From 7c433f2ca1d369eb9da6bbd5387f4b3361636ddc Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 6 Nov 2023 09:31:41 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2cmx-v434-xjgc.json | 35 ++++++++++++ .../GHSA-393j-fpg3-h6c9.json | 35 ++++++++++++ .../GHSA-45ch-3c88-xp9m.json | 35 ++++++++++++ .../GHSA-4qfp-2f8x-99wm.json | 35 ++++++++++++ .../GHSA-5mm9-mxvw-xq9r.json | 35 ++++++++++++ .../GHSA-772v-9mr6-2jg6.json | 35 ++++++++++++ .../GHSA-7w65-mrqr-m6xw.json | 35 ++++++++++++ .../GHSA-8pqw-r7j4-j7cq.json | 35 ++++++++++++ .../GHSA-8q58-8vm2-mf3q.json | 54 +++++++++++++++++++ .../GHSA-9xrg-mh99-h5f7.json | 35 ++++++++++++ .../GHSA-c82g-hm52-r6fr.json | 35 ++++++++++++ .../GHSA-cx58-rgfc-jwq7.json | 35 ++++++++++++ .../GHSA-g96f-c9hf-8584.json | 35 ++++++++++++ .../GHSA-h2w6-c2hx-7jcf.json | 35 ++++++++++++ .../GHSA-hcrv-8mmq-xp49.json | 35 ++++++++++++ .../GHSA-jg7r-pc4g-p6vp.json | 38 +++++++++++++ .../GHSA-m8v7-q2v8-xpcv.json | 50 +++++++++++++++++ .../GHSA-mpx8-qgg5-7wpm.json | 35 ++++++++++++ .../GHSA-mq7v-wfr3-56f3.json | 35 ++++++++++++ .../GHSA-mvh5-v533-3v55.json | 35 ++++++++++++ .../GHSA-p3wg-m8cr-724c.json | 35 ++++++++++++ .../GHSA-rq4x-9q74-vqwc.json | 35 ++++++++++++ .../GHSA-rvhc-5c8m-3qg8.json | 35 ++++++++++++ .../GHSA-v9wj-35hg-7vg8.json | 35 ++++++++++++ .../GHSA-vp68-65xj-g24v.json | 35 ++++++++++++ 25 files changed, 912 insertions(+) create mode 100644 advisories/unreviewed/2023/11/GHSA-2cmx-v434-xjgc/GHSA-2cmx-v434-xjgc.json create mode 100644 advisories/unreviewed/2023/11/GHSA-393j-fpg3-h6c9/GHSA-393j-fpg3-h6c9.json create mode 100644 advisories/unreviewed/2023/11/GHSA-45ch-3c88-xp9m/GHSA-45ch-3c88-xp9m.json create mode 100644 advisories/unreviewed/2023/11/GHSA-4qfp-2f8x-99wm/GHSA-4qfp-2f8x-99wm.json create mode 100644 advisories/unreviewed/2023/11/GHSA-5mm9-mxvw-xq9r/GHSA-5mm9-mxvw-xq9r.json create mode 100644 advisories/unreviewed/2023/11/GHSA-772v-9mr6-2jg6/GHSA-772v-9mr6-2jg6.json create mode 100644 advisories/unreviewed/2023/11/GHSA-7w65-mrqr-m6xw/GHSA-7w65-mrqr-m6xw.json create mode 100644 advisories/unreviewed/2023/11/GHSA-8pqw-r7j4-j7cq/GHSA-8pqw-r7j4-j7cq.json create mode 100644 advisories/unreviewed/2023/11/GHSA-8q58-8vm2-mf3q/GHSA-8q58-8vm2-mf3q.json create mode 100644 advisories/unreviewed/2023/11/GHSA-9xrg-mh99-h5f7/GHSA-9xrg-mh99-h5f7.json create mode 100644 advisories/unreviewed/2023/11/GHSA-c82g-hm52-r6fr/GHSA-c82g-hm52-r6fr.json create mode 100644 advisories/unreviewed/2023/11/GHSA-cx58-rgfc-jwq7/GHSA-cx58-rgfc-jwq7.json create mode 100644 advisories/unreviewed/2023/11/GHSA-g96f-c9hf-8584/GHSA-g96f-c9hf-8584.json create mode 100644 advisories/unreviewed/2023/11/GHSA-h2w6-c2hx-7jcf/GHSA-h2w6-c2hx-7jcf.json create mode 100644 advisories/unreviewed/2023/11/GHSA-hcrv-8mmq-xp49/GHSA-hcrv-8mmq-xp49.json create mode 100644 advisories/unreviewed/2023/11/GHSA-jg7r-pc4g-p6vp/GHSA-jg7r-pc4g-p6vp.json create mode 100644 advisories/unreviewed/2023/11/GHSA-m8v7-q2v8-xpcv/GHSA-m8v7-q2v8-xpcv.json create mode 100644 advisories/unreviewed/2023/11/GHSA-mpx8-qgg5-7wpm/GHSA-mpx8-qgg5-7wpm.json create mode 100644 advisories/unreviewed/2023/11/GHSA-mq7v-wfr3-56f3/GHSA-mq7v-wfr3-56f3.json create mode 100644 advisories/unreviewed/2023/11/GHSA-mvh5-v533-3v55/GHSA-mvh5-v533-3v55.json create mode 100644 advisories/unreviewed/2023/11/GHSA-p3wg-m8cr-724c/GHSA-p3wg-m8cr-724c.json create mode 100644 advisories/unreviewed/2023/11/GHSA-rq4x-9q74-vqwc/GHSA-rq4x-9q74-vqwc.json create mode 100644 advisories/unreviewed/2023/11/GHSA-rvhc-5c8m-3qg8/GHSA-rvhc-5c8m-3qg8.json create mode 100644 advisories/unreviewed/2023/11/GHSA-v9wj-35hg-7vg8/GHSA-v9wj-35hg-7vg8.json create mode 100644 advisories/unreviewed/2023/11/GHSA-vp68-65xj-g24v/GHSA-vp68-65xj-g24v.json diff --git a/advisories/unreviewed/2023/11/GHSA-2cmx-v434-xjgc/GHSA-2cmx-v434-xjgc.json b/advisories/unreviewed/2023/11/GHSA-2cmx-v434-xjgc/GHSA-2cmx-v434-xjgc.json new file mode 100644 index 00000000000..90074118f39 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-2cmx-v434-xjgc/GHSA-2cmx-v434-xjgc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cmx-v434-xjgc", + "modified": "2023-11-06T09:30:14Z", + "published": "2023-11-06T09:30:14Z", + "aliases": [ + "CVE-2022-45373" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jason Crouse, VeronaLabs Slimstat Analytics allows SQL Injection.This issue affects Slimstat Analytics: from n/a through 5.0.4.