": "https://blog.stmcyber.com/pax-pos-cves-2023" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/10/CVE-2023-42133" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/10/CVE-2023-42133" + }, + { + "type": "WEB", + "url": "https://ppn.paxengine.com/release/development?" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xxrw-hw8c-v7g8/GHSA-xxrw-hw8c-v7g8.json b/advisories/unreviewed/2024/10/GHSA-xxrw-hw8c-v7g8/GHSA-xxrw-hw8c-v7g8.json new file mode 100644 index 00000000000..0ecab385c37 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xxrw-hw8c-v7g8/GHSA-xxrw-hw8c-v7g8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxrw-hw8c-v7g8", + "modified": "2024-10-11T15:30:32Z", + "published": "2024-10-11T15:30:32Z", + "aliases": [ + "CVE-2024-7514" + ], + "details": "The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during the comments import process, in versions up to, and including, 2.3.7. This makes it possible for authenticated attackers, with Author-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.\nThe issue was partially fixed in version 2.3.8 and fully fixed in 2.3.9", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7514" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/comments-import-export-woocommerce/tags/2.3.7/includes/importer/class-hf_cmt_impexpcsv-import.php#L346" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/30a79974-ee61-4764-8864-89659b1848a4?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-11T13:15:16Z" + } +} \ No newline at end of file