From 77e0b31230cecbc1fa1d1a695a7b6a834a848a36 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 29 Mar 2024 18:32:09 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2gjv-8mpf-hmgr.json | 38 ++++++++++++++ .../GHSA-2v5w-v683-c839.json | 35 +++++++++++++ .../GHSA-3x6c-xfwc-qp7m.json | 43 ++++++++++++++++ .../GHSA-49fj-mjvv-64mx.json | 38 ++++++++++++++ .../GHSA-4xc2-vg9r-33pp.json | 38 ++++++++++++++ .../GHSA-57mr-mm8q-cx2c.json | 38 ++++++++++++++ .../GHSA-6826-vrr5-pj78.json | 38 ++++++++++++++ .../GHSA-73v2-rxqp-7q4f.json | 43 ++++++++++++++++ .../GHSA-7wv7-r7c6-6vxj.json | 38 ++++++++++++++ .../GHSA-84hj-9c53-vjg2.json | 38 ++++++++++++++ .../GHSA-8cj4-8jjc-q2wp.json | 38 ++++++++++++++ .../GHSA-8m9r-q2w3-mv25.json | 38 ++++++++++++++ .../GHSA-8q58-m2fq-vx7q.json | 38 ++++++++++++++ .../GHSA-8r5j-gm3j-cx9c.json | 39 +++++++++++++++ .../GHSA-9v2j-c2x9-mg6g.json | 38 ++++++++++++++ .../GHSA-c6xc-566p-8x98.json | 38 ++++++++++++++ .../GHSA-f24r-grxv-qh73.json | 38 ++++++++++++++ .../GHSA-f84j-qc2w-2jwg.json | 38 ++++++++++++++ .../GHSA-fqwf-c5xq-hmcf.json | 38 ++++++++++++++ .../GHSA-fr96-wc8w-hg4c.json | 38 ++++++++++++++ .../GHSA-fvj3-jc98-5xq5.json | 38 ++++++++++++++ .../GHSA-hc9j-3vxr-92w7.json | 38 ++++++++++++++ .../GHSA-hhx8-g69h-8rqr.json | 38 ++++++++++++++ .../GHSA-hphh-hmh6-f2pw.json | 38 ++++++++++++++ .../GHSA-jhpj-24rw-g99w.json | 38 ++++++++++++++ .../GHSA-m26f-2hcm-4fw2.json | 38 ++++++++++++++ .../GHSA-m3m6-68fj-x8xv.json | 38 ++++++++++++++ .../GHSA-m478-4q3h-f88g.json | 38 ++++++++++++++ .../GHSA-m966-6288-pj94.json | 35 +++++++++++++ .../GHSA-mxr2-5rww-vf6f.json | 38 ++++++++++++++ .../GHSA-p3j3-7mrp-gvwv.json | 38 ++++++++++++++ .../GHSA-p7hr-h6xh-x5wj.json | 38 ++++++++++++++ .../GHSA-pm5x-67pp-5cc7.json | 38 ++++++++++++++ .../GHSA-q5gv-8p63-3qrr.json | 38 ++++++++++++++ .../GHSA-qc2c-wgwh-39x8.json | 38 ++++++++++++++ .../GHSA-qrhf-rx22-ww4h.json | 38 ++++++++++++++ .../GHSA-qx2q-rhgv-qcr8.json | 38 ++++++++++++++ .../GHSA-rhmx-5882-q3qw.json | 35 +++++++++++++ .../GHSA-rm34-2767-5m5f.json | 38 ++++++++++++++ .../GHSA-rxwq-x6h5-x525.json | 50 +++++++++++++++++++ .../GHSA-v797-jg7x-7796.json | 38 ++++++++++++++ .../GHSA-vpp6-9fcm-rv58.json | 43 ++++++++++++++++ .../GHSA-w44h-wfp7-qpq7.json | 38 ++++++++++++++ .../GHSA-w56w-4mw9-32p3.json | 38 ++++++++++++++ .../GHSA-w7w6-42mw-922h.json | 38 ++++++++++++++ .../GHSA-wc86-g5f7-g83x.json | 38 ++++++++++++++ .../GHSA-wwf3-3r88-2q8v.json | 38 ++++++++++++++ .../GHSA-x9pr-7qrq-58vq.json | 43 ++++++++++++++++ 48 files changed, 1848 insertions(+) create mode 100644 advisories/unreviewed/2024/03/GHSA-2gjv-8mpf-hmgr/GHSA-2gjv-8mpf-hmgr.json create mode 100644 advisories/unreviewed/2024/03/GHSA-2v5w-v683-c839/GHSA-2v5w-v683-c839.json create mode 100644 advisories/unreviewed/2024/03/GHSA-3x6c-xfwc-qp7m/GHSA-3x6c-xfwc-qp7m.json create mode 100644 advisories/unreviewed/2024/03/GHSA-49fj-mjvv-64mx/GHSA-49fj-mjvv-64mx.json create mode 100644 advisories/unreviewed/2024/03/GHSA-4xc2-vg9r-33pp/GHSA-4xc2-vg9r-33pp.json create mode 100644 advisories/unreviewed/2024/03/GHSA-57mr-mm8q-cx2c/GHSA-57mr-mm8q-cx2c.json create mode 100644 advisories/unreviewed/2024/03/GHSA-6826-vrr5-pj78/GHSA-6826-vrr5-pj78.json create mode 100644 advisories/unreviewed/2024/03/GHSA-73v2-rxqp-7q4f/GHSA-73v2-rxqp-7q4f.json create mode 100644 advisories/unreviewed/2024/03/GHSA-7wv7-r7c6-6vxj/GHSA-7wv7-r7c6-6vxj.json create mode 100644 advisories/unreviewed/2024/03/GHSA-84hj-9c53-vjg2/GHSA-84hj-9c53-vjg2.json create mode 100644 advisories/unreviewed/2024/03/GHSA-8cj4-8jjc-q2wp/GHSA-8cj4-8jjc-q2wp.json create mode 100644 advisories/unreviewed/2024/03/GHSA-8m9r-q2w3-mv25/GHSA-8m9r-q2w3-mv25.json create mode 100644 advisories/unreviewed/2024/03/GHSA-8q58-m2fq-vx7q/GHSA-8q58-m2fq-vx7q.json create mode 100644 advisories/unreviewed/2024/03/GHSA-8r5j-gm3j-cx9c/GHSA-8r5j-gm3j-cx9c.json create mode 100644 advisories/unreviewed/2024/03/GHSA-9v2j-c2x9-mg6g/GHSA-9v2j-c2x9-mg6g.json create mode 100644 advisories/unreviewed/2024/03/GHSA-c6xc-566p-8x98/GHSA-c6xc-566p-8x98.json create mode 100644 advisories/unreviewed/2024/03/GHSA-f24r-grxv-qh73/GHSA-f24r-grxv-qh73.json create mode 100644 advisories/unreviewed/2024/03/GHSA-f84j-qc2w-2jwg/GHSA-f84j-qc2w-2jwg.json create mode 100644 advisories/unreviewed/2024/03/GHSA-fqwf-c5xq-hmcf/GHSA-fqwf-c5xq-hmcf.json create mode 100644 advisories/unreviewed/2024/03/GHSA-fr96-wc8w-hg4c/GHSA-fr96-wc8w-hg4c.json create mode 100644 advisories/unreviewed/2024/03/GHSA-fvj3-jc98-5xq5/GHSA-fvj3-jc98-5xq5.json create mode 100644 advisories/unreviewed/2024/03/GHSA-hc9j-3vxr-92w7/GHSA-hc9j-3vxr-92w7.json create mode 100644 advisories/unreviewed/2024/03/GHSA-hhx8-g69h-8rqr/GHSA-hhx8-g69h-8rqr.json create mode 100644 advisories/unreviewed/2024/03/GHSA-hphh-hmh6-f2pw/GHSA-hphh-hmh6-f2pw.json create mode 100644 advisories/unreviewed/2024/03/GHSA-jhpj-24rw-g99w/GHSA-jhpj-24rw-g99w.json create mode 100644 advisories/unreviewed/2024/03/GHSA-m26f-2hcm-4fw2/GHSA-m26f-2hcm-4fw2.json create mode 100644 advisories/unreviewed/2024/03/GHSA-m3m6-68fj-x8xv/GHSA-m3m6-68fj-x8xv.json create mode 100644 advisories/unreviewed/2024/03/GHSA-m478-4q3h-f88g/GHSA-m478-4q3h-f88g.json create mode 100644 advisories/unreviewed/2024/03/GHSA-m966-6288-pj94/GHSA-m966-6288-pj94.json create mode 100644 advisories/unreviewed/2024/03/GHSA-mxr2-5rww-vf6f/GHSA-mxr2-5rww-vf6f.json create mode 100644 advisories/unreviewed/2024/03/GHSA-p3j3-7mrp-gvwv/GHSA-p3j3-7mrp-gvwv.json create mode 100644 advisories/unreviewed/2024/03/GHSA-p7hr-h6xh-x5wj/GHSA-p7hr-h6xh-x5wj.json create mode 100644 advisories/unreviewed/2024/03/GHSA-pm5x-67pp-5cc7/GHSA-pm5x-67pp-5cc7.json create mode 100644 advisories/unreviewed/2024/03/GHSA-q5gv-8p63-3qrr/GHSA-q5gv-8p63-3qrr.json create mode 100644 advisories/unreviewed/2024/03/GHSA-qc2c-wgwh-39x8/GHSA-qc2c-wgwh-39x8.json