diff --git a/advisories/unreviewed/2023/03/GHSA-259p-4x9p-wc8m/GHSA-259p-4x9p-wc8m.json b/advisories/unreviewed/2023/03/GHSA-259p-4x9p-wc8m/GHSA-259p-4x9p-wc8m.json new file mode 100644 index 00000000000..ca5906e9c38 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-259p-4x9p-wc8m/GHSA-259p-4x9p-wc8m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-259p-4x9p-wc8m", + "modified": "2023-03-29T12:30:35Z", + "published": "2023-03-29T12:30:35Z", + "aliases": [ + "CVE-2023-1689" + ], + "details": "A vulnerability classified as problematic was found in SourceCodester Earnings and Expense Tracker App 1.0. This vulnerability affects unknown code of the file Master.php?a=save_earning. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-224308.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1689" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.224308" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.224308" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T10:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-4v79-g36g-gxp6/GHSA-4v79-g36g-gxp6.json b/advisories/unreviewed/2023/03/GHSA-4v79-g36g-gxp6/GHSA-4v79-g36g-gxp6.json new file mode 100644 index 00000000000..e04d7324221 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-4v79-g36g-gxp6/GHSA-4v79-g36g-gxp6.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v79-g36g-gxp6", + "modified": "2023-03-29T12:30:35Z", + "published": "2023-03-29T12:30:35Z", + "aliases": [ + "CVE-2023-1509" + ], + "details": "The GMAce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This is due to missing nonce validation on the gmace_manager_server function called via the wp_ajax_gmace_manager AJAX action. This makes it possible for unauthenticated attackers to modify arbitrary files and achieve remote code execution via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1509" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/gmace/trunk/gmace.php?rev=1583327#L84" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/gmace/trunk/inc/filemanager.php?rev=1583319#L27" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/826b3913-9a37-4e15-80fd-b35cefb51af8?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T11:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-9468-42qx-67cg/GHSA-9468-42qx-67cg.json b/advisories/unreviewed/2023/03/GHSA-9468-42qx-67cg/GHSA-9468-42qx-67cg.json index 58112fae917..ba2196098d9 100644 --- a/advisories/unreviewed/2023/03/GHSA-9468-42qx-67cg/GHSA-9468-42qx-67cg.json +++ b/advisories/unreviewed/2023/03/GHSA-9468-42qx-67cg/GHSA-9468-42qx-67cg.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38452" }, + { + "type": "WEB", + "url": "https://kb.netgear.com/000065567/Security-Advisory-for-Post-authentication-Command-Injection-on-the-RBR750-PSV-2022-0186" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2022-1595" diff --git a/advisories/unreviewed/2023/03/GHSA-f75p-j579-8r2c/GHSA-f75p-j579-8r2c.json b/advisories/unreviewed/2023/03/GHSA-f75p-j579-8r2c/GHSA-f75p-j579-8r2c.json new file mode 100644 index 00000000000..d8f639e1e5b --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-f75p-j579-8r2c/GHSA-f75p-j579-8r2c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f75p-j579-8r2c", + "modified": "2023-03-29T12:30:35Z", + "published": "2023-03-29T12:30:35Z", + "aliases": [ + "CVE-2023-0213" + ], + "details": "Elevation of privilege issue in M-Files Installer versions before 22.6 on Windows allows user to gain SYSTEM privileges via DLL hijacking.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0213" + }, + { + "type": "WEB", + "url": "https://www.m-files.com/about/trust-center/security-advisories/cve-2023-0213/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T11:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/03/GHSA-hqcp-27rh-hjjg/GHSA-hqcp-27rh-hjjg.json b/advisories/unreviewed/2023/03/GHSA-hqcp-27rh-hjjg/GHSA-hqcp-27rh-hjjg.json index da3c1b1baf3..192e693d370 100644 --- a/advisories/unreviewed/2023/03/GHSA-hqcp-27rh-hjjg/GHSA-hqcp-27rh-hjjg.json +++ b/advisories/unreviewed/2023/03/GHSA-hqcp-27rh-hjjg/GHSA-hqcp-27rh-hjjg.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37337" }, + { + "type": "WEB", + "url": "https://kb.netgear.com/000065417/Security-Advisory-for-Command-Injection-on-Some-Orbi-WiFi-Systems-PSV-2022-0187" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2022-1596" diff --git a/advisories/unreviewed/2023/03/GHSA-qxv5-xxxc-xw7m/GHSA-qxv5-xxxc-xw7m.json b/advisories/unreviewed/2023/03/GHSA-qxv5-xxxc-xw7m/GHSA-qxv5-xxxc-xw7m.json index e580073b2ce..8c0443419e5 100644 --- a/advisories/unreviewed/2023/03/GHSA-qxv5-xxxc-xw7m/GHSA-qxv5-xxxc-xw7m.json +++ b/advisories/unreviewed/2023/03/GHSA-qxv5-xxxc-xw7m/GHSA-qxv5-xxxc-xw7m.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36429" }, + { + "type": "WEB", + "url": "https://kb.netgear.com/000065424/Security-Advisory-for-Command-Injection-on-Some-Orbi-WiFi-Systems-PSV-2022-0188" + }, { "type": "WEB", "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2022-1597" diff --git a/advisories/unreviewed/2023/03/GHSA-vp77-7r82-hp2q/GHSA-vp77-7r82-hp2q.json b/advisories/unreviewed/2023/03/GHSA-vp77-7r82-hp2q/GHSA-vp77-7r82-hp2q.json new file mode 100644 index 00000000000..46fb8703b01 --- /dev/null +++ b/advisories/unreviewed/2023/03/GHSA-vp77-7r82-hp2q/GHSA-vp77-7r82-hp2q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp77-7r82-hp2q", + "modified": "2023-03-29T12:30:34Z", + "published": "2023-03-29T12:30:34Z", + "aliases": [ + "CVE-2023-1690" + ], + "details": "A vulnerability, which was classified as problematic, has been found in SourceCodester Earnings and Expense Tracker App 1.0. This issue affects some unknown processing of the file LoginRegistration.php?a=register_user. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-224309 was assigned to this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1690" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.224309" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.224309" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-03-29T11:15:00Z" + } +} \ No newline at end of file