Publish Advisories

GHSA-259p-4x9p-wc8m
GHSA-4v79-g36g-gxp6
GHSA-9468-42qx-67cg
GHSA-f75p-j579-8r2c
GHSA-hqcp-27rh-hjjg
GHSA-qxv5-xxxc-xw7m
GHSA-vp77-7r82-hp2q
This commit is contained in:
advisory-database[bot]
2023-03-29 12:31:49 +00:00
parent 1048a18e84
commit 7a3431938c
7 changed files with 168 additions and 0 deletions
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-259p-4x9p-wc8m",
"modified": "2023-03-29T12:30:35Z",
"published": "2023-03-29T12:30:35Z",
"aliases": [
"CVE-2023-1689"
],
"details": "A vulnerability classified as problematic was found in SourceCodester Earnings and Expense Tracker App 1.0. This vulnerability affects unknown code of the file Master.php?a=save_earning. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-224308.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1689"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.224308"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.224308"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-03-29T10:15:00Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4v79-g36g-gxp6",
"modified": "2023-03-29T12:30:35Z",
"published": "2023-03-29T12:30:35Z",
"aliases": [
"CVE-2023-1509"
],
"details": "The GMAce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This is due to missing nonce validation on the gmace_manager_server function called via the wp_ajax_gmace_manager AJAX action. This makes it possible for unauthenticated attackers to modify arbitrary files and achieve remote code execution via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1509"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/gmace/trunk/gmace.php?rev=1583327#L84"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/gmace/trunk/inc/filemanager.php?rev=1583319#L27"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/826b3913-9a37-4e15-80fd-b35cefb51af8?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-03-29T11:15:00Z"
}
}
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38452"
},
{
"type": "WEB",
"url": "https://kb.netgear.com/000065567/Security-Advisory-for-Post-authentication-Command-Injection-on-the-RBR750-PSV-2022-0186"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2022-1595"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f75p-j579-8r2c",
"modified": "2023-03-29T12:30:35Z",
"published": "2023-03-29T12:30:35Z",
"aliases": [
"CVE-2023-0213"
],
"details": "Elevation of privilege issue in M-Files Installer versions before 22.6 on Windows allows user to gain SYSTEM privileges via DLL hijacking.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0213"
},
{
"type": "WEB",
"url": "https://www.m-files.com/about/trust-center/security-advisories/cve-2023-0213/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-03-29T11:15:00Z"
}
}
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37337"
},
{
"type": "WEB",
"url": "https://kb.netgear.com/000065417/Security-Advisory-for-Command-Injection-on-Some-Orbi-WiFi-Systems-PSV-2022-0187"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2022-1596"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36429"
},
{
"type": "WEB",
"url": "https://kb.netgear.com/000065424/Security-Advisory-for-Command-Injection-on-Some-Orbi-WiFi-Systems-PSV-2022-0188"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2022-1597"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vp77-7r82-hp2q",
"modified": "2023-03-29T12:30:34Z",
"published": "2023-03-29T12:30:34Z",
"aliases": [
"CVE-2023-1690"
],
"details": "A vulnerability, which was classified as problematic, has been found in SourceCodester Earnings and Expense Tracker App 1.0. This issue affects some unknown processing of the file LoginRegistration.php?a=register_user. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-224309 was assigned to this vulnerability.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1690"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.224309"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.224309"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-03-29T11:15:00Z"
}
}