create mode 100644 advisories/unreviewed/2024/03/GHSA-qrhf-rx22-ww4h/GHSA-qrhf-rx22-ww4h.json create mode 100644 advisories/unreviewed/2024/03/GHSA-qx2q-rhgv-qcr8/GHSA-qx2q-rhgv-qcr8.json create mode 100644 advisories/unreviewed/2024/03/GHSA-rhmx-5882-q3qw/GHSA-rhmx-5882-q3qw.json create mode 100644 advisories/unreviewed/2024/03/GHSA-rm34-2767-5m5f/GHSA-rm34-2767-5m5f.json create mode 100644 advisories/unreviewed/2024/03/GHSA-rxwq-x6h5-x525/GHSA-rxwq-x6h5-x525.json create mode 100644 advisories/unreviewed/2024/03/GHSA-v797-jg7x-7796/GHSA-v797-jg7x-7796.json create mode 100644 advisories/unreviewed/2024/03/GHSA-vpp6-9fcm-rv58/GHSA-vpp6-9fcm-rv58.json create mode 100644 advisories/unreviewed/2024/03/GHSA-w44h-wfp7-qpq7/GHSA-w44h-wfp7-qpq7.json create mode 100644 advisories/unreviewed/2024/03/GHSA-w56w-4mw9-32p3/GHSA-w56w-4mw9-32p3.json create mode 100644 advisories/unreviewed/2024/03/GHSA-w7w6-42mw-922h/GHSA-w7w6-42mw-922h.json create mode 100644 advisories/unreviewed/2024/03/GHSA-wc86-g5f7-g83x/GHSA-wc86-g5f7-g83x.json create mode 100644 advisories/unreviewed/2024/03/GHSA-wwf3-3r88-2q8v/GHSA-wwf3-3r88-2q8v.json create mode 100644 advisories/unreviewed/2024/03/GHSA-x9pr-7qrq-58vq/GHSA-x9pr-7qrq-58vq.json diff --git a/advisories/unreviewed/2024/03/GHSA-2gjv-8mpf-hmgr/GHSA-2gjv-8mpf-hmgr.json b/advisories/unreviewed/2024/03/GHSA-2gjv-8mpf-hmgr/GHSA-2gjv-8mpf-hmgr.json new file mode 100644 index 00000000000..04ab63311ee --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2gjv-8mpf-hmgr/GHSA-2gjv-8mpf-hmgr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gjv-8mpf-hmgr", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30432" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Slider - Slider for your block editor allows Stored XSS.This issue affects B Slider - Slider for your block editor: from n/a through 1.1.12.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30432" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/b-slider/wordpress-b-slider-plugin-1-1-12-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-2v5w-v683-c839/GHSA-2v5w-v683-c839.json b/advisories/unreviewed/2024/03/GHSA-2v5w-v683-c839/GHSA-2v5w-v683-c839.json new file mode 100644 index 00000000000..64b11e90781 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2v5w-v683-c839/GHSA-2v5w-v683-c839.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2v5w-v683-c839", + "modified": "2024-03-29T18:30:42Z", + "published": "2024-03-29T18:30:42Z", + "aliases": [ + "CVE-2024-30645" + ], + "details": "Tenda AC15V1.0 V15.03.20_multi has a command injection vulnerability via the deviceName parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30645" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/AC15/V1.0%20V15.03.20_multi/setUsbUnload.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-3x6c-xfwc-qp7m/GHSA-3x6c-xfwc-qp7m.json b/advisories/unreviewed/2024/03/GHSA-3x6c-xfwc-qp7m/GHSA-3x6c-xfwc-qp7m.json new file mode 100644 index 00000000000..c1b55cdb3af --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3x6c-xfwc-qp7m/GHSA-3x6c-xfwc-qp7m.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x6c-xfwc-qp7m", + "modified": "2024-03-29T18:30:42Z", + "published": "2024-03-29T18:30:42Z", + "aliases": [ + "CVE-2023-49234" + ], + "details": "An XML external entity (XXE) vulnerability was found in Stilog Visual Planning 8. It allows an authenticated attacker to access local server files and exfiltrate data to an external server.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49234" + }, + { + "type": "WEB", + "url": "https://www.schutzwerk.com/advisories/SCHUTZWERK-SA-2023-006.txt" + }, + { + "type": "WEB", + "url": "https://www.schutzwerk.com/blog/schutzwerk-sa-2023-006" + }, + { + "type": "WEB", + "url": "https://www.visual-planning.com/en/support-portal/updates" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-49fj-mjvv-64mx/GHSA-49fj-mjvv-64mx.json b/advisories/unreviewed/2024/03/GHSA-49fj-mjvv-64mx/GHSA-49fj-mjvv-64mx.json new file mode 100644 index 00000000000..2bf6adf9689 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-49fj-mjvv-64mx/GHSA-49fj-mjvv-64mx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49fj-mjvv-64mx", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30440" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Themify Event Post allows Stored XSS.This issue affects Themify Event Post: from n/a through 1.2.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30440" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/themify-event-post/wordpress-themify-event-post-plugin-1-2-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-4xc2-vg9r-33pp/GHSA-4xc2-vg9r-33pp.json b/advisories/unreviewed/2024/03/GHSA-4xc2-vg9r-33pp/GHSA-4xc2-vg9r-33pp.json new file mode 100644 index 00000000000..ec00a40f62f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4xc2-vg9r-33pp/GHSA-4xc2-vg9r-33pp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xc2-vg9r-33pp", + "modified": "2024-03-29T18:30:42Z", + "published": "2024-03-29T18:30:42Z", + "aliases": [ + "CVE-2024-30518" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30518" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/add-fields-to-checkout-page-woocommerce/wordpress-custom-woocommerce-checkout-fields-editor-plugin-1-3-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-57mr-mm8q-cx2c/GHSA-57mr-mm8q-cx2c.json b/advisories/unreviewed/2024/03/GHSA-57mr-mm8q-cx2c/GHSA-57mr-mm8q-cx2c.json new file mode 100644 index 00000000000..5f375095d98 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-57mr-mm8q-cx2c/GHSA-57mr-mm8q-cx2c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57mr-mm8q-cx2c", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30439" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BestWebSoft Limit Attempts by BestWebSoft allows Reflected XSS.This issue affects Limit Attempts by BestWebSoft: from n/a through 1.2.