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45373" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-slimstat/wordpress-slimstat-analytics-plugin-5-0-4-sql-injection-sqli-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T08:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-393j-fpg3-h6c9/GHSA-393j-fpg3-h6c9.json b/advisories/unreviewed/2023/11/GHSA-393j-fpg3-h6c9/GHSA-393j-fpg3-h6c9.json new file mode 100644 index 00000000000..525de7294e4 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-393j-fpg3-h6c9/GHSA-393j-fpg3-h6c9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-393j-fpg3-h6c9", + "modified": "2023-11-06T09:30:15Z", + "published": "2023-11-06T09:30:15Z", + "aliases": [ + "CVE-2023-45074" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress allows SQL Injection.This issue affects Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress: from n/a through 7.1.1.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45074" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/advanced-page-visit-counter/wordpress-advanced-page-visit-counter-plugin-7-1-1-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-45ch-3c88-xp9m/GHSA-45ch-3c88-xp9m.json b/advisories/unreviewed/2023/11/GHSA-45ch-3c88-xp9m/GHSA-45ch-3c88-xp9m.json new file mode 100644 index 00000000000..3145eb4f11a --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-45ch-3c88-xp9m/GHSA-45ch-3c88-xp9m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45ch-3c88-xp9m", + "modified": "2023-11-06T09:30:15Z", + "published": "2023-11-06T09:30:15Z", + "aliases": [ + "CVE-2023-33924" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Felix Welberg SIS Handball allows SQL Injection.This issue affects SIS Handball: from n/a through 1.0.45.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33924" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sis-handball/wordpress-sis-handball-plugin-1-0-45-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-4qfp-2f8x-99wm/GHSA-4qfp-2f8x-99wm.json b/advisories/unreviewed/2023/11/GHSA-4qfp-2f8x-99wm/GHSA-4qfp-2f8x-99wm.json new file mode 100644 index 00000000000..e1c13a9b35a --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-4qfp-2f8x-99wm/GHSA-4qfp-2f8x-99wm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qfp-2f8x-99wm", + "modified": "2023-11-06T09:30:15Z", + "published": "2023-11-06T09:30:15Z", + "aliases": [ + "CVE-2022-47432" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kemal YAZICI - PluginPress Shortcode IMDB allows SQL Injection.This issue affects Shortcode IMDB: from n/a through 6.0.8.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47432" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/shortcode-imdb/wordpress-shortcode-imdb-plugin-6-0-8-sql-injection?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T08:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5mm9-mxvw-xq9r/GHSA-5mm9-mxvw-xq9r.json b/advisories/unreviewed/2023/11/GHSA-5mm9-mxvw-xq9r/GHSA-5mm9-mxvw-xq9r.json new file mode 100644 index 00000000000..748868cd500 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5mm9-mxvw-xq9r/GHSA-5mm9-mxvw-xq9r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mm9-mxvw-xq9r", + "modified": "2023-11-06T09:30:14Z", + "published": "2023-11-06T09:30:14Z", + "aliases": [ + "CVE-2022-47420" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Online ADA Accessibility Suite by Online ADA allows SQL Injection.This issue affects Accessibility Suite by Online ADA: from n/a through 4.11.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47420" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/online-accessibility/wordpress-accessibility-suite-by-online-ada-plugin-4-11-sql-injection?