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30439" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/limit-attempts/wordpress-limit-attempts-by-bestwebsoft-plugin-1-2-9-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6826-vrr5-pj78/GHSA-6826-vrr5-pj78.json b/advisories/unreviewed/2024/03/GHSA-6826-vrr5-pj78/GHSA-6826-vrr5-pj78.json new file mode 100644 index 00000000000..56cb08761f0 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6826-vrr5-pj78/GHSA-6826-vrr5-pj78.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6826-vrr5-pj78", + "modified": "2024-03-29T18:30:42Z", + "published": "2024-03-29T18:30:42Z", + "aliases": [ + "CVE-2024-30446" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms allows Stored XSS.This issue affects CRM Perks Forms: from n/a through 1.1.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30446" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/crm-perks-forms/wordpress-crm-perks-forms-plugin-1-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-73v2-rxqp-7q4f/GHSA-73v2-rxqp-7q4f.json b/advisories/unreviewed/2024/03/GHSA-73v2-rxqp-7q4f/GHSA-73v2-rxqp-7q4f.json new file mode 100644 index 00000000000..38a2b33f415 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-73v2-rxqp-7q4f/GHSA-73v2-rxqp-7q4f.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73v2-rxqp-7q4f", + "modified": "2024-03-29T18:30:42Z", + "published": "2024-03-29T18:30:42Z", + "aliases": [ + "CVE-2024-29640" + ], + "details": "An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameter in the action_query_qrcode component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29640" + }, + { + "type": "WEB", + "url": "https://github.com/lakemoon602/vuln/blob/main/detail.md" + }, + { + "type": "WEB", + "url": "https://github.com/messense/aliyundrive-webdav" + }, + { + "type": "WEB", + "url": "http://aliyundrive-webdav.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7wv7-r7c6-6vxj/GHSA-7wv7-r7c6-6vxj.json b/advisories/unreviewed/2024/03/GHSA-7wv7-r7c6-6vxj/GHSA-7wv7-r7c6-6vxj.json new file mode 100644 index 00000000000..f8cbda21b88 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7wv7-r7c6-6vxj/GHSA-7wv7-r7c6-6vxj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wv7-r7c6-6vxj", + "modified": "2024-03-29T18:30:42Z", + "published": "2024-03-29T18:30:42Z", + "aliases": [ + "CVE-2024-30482" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Brice CAPOBIANCO Simple Revisions Delete.This issue affects Simple Revisions Delete: from n/a through 1.5.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30482" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/simple-revisions-delete/wordpress-simple-revisions-delete-plugin-1-5-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-84hj-9c53-vjg2/GHSA-84hj-9c53-vjg2.json b/advisories/unreviewed/2024/03/GHSA-84hj-9c53-vjg2/GHSA-84hj-9c53-vjg2.json new file mode 100644 index 00000000000..433bcff5efb --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-84hj-9c53-vjg2/GHSA-84hj-9c53-vjg2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84hj-9c53-vjg2", + "modified": "2024-03-29T18:30:42Z", + "published": "2024-03-29T18:30:42Z", + "aliases": [ + "CVE-2024-30513" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30513" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/profilegrid-user-profiles-groups-and-communities/wordpress-profilegrid-plugin-5-7-2-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8cj4-8jjc-q2wp/GHSA-8cj4-8jjc-q2wp.json b/advisories/unreviewed/2024/03/GHSA-8cj4-8jjc-q2wp/GHSA-8cj4-8jjc-q2wp.json new file mode 100644 index 00000000000..90dcbe04c43 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8cj4-8jjc-q2wp/GHSA-8cj4-8jjc-q2wp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cj4-8jjc-q2wp", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30433" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MultiVendorX WC Marketplace allows Stored XSS.This issue affects WC Marketplace: from n/a through 4.1.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30433" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/dc-woocommerce-multi-vendor/wordpress-multivendorx-marketplace-plugin-4-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8m9r-q2w3-mv25/GHSA-8m9r-q2w3-mv25.json b/advisories/unreviewed/2024/03/GHSA-8m9r-q2w3-mv25/GHSA-8m9r-q2w3-mv25.json new file mode 100644 index 00000000000..f3f3726c7cf --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8m9r-q2w3-mv25/GHSA-8m9r-q2w3-mv25.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m9r-q2w3-mv25", + "modified": "2024-03-29T18:30:42Z", + "published": "2024-03-29T18:30:42Z", + "aliases": [ + "CVE-2024-30445" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab, Inc. Web Icons allows Stored XSS.This issue affects Web Icons: from n/a through 1.0.0.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30445" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/icon/wordpress-web-icons-plugin-1-0-0-10-cross-site-scripting-xss-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8q58-m2fq-vx7q/GHSA-8q58-m2fq-vx7q.json b/advisories/unreviewed/2024/03/GHSA-8q58-m2fq-vx7q/GHSA-8q58-m2fq-vx7q.json new file mode 100644 index 00000000000..03d24445bde --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8q58-m2fq-vx7q/GHSA-8q58-m2fq-vx7q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q58-m2fq-vx7q", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30452" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Landing Page Builder allows Stored XSS.This issue affects Landing Page Builder: from n/a through 1.5.1.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30452" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/page-builder-add/wordpress-landing-page-builder-plugin-1-5-1-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8r5j-gm3j-cx9c/GHSA-8r5j-gm3j-cx9c.json b/advisories/unreviewed/2024/03/GHSA-8r5j-gm3j-cx9c/GHSA-8r5j-gm3j-cx9c.json new file mode 100644 index 00000000000..a9639a86a4c --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8r5j-gm3j-cx9c/GHSA-8r5j-gm3j-cx9c.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r5j-gm3j-cx9c", + "modified": "2024-03-29T18:30:42Z", + "published": "2024-03-29T18:30:42Z", + "aliases": [ + "CVE-2024-29686" + ], + "details": "Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted payload to the CMS Pages field and Plugin components.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29686" + }, + { + "type": "WEB", + "url": "https://forum.ksec.co.uk/t/webapps-winter-cms-1-2-3-server-side-template-injection-ssti-authenticated/2779" + }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/51893" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9v2j-c2x9-mg6g/GHSA-9v2j-c2x9-mg6g.json b/advisories/unreviewed/2024/03/GHSA-9v2j-c2x9-mg6g/GHSA-9v2j-c2x9-mg6g.json new file mode 100644 index 00000000000..170cc8925f9 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9v2j-c2x9-mg6g/GHSA-9v2j-c2x9-mg6g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v2j-c2x9-mg6g", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30449" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Booking Activities Team Booking Activities allows Reflected XSS.This issue affects Booking Activities: from n/a through 1.15.19.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30449" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/booking-activities/wordpress-booking-activities-plugin-1-15-19-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-c6xc-566p-8x98/GHSA-c6xc-566p-8x98.json b/advisories/unreviewed/2024/03/GHSA-c6xc-566p-8x98/GHSA-c6xc-566p-8x98.json new file mode 100644 index 00000000000..ba33eaaa3ae --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-c6xc-566p-8x98/GHSA-c6xc-566p-8x98.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6xc-566p-8x98", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30447" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative Solutions Creative Image Slider – Responsive Slider Plugin allows Reflected XSS.This issue affects Creative Image Slider – Responsive Slider Plugin: from n/a through 2.1.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30447" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/creative-image-slider/wordpress-creative-image-slider-plugin-2-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-f24r-grxv-qh73/GHSA-f24r-grxv-qh73.json b/advisories/unreviewed/2024/03/GHSA-f24r-grxv-qh73/GHSA-f24r-grxv-qh73.json new file mode 100644 index 00000000000..b7e6c219a68 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-f24r-grxv-qh73/GHSA-f24r-grxv-qh73.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f24r-grxv-qh73", + "modified": "2024-03-29T18:30:42Z", + "published": "2024-03-29T18:30:42Z", + "aliases": [ + "CVE-2024-30521" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Landingi Landingi Landing Pages.This issue affects Landingi Landing Pages: from n/a through 3.1.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30521" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/landingi-landing-pages/wordpress-landingi-landing-pages-plugin-3-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-f84j-qc2w-2jwg/GHSA-f84j-qc2w-2jwg.json b/advisories/unreviewed/2024/03/GHSA-f84j-qc2w-2jwg/GHSA-f84j-qc2w-2jwg.json new file mode 100644 index 00000000000..72de1b2dedf --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-f84j-qc2w-2jwg/GHSA-f84j-qc2w-2jwg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f84j-qc2w-2jwg", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30441" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Post Grid allows Reflected XSS.This issue affects Post Grid: from n/a through 2.2.74.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30441" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/post-grid/wordpress-combo-blocks-plugin-2-2-74-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fqwf-c5xq-hmcf/GHSA-fqwf-c5xq-hmcf.json b/advisories/unreviewed/2024/03/GHSA-fqwf-c5xq-hmcf/GHSA-fqwf-c5xq-hmcf.json new file mode 100644 index 00000000000..ae6e0c7e9a1 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fqwf-c5xq-hmcf/GHSA-fqwf-c5xq-hmcf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqwf-c5xq-hmcf", + "modified": "2024-03-29T18:30:42Z", + "published": "2024-03-29T18:30:42Z", + "aliases": [ + "CVE-2024-30511" + ], + "details": "Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce.This issue affects FG PrestaShop to WooCommerce: from n/a through 4.45.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30511" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/fg-prestashop-to-woocommerce/wordpress-fg-prestashop-to-woocommerce-plugin-4-45-1-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fr96-wc8w-hg4c/GHSA-fr96-wc8w-hg4c.json b/advisories/unreviewed/2024/03/GHSA-fr96-wc8w-hg4c/GHSA-fr96-wc8w-hg4c.json new file mode 100644 index 00000000000..a7822db4dd6 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fr96-wc8w-hg4c/GHSA-fr96-wc8w-hg4c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr96-wc8w-hg4c", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30453" + ], + "details": "Server-Side Request Forgery (SSRF) vulnerability in Brave Brave Popup Builder.This issue affects Brave Popup Builder: from n/a through 0.6.