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T08:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-772v-9mr6-2jg6/GHSA-772v-9mr6-2jg6.json b/advisories/unreviewed/2023/11/GHSA-772v-9mr6-2jg6/GHSA-772v-9mr6-2jg6.json new file mode 100644 index 00000000000..3f269229abd --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-772v-9mr6-2jg6/GHSA-772v-9mr6-2jg6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-772v-9mr6-2jg6", + "modified": "2023-11-06T09:30:15Z", + "published": "2023-11-06T09:30:15Z", + "aliases": [ + "CVE-2023-45055" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InspireUI MStore API allows SQL Injection.This issue affects MStore API: from n/a through 4.0.6.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45055" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mstore-api/wordpress-mstore-api-plugin-4-0-6-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7w65-mrqr-m6xw/GHSA-7w65-mrqr-m6xw.json b/advisories/unreviewed/2023/11/GHSA-7w65-mrqr-m6xw/GHSA-7w65-mrqr-m6xw.json new file mode 100644 index 00000000000..1e9412a95ba --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-7w65-mrqr-m6xw/GHSA-7w65-mrqr-m6xw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7w65-mrqr-m6xw", + "modified": "2023-11-06T09:30:15Z", + "published": "2023-11-06T09:30:15Z", + "aliases": [ + "CVE-2023-45830" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Online ADA Accessibility Suite by Online ADA allows SQL Injection.This issue affects Accessibility Suite by Online ADA: from n/a through 4.11.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45830" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/online-accessibility/wordpress-accessibility-suite-by-online-ada-plugin-4-11-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-8pqw-r7j4-j7cq/GHSA-8pqw-r7j4-j7cq.json b/advisories/unreviewed/2023/11/GHSA-8pqw-r7j4-j7cq/GHSA-8pqw-r7j4-j7cq.json new file mode 100644 index 00000000000..ca2a26fe603 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-8pqw-r7j4-j7cq/GHSA-8pqw-r7j4-j7cq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pqw-r7j4-j7cq", + "modified": "2023-11-06T09:30:15Z", + "published": "2023-11-06T09:30:15Z", + "aliases": [ + "CVE-2023-45001" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Castos Seriously Simple Stats allows SQL Injection.This issue affects Seriously Simple Stats: from n/a through 1.5.0.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45001" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/seriously-simple-stats/wordpress-seriously-simple-stats-plugin-1-5-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-8q58-8vm2-mf3q/GHSA-8q58-8vm2-mf3q.json b/advisories/unreviewed/2023/11/GHSA-8q58-8vm2-mf3q/GHSA-8q58-8vm2-mf3q.json new file mode 100644 index 00000000000..8222ea72ad2 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-8q58-8vm2-mf3q/GHSA-8q58-8vm2-mf3q.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q58-8vm2-mf3q", + "modified": "2023-11-06T09:30:14Z", + "published": "2023-11-06T09:30:14Z", + "aliases": [ + "CVE-2023-42669" + ], + "details": "A vulnerability was found in Samba's \"rpcecho\" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements. This vulnerability stems from an RPC function that can be blocked indefinitely. The issue arises because the \"rpcecho\" service operates with only one worker in the main RPC task, allowing calls to the \"rpcecho\" server to be blocked for a specified time, causing service disruptions. This disruption is triggered by a \"sleep()\" call in the \"dcesrv_echo_TestSleep()\" function under specific conditions. Authenticated users or attackers can exploit this vulnerability to make calls to the \"rpcecho\" server, requesting it to block for a specified duration, effectively disrupting most services and leading to a complete denial of service on the AD DC. The DoS affects all other services as \"rpcecho\" runs in the main RPC task.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42669" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2023:6209" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-42669" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2241884" + }, + { + "type": "WEB", + "url": "https://bugzilla.samba.org/show_bug.cgi?id=15474" + }, + { + "type": "WEB", + "url": "https://www.samba.org/samba/security/CVE-2023-42669.