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30453" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/brave-popup-builder/wordpress-brave-plugin-0-6-5-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fvj3-jc98-5xq5/GHSA-fvj3-jc98-5xq5.json b/advisories/unreviewed/2024/03/GHSA-fvj3-jc98-5xq5/GHSA-fvj3-jc98-5xq5.json new file mode 100644 index 00000000000..20015d4216f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fvj3-jc98-5xq5/GHSA-fvj3-jc98-5xq5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvj3-jc98-5xq5", + "modified": "2024-03-29T18:30:42Z", + "published": "2024-03-29T18:30:42Z", + "aliases": [ + "CVE-2024-30477" + ], + "details": "Missing Authorization vulnerability in Klarna Klarna Payments for WooCommerce.This issue affects Klarna Payments for WooCommerce: from n/a through 3.2.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30477" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/klarna-payments-for-woocommerce/wordpress-klarna-payments-for-woocommerce-plugin-3-2-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-hc9j-3vxr-92w7/GHSA-hc9j-3vxr-92w7.json b/advisories/unreviewed/2024/03/GHSA-hc9j-3vxr-92w7/GHSA-hc9j-3vxr-92w7.json new file mode 100644 index 00000000000..c990f5d7914 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-hc9j-3vxr-92w7/GHSA-hc9j-3vxr-92w7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc9j-3vxr-92w7", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30435" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Blocks for Block Editor | Gutenberg allows Reflected XSS.This issue affects The Plus Blocks for Block Editor | Gutenberg: from n/a through 3.2.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30435" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/the-plus-addons-for-block-editor/wordpress-the-plus-blocks-for-block-editor-gutenberg-plugin-3-2-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-hhx8-g69h-8rqr/GHSA-hhx8-g69h-8rqr.json b/advisories/unreviewed/2024/03/GHSA-hhx8-g69h-8rqr/GHSA-hhx8-g69h-8rqr.json new file mode 100644 index 00000000000..72de5d1e5c2 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-hhx8-g69h-8rqr/GHSA-hhx8-g69h-8rqr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhx8-g69h-8rqr", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30455" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in GamiPress.This issue affects GamiPress: from n/a through 6.8.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30455" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/gamipress/wordpress-gamipress-plugin-6-8-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-hphh-hmh6-f2pw/GHSA-hphh-hmh6-f2pw.json b/advisories/unreviewed/2024/03/GHSA-hphh-hmh6-f2pw/GHSA-hphh-hmh6-f2pw.json new file mode 100644 index 00000000000..866b311e937 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-hphh-hmh6-f2pw/GHSA-hphh-hmh6-f2pw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hphh-hmh6-f2pw", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30443" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GS Plugins GS Testimonial Slider allows Stored XSS.This issue affects GS Testimonial Slider: from n/a through 3.1.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30443" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/gs-testimonial/wordpress-gs-testimonial-slider-plugin-3-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-jhpj-24rw-g99w/GHSA-jhpj-24rw-g99w.json b/advisories/unreviewed/2024/03/GHSA-jhpj-24rw-g99w/GHSA-jhpj-24rw-g99w.json new file mode 100644 index 00000000000..935535e1f93 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-jhpj-24rw-g99w/GHSA-jhpj-24rw-g99w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhpj-24rw-g99w", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30431" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hometory Mang Board WP allows Reflected XSS.This issue affects Mang Board WP: from n/a through 1.8.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30431" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mangboard/wordpress-mang-board-wp-plugin-1-8-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-m26f-2hcm-4fw2/GHSA-m26f-2hcm-4fw2.json b/advisories/unreviewed/2024/03/GHSA-m26f-2hcm-4fw2/GHSA-m26f-2hcm-4fw2.json new file mode 100644 index 00000000000..f528e634fb2 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-m26f-2hcm-4fw2/GHSA-m26f-2hcm-4fw2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m26f-2hcm-4fw2", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30450" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Step-Byte-Service GmbH OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) allows Stored XSS.This issue affects OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer): from n/a through 1.1.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30450" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/stepbyteservice-openstreetmap/wordpress-openstreetmap-for-gutenberg-and-wpbakery-page-builder-plugin-1-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-m3m6-68fj-x8xv/GHSA-m3m6-68fj-x8xv.json b/advisories/unreviewed/2024/03/GHSA-m3m6-68fj-x8xv/GHSA-m3m6-68fj-x8xv.json new file mode 100644 index 00000000000..888b33a32e6 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-m3m6-68fj-x8xv/GHSA-m3m6-68fj-x8xv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3m6-68fj-x8xv", + "modified": "2024-03-29T18:30:42Z", + "published": "2024-03-29T18:30:42Z", + "aliases": [ + "CVE-2024-25944" + ], + "details": "Dell OpenManage Enterprise, v4.0 and prior, contain(s) a path traversal vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, to gain unauthorized access to the files stored on the server filesystem, with the privileges of the running web application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25944" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000223623/dsa-2024-100-security-update-for-dell-openmanage-enterprise-path-traversal-sensitive-data-disclosure-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-m478-4q3h-f88g/GHSA-m478-4q3h-f88g.json b/advisories/unreviewed/2024/03/GHSA-m478-4q3h-f88g/GHSA-m478-4q3h-f88g.json new file mode 100644 index 00000000000..58d1ae01387 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-m478-4q3h-f88g/GHSA-m478-4q3h-f88g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m478-4q3h-f88g", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30437" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL Webinar and Video Conference with Jitsi Meet allows Stored XSS.This issue affects Webinar and Video Conference with Jitsi Meet: from n/a through 2.6.