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9xrg-mh99-h5f7/GHSA-9xrg-mh99-h5f7.json b/advisories/unreviewed/2023/11/GHSA-9xrg-mh99-h5f7/GHSA-9xrg-mh99-h5f7.json new file mode 100644 index 00000000000..62d7797e48b --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-9xrg-mh99-h5f7/GHSA-9xrg-mh99-h5f7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xrg-mh99-h5f7", + "modified": "2023-11-06T09:30:15Z", + "published": "2023-11-06T09:30:15Z", + "aliases": [ + "CVE-2023-45657" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in POSIMYTH Nexter allows SQL Injection.This issue affects Nexter: from n/a through 2.0.3.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45657" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/nexter/wordpress-nexter-theme-2-0-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-c82g-hm52-r6fr/GHSA-c82g-hm52-r6fr.json b/advisories/unreviewed/2023/11/GHSA-c82g-hm52-r6fr/GHSA-c82g-hm52-r6fr.json new file mode 100644 index 00000000000..c7d78648885 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-c82g-hm52-r6fr/GHSA-c82g-hm52-r6fr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c82g-hm52-r6fr", + "modified": "2023-11-06T09:30:14Z", + "published": "2023-11-06T09:30:14Z", + "aliases": [ + "CVE-2022-46860" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in KaizenCoders Short URL allows SQL Injection.This issue affects Short URL: from n/a through 1.6.4.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46860" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/shorten-url/wordpress-short-url-plugin-1-6-4-sql-injection?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T08:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-cx58-rgfc-jwq7/GHSA-cx58-rgfc-jwq7.json b/advisories/unreviewed/2023/11/GHSA-cx58-rgfc-jwq7/GHSA-cx58-rgfc-jwq7.json new file mode 100644 index 00000000000..4ebf60d68f3 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cx58-rgfc-jwq7/GHSA-cx58-rgfc-jwq7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx58-rgfc-jwq7", + "modified": "2023-11-06T09:30:15Z", + "published": "2023-11-06T09:30:15Z", + "aliases": [ + "CVE-2023-28748" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in biztechc Copy or Move Comments allows SQL Injection.This issue affects Copy or Move Comments: from n/a through 5.0.4.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28748" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/copy-or-move-comments/wordpress-copy-or-move-comments-plugin-5-0-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-g96f-c9hf-8584/GHSA-g96f-c9hf-8584.json b/advisories/unreviewed/2023/11/GHSA-g96f-c9hf-8584/GHSA-g96f-c9hf-8584.json new file mode 100644 index 00000000000..1a2f7324bdf --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-g96f-c9hf-8584/GHSA-g96f-c9hf-8584.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g96f-c9hf-8584", + "modified": "2023-11-06T09:30:15Z", + "published": "2023-11-06T09:30:15Z", + "aliases": [ + "CVE-2023-40207" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RedNao Donations Made Easy – Smart Donations allows SQL Injection.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40207" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/smart-donations/wordpress-donations-made-easy-smart-donations-plugin-4-0-12-sql-injection?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-h2w6-c2hx-7jcf/GHSA-h2w6-c2hx-7jcf.json b/advisories/unreviewed/2023/11/GHSA-h2w6-c2hx-7jcf/GHSA-h2w6-c2hx-7jcf.json new file mode 100644 index 00000000000..a784661d9c7 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-h2w6-c2hx-7jcf/GHSA-h2w6-c2hx-7jcf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2w6-c2hx-7jcf", + "modified": "2023-11-06T09:30:15Z", + "published": "2023-11-06T09:30:15Z", + "aliases": [ + "CVE-2023-45069" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Video Gallery by Total-Soft Video Gallery – Best WordPress YouTube Gallery Plugin allows SQL Injection.This issue affects Video Gallery – Best WordPress YouTube Gallery Plugin: from n/a through 2.1.3.