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30437" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/webinar-and-video-conference-with-jitsi-meet/wordpress-webinar-and-video-conference-with-jitsi-meet-plugin-2-6-3-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-m966-6288-pj94/GHSA-m966-6288-pj94.json b/advisories/unreviewed/2024/03/GHSA-m966-6288-pj94/GHSA-m966-6288-pj94.json new file mode 100644 index 00000000000..65e5a26ece8 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-m966-6288-pj94/GHSA-m966-6288-pj94.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m966-6288-pj94", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-31032" + ], + "details": "An issue in Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport v.1.1.2 allows a remote attacker to execute arbitrary code via the manager/ipping.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31032" + }, + { + "type": "WEB", + "url": "https://github.com/whgojp/cve-reports/blob/master/Huashi_Private_Cloud_CDN_Live_Streaming_Acceleration_Server_Has_RCE_Vulnerability/report.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-mxr2-5rww-vf6f/GHSA-mxr2-5rww-vf6f.json b/advisories/unreviewed/2024/03/GHSA-mxr2-5rww-vf6f/GHSA-mxr2-5rww-vf6f.json new file mode 100644 index 00000000000..dce86562a54 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-mxr2-5rww-vf6f/GHSA-mxr2-5rww-vf6f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxr2-5rww-vf6f", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30438" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Print Page block allows Stored XSS.This issue affects Print Page block: from n/a through 1.0.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30438" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/print-page/wordpress-print-page-block-plugin-1-0-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p3j3-7mrp-gvwv/GHSA-p3j3-7mrp-gvwv.json b/advisories/unreviewed/2024/03/GHSA-p3j3-7mrp-gvwv/GHSA-p3j3-7mrp-gvwv.json new file mode 100644 index 00000000000..cd46970dc56 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p3j3-7mrp-gvwv/GHSA-p3j3-7mrp-gvwv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3j3-7mrp-gvwv", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30442" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through 4.8.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30442" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bold-page-builder/wordpress-bold-page-builder-plugin-4-8-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p7hr-h6xh-x5wj/GHSA-p7hr-h6xh-x5wj.json b/advisories/unreviewed/2024/03/GHSA-p7hr-h6xh-x5wj/GHSA-p7hr-h6xh-x5wj.json new file mode 100644 index 00000000000..2e859c1833e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p7hr-h6xh-x5wj/GHSA-p7hr-h6xh-x5wj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7hr-h6xh-x5wj", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30434" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-CRM System allows Stored XSS.This issue affects WP-CRM System: from n/a through 3.2.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30434" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-crm-system/wordpress-wp-crm-system-plugin-3-2-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-pm5x-67pp-5cc7/GHSA-pm5x-67pp-5cc7.json b/advisories/unreviewed/2024/03/GHSA-pm5x-67pp-5cc7/GHSA-pm5x-67pp-5cc7.json new file mode 100644 index 00000000000..0aa7b6b21a1 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-pm5x-67pp-5cc7/GHSA-pm5x-67pp-5cc7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pm5x-67pp-5cc7", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30451" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in INFINITUM FORM Geo Controller allows Stored XSS.This issue affects Geo Controller: from n/a through 8.6.4.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30451" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cf-geoplugin/wordpress-geo-controller-plugin-8-6-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-q5gv-8p63-3qrr/GHSA-q5gv-8p63-3qrr.json b/advisories/unreviewed/2024/03/GHSA-q5gv-8p63-3qrr/GHSA-q5gv-8p63-3qrr.json new file mode 100644 index 00000000000..03df73985d2 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-q5gv-8p63-3qrr/GHSA-q5gv-8p63-3qrr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5gv-8p63-3qrr", + "modified": "2024-03-29T18:30:42Z", + "published": "2024-03-29T18:30:42Z", + "aliases": [ + "CVE-2024-30514" + ], + "details": "Insertion of Sensitive Information into Log File vulnerability in Paid Memberships Pro Paid Memberships Pro – Payfast Gateway Add On.This issue affects Paid Memberships Pro – Payfast Gateway Add On: from n/a through 1.4.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30514" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pmpro-payfast/wordpress-paid-memberships-pro-payfast-gateway-add-on-plugin-1-4-1-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qc2c-wgwh-39x8/GHSA-qc2c-wgwh-39x8.json b/advisories/unreviewed/2024/03/GHSA-qc2c-wgwh-39x8/GHSA-qc2c-wgwh-39x8.json new file mode 100644 index 00000000000..9375615d9c3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qc2c-wgwh-39x8/GHSA-qc2c-wgwh-39x8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc2c-wgwh-39x8", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30436" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Collect.Chat Inc. Collectchat allows Stored XSS.This issue affects Collectchat: from n/a through 2.4.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30436" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/collectchat/wordpress-collect-chat-plugin-2-4-1-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qrhf-rx22-ww4h/GHSA-qrhf-rx22-ww4h.json b/advisories/unreviewed/2024/03/GHSA-qrhf-rx22-ww4h/GHSA-qrhf-rx22-ww4h.json new file mode 100644 index 00000000000..6c064eec36b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qrhf-rx22-ww4h/GHSA-qrhf-rx22-ww4h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrhf-rx22-ww4h", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30454" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.6.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30454" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-sms/wordpress-wp-sms-plugin-6-6-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qx2q-rhgv-qcr8/GHSA-qx2q-rhgv-qcr8.json b/advisories/unreviewed/2024/03/GHSA-qx2q-rhgv-qcr8/GHSA-qx2q-rhgv-qcr8.json new file mode 100644 index 00000000000..71d737e435f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qx2q-rhgv-qcr8/GHSA-qx2q-rhgv-qcr8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qx2q-rhgv-qcr8", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30468" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in All In One WP Security & Firewall Team All In One WP Security & Firewall.This issue affects All In One WP Security & Firewall: from n/a through 5.2.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30468" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/all-in-one-wp-security-and-firewall/wordpress-all-in-one-security-aios-security-and-firewall-plugin-5-2-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rhmx-5882-q3qw/GHSA-rhmx-5882-q3qw.json b/advisories/unreviewed/2024/03/GHSA-rhmx-5882-q3qw/GHSA-rhmx-5882-q3qw.json new file mode 100644 index 00000000000..a1580f09992 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rhmx-5882-q3qw/GHSA-rhmx-5882-q3qw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhmx-5882-q3qw", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-29667" + ], + "details": "SQL Injection vulnerability in Tongtianxing Technology Co., Ltd CMSV6 v.7.31.0.2 through v.7.31.0.3 allows a remote attacker to escalate privileges and obtain sensitive information via the ids parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29667" + }, + { + "type": "WEB", + "url": "https://github.com/whgojp/cve-reports/wiki/CMSV6-vehicle-monitoring-platform-system-SQL-injection" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rm34-2767-5m5f/GHSA-rm34-2767-5m5f.json b/advisories/unreviewed/2024/03/GHSA-rm34-2767-5m5f/GHSA-rm34-2767-5m5f.json new file mode 100644 index 00000000000..7fb8c2cb0f1 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rm34-2767-5m5f/GHSA-rm34-2767-5m5f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm34-2767-5m5f", + "modified": "2024-03-29T18:30:42Z", + "published": "2024-03-29T18:30:42Z", + "aliases": [ + "CVE-2024-30444" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zionbuilder.Io WordPress Page Builder – Zion Builder allows Stored XSS.This issue affects WordPress Page Builder – Zion Builder: from n/a through 3.6.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30444" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/zionbuilder/wordpress-wordpress-page-builder-zion-builder-plugin-3-6-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rxwq-x6h5-x525/GHSA-rxwq-x6h5-x525.json b/advisories/unreviewed/2024/03/GHSA-rxwq-x6h5-x525/GHSA-rxwq-x6h5-x525.json new file mode 100644 index 00000000000..1a4ea38d7f5 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rxwq-x6h5-x525/GHSA-rxwq-x6h5-x525.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxwq-x6h5-x525", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-3094" + ], + "details": "Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. The tarballs included extra .m4 files, which contained instructions for building with automake that did not exist in the repository. These instructions, through a series of complex obfuscations, extract a prebuilt object file from one of the test archives, which is then used to modify specific functions in the code while building the liblzma package. This issue results in liblzma being used by additional software, like sshd, to provide functionality that will be interpreted by the modified functions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3094" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-3094" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2272210" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/03/29/4" + }, + { + "type": "WEB", + "url": "https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-506" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-v797-jg7x-7796/GHSA-v797-jg7x-7796.json b/advisories/unreviewed/2024/03/GHSA-v797-jg7x-7796/GHSA-v797-jg7x-7796.json new file mode 100644 index 00000000000..f0fa60778c3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-v797-jg7x-7796/GHSA-v797-jg7x-7796.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v797-jg7x-7796", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30448" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Supsystic Slider by Supsystic allows Stored XSS.This issue affects Slider by Supsystic: from n/a through 1.8.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30448" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/slider-by-supsystic/wordpress-slider-by-supsystic-plugin-1-8-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-vpp6-9fcm-rv58/GHSA-vpp6-9fcm-rv58.json b/advisories/unreviewed/2024/03/GHSA-vpp6-9fcm-rv58/GHSA-vpp6-9fcm-rv58.json new file mode 100644 index 00000000000..2f0cea20888 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-vpp6-9fcm-rv58/GHSA-vpp6-9fcm-rv58.