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45069" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/gallery-videos/wordpress-gallery-video-plugin-2-0-2-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-hcrv-8mmq-xp49/GHSA-hcrv-8mmq-xp49.json b/advisories/unreviewed/2023/11/GHSA-hcrv-8mmq-xp49/GHSA-hcrv-8mmq-xp49.json new file mode 100644 index 00000000000..41231e9f7e7 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-hcrv-8mmq-xp49/GHSA-hcrv-8mmq-xp49.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcrv-8mmq-xp49", + "modified": "2023-11-06T09:30:15Z", + "published": "2023-11-06T09:30:15Z", + "aliases": [ + "CVE-2023-41685" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ilGhera Woocommerce Support System allows SQL Injection.This issue affects Woocommerce Support System: from n/a through 1.2.1.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41685" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wc-support-system/wordpress-woocommerce-support-system-plugin-1-2-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-jg7r-pc4g-p6vp/GHSA-jg7r-pc4g-p6vp.json b/advisories/unreviewed/2023/11/GHSA-jg7r-pc4g-p6vp/GHSA-jg7r-pc4g-p6vp.json new file mode 100644 index 00000000000..7175ef0c8b2 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-jg7r-pc4g-p6vp/GHSA-jg7r-pc4g-p6vp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jg7r-pc4g-p6vp", + "modified": "2023-11-06T09:30:15Z", + "published": "2023-11-06T09:30:15Z", + "aliases": [ + "CVE-2023-28794" + ], + "details": "Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Privilege Abuse. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28794" + }, + { + "type": "WEB", + "url": "https://help.zscaler.com/client-connector/client-connector-app-release-summary-2022?applicable_category=Linux&applicable_version=1.3.1&deployment_date=2022-09-19" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-346" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T08:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-m8v7-q2v8-xpcv/GHSA-m8v7-q2v8-xpcv.json b/advisories/unreviewed/2023/11/GHSA-m8v7-q2v8-xpcv/GHSA-m8v7-q2v8-xpcv.json new file mode 100644 index 00000000000..1e36586f66a --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-m8v7-q2v8-xpcv/GHSA-m8v7-q2v8-xpcv.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8v7-q2v8-xpcv", + "modified": "2023-11-06T09:30:14Z", + "published": "2023-11-06T09:30:14Z", + "aliases": [ + "CVE-2021-4430" + ], + "details": "A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknown part of the file src/defaultConfig.js of the component ENV Variable Handler. The manipulation leads to information disclosure. Upgrading to version 3.1.7 is able to address this issue. The identifier of the patch is a3aa62daea2e44c76d08d1eac63768cd928cd69e. It is recommended to upgrade the affected component. The identifier VDB-244485 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-4430" + }, + { + "type": "WEB", + "url": "https://github.com/Ortus-Solutions/coldbox-elixir/commit/a3aa62daea2e44c76d08d1eac63768cd928cd69e" + }, + { + "type": "WEB", + "url": "https://github.com/Ortus-Solutions/coldbox-elixir/releases/tag/v3.1.7" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.244485" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.244485" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T08:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-mpx8-qgg5-7wpm/GHSA-mpx8-qgg5-7wpm.json b/advisories/unreviewed/2023/11/GHSA-mpx8-qgg5-7wpm/GHSA-mpx8-qgg5-7wpm.json new file mode 100644 index 00000000000..e34e3389ae8 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-mpx8-qgg5-7wpm/GHSA-mpx8-qgg5-7wpm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpx8-qgg5-7wpm", + "modified": "2023-11-06T09:30:14Z", + "published": "2023-11-06T09:30:14Z", + "aliases": [ + "CVE-2022-46849" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar Coming Soon Page – Responsive Coming Soon & Maintenance Mode allows SQL Injection.This issue affects Coming Soon Page – Responsive Coming Soon & Maintenance Mode: from n/a through 1.5.9.