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpp6-9fcm-rv58", + "modified": "2024-03-29T18:30:42Z", + "published": "2024-03-29T18:30:42Z", + "aliases": [ + "CVE-2023-49231" + ], + "details": "An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to receive an administrative API token.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49231" + }, + { + "type": "WEB", + "url": "https://www.schutzwerk.com/advisories/SCHUTZWERK-SA-2023-003.txt" + }, + { + "type": "WEB", + "url": "https://www.schutzwerk.com/blog/schutzwerk-sa-2023-003" + }, + { + "type": "WEB", + "url": "https://www.visual-planning.com/en/support-portal/updates" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-w44h-wfp7-qpq7/GHSA-w44h-wfp7-qpq7.json b/advisories/unreviewed/2024/03/GHSA-w44h-wfp7-qpq7/GHSA-w44h-wfp7-qpq7.json new file mode 100644 index 00000000000..4327693f949 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-w44h-wfp7-qpq7/GHSA-w44h-wfp7-qpq7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w44h-wfp7-qpq7", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30463" + ], + "details": "Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.3.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30463" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woo-bulk-editor/wordpress-bear-plugin-1-1-4-3-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-w56w-4mw9-32p3/GHSA-w56w-4mw9-32p3.json b/advisories/unreviewed/2024/03/GHSA-w56w-4mw9-32p3/GHSA-w56w-4mw9-32p3.json new file mode 100644 index 00000000000..a1d8661bf05 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-w56w-4mw9-32p3/GHSA-w56w-4mw9-32p3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w56w-4mw9-32p3", + "modified": "2024-03-29T18:30:42Z", + "published": "2024-03-29T18:30:42Z", + "aliases": [ + "CVE-2024-30492" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a through 2.5.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30492" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/users-customers-import-export-for-wp-woocommerce/wordpress-export-and-import-users-and-customers-plugin-2-5-2-path-traversal-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-w7w6-42mw-922h/GHSA-w7w6-42mw-922h.json b/advisories/unreviewed/2024/03/GHSA-w7w6-42mw-922h/GHSA-w7w6-42mw-922h.json new file mode 100644 index 00000000000..dbc50dcc414 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-w7w6-42mw-922h/GHSA-w7w6-42mw-922h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7w6-42mw-922h", + "modified": "2024-03-29T18:30:42Z", + "published": "2024-03-29T18:30:42Z", + "aliases": [ + "CVE-2024-30469" + ], + "details": "Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce: from n/a through 2.3.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30469" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-wholesale-pricing/wordpress-wholesale-for-woocommerce-plugin-2-3-0-unauthenticated-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-wc86-g5f7-g83x/GHSA-wc86-g5f7-g83x.json b/advisories/unreviewed/2024/03/GHSA-wc86-g5f7-g83x/GHSA-wc86-g5f7-g83x.json new file mode 100644 index 00000000000..19cd793bf77 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-wc86-g5f7-g83x/GHSA-wc86-g5f7-g83x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc86-g5f7-g83x", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30460" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Tumult Inc Tumult Hype Animations.This issue affects Tumult Hype Animations: from n/a through 1.9.11.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30460" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/tumult-hype-animations/wordpress-tumult-hype-animations-plugin-1-9-11-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-wwf3-3r88-2q8v/GHSA-wwf3-3r88-2q8v.json b/advisories/unreviewed/2024/03/GHSA-wwf3-3r88-2q8v/GHSA-wwf3-3r88-2q8v.json new file mode 100644 index 00000000000..1689262021e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-wwf3-3r88-2q8v/GHSA-wwf3-3r88-2q8v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwf3-3r88-2q8v", + "modified": "2024-03-29T18:30:43Z", + "published": "2024-03-29T18:30:43Z", + "aliases": [ + "CVE-2024-30462" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in realmag777 HUSKY – Products Filter for WooCommerce (formerly WOOF).This issue affects HUSKY – Products Filter for WooCommerce (formerly WOOF): from n/a through 1.3.5.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30462" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-products-filter/wordpress-husky-plugin-1-3-5-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-x9pr-7qrq-58vq/GHSA-x9pr-7qrq-58vq.json b/advisories/unreviewed/2024/03/GHSA-x9pr-7qrq-58vq/GHSA-x9pr-7qrq-58vq.json new file mode 100644 index 00000000000..585f1ece98e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-x9pr-7qrq-58vq/GHSA-x9pr-7qrq-58vq.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9pr-7qrq-58vq", + "modified": "2024-03-29T18:30:42Z", + "published": "2024-03-29T18:30:42Z", + "aliases": [ + "CVE-2023-49232" + ], + "details": "An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to brute-force the password reset PINs of administrative users.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49232" + }, + { + "type": "WEB", + "url": "https://www.schutzwerk.com/advisories/SCHUTZWERK-SA-2023-004.txt" + }, + { + "type": "WEB", + "url": "https://www.schutzwerk.com/blog/schutzwerk-sa-2023-004" + }, + { + "type": "WEB", + "url": "https://www.visual-planning.com/en/support-portal/updates" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-29T17:15:11Z" + } +} \ No newline at end of file