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46849" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/responsive-coming-soon-page/wordpress-coming-soon-page-plugin-1-5-8-sql-injection-sqli-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T08:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-mq7v-wfr3-56f3/GHSA-mq7v-wfr3-56f3.json b/advisories/unreviewed/2023/11/GHSA-mq7v-wfr3-56f3/GHSA-mq7v-wfr3-56f3.json new file mode 100644 index 00000000000..12781fa5a5b --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-mq7v-wfr3-56f3/GHSA-mq7v-wfr3-56f3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq7v-wfr3-56f3", + "modified": "2023-11-06T09:30:15Z", + "published": "2023-11-06T09:30:15Z", + "aliases": [ + "CVE-2023-38382" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category allows SQL Injection.This issue affects Subscribe to Category: from n/a through 2.7.4.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38382" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/subscribe-to-category/wordpress-subscribe-to-category-plugin-2-7-4-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-mvh5-v533-3v55/GHSA-mvh5-v533-3v55.json b/advisories/unreviewed/2023/11/GHSA-mvh5-v533-3v55/GHSA-mvh5-v533-3v55.json new file mode 100644 index 00000000000..2d7189f2924 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-mvh5-v533-3v55/GHSA-mvh5-v533-3v55.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvh5-v533-3v55", + "modified": "2023-11-06T09:30:15Z", + "published": "2023-11-06T09:30:15Z", + "aliases": [ + "CVE-2023-35911" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Creative Solutions Contact Form Generator : Creative form builder for WordPress allows SQL Injection.This issue affects Contact Form Generator : Creative form builder for WordPress: from n/a through 2.6.0.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35911" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/contact-form-generator/wordpress-contact-form-generator-plugin-2-6-0-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-p3wg-m8cr-724c/GHSA-p3wg-m8cr-724c.json b/advisories/unreviewed/2023/11/GHSA-p3wg-m8cr-724c/GHSA-p3wg-m8cr-724c.json new file mode 100644 index 00000000000..50b10ac0750 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-p3wg-m8cr-724c/GHSA-p3wg-m8cr-724c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3wg-m8cr-724c", + "modified": "2023-11-06T09:30:15Z", + "published": "2023-11-06T09:30:15Z", + "aliases": [ + "CVE-2023-27605" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sajjad Hossain WP Reroute Email allows SQL Injection.This issue affects WP Reroute Email: from n/a through 1.4.6.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27605" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-reroute-email/wordpress-wp-reroute-email-plugin-1-4-6-admin-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-rq4x-9q74-vqwc/GHSA-rq4x-9q74-vqwc.json b/advisories/unreviewed/2023/11/GHSA-rq4x-9q74-vqwc/GHSA-rq4x-9q74-vqwc.json new file mode 100644 index 00000000000..2a0212b7fb2 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-rq4x-9q74-vqwc/GHSA-rq4x-9q74-vqwc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq4x-9q74-vqwc", + "modified": "2023-11-06T09:30:15Z", + "published": "2023-11-06T09:30:15Z", + "aliases": [ + "CVE-2023-40609" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aiyaz, maheshpatel Contact form 7 Custom validation allows SQL Injection.This issue affects Contact form 7 Custom validation: from n/a through 1.1.3.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40609" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cf7-field-validation/wordpress-contact-form-7-custom-validation-plugin-1-1-3-unauth-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-rvhc-5c8m-3qg8/GHSA-rvhc-5c8m-3qg8.json b/advisories/unreviewed/2023/11/GHSA-rvhc-5c8m-3qg8/GHSA-rvhc-5c8m-3qg8.json new file mode 100644 index 00000000000..a644fa9ba54 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-rvhc-5c8m-3qg8/GHSA-rvhc-5c8m-3qg8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvhc-5c8m-3qg8", + "modified": "2023-11-06T09:30:14Z", + "published": "2023-11-06T09:30:14Z", + "aliases": [ + "CVE-2022-47430" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar The School Management – Education & Learning Management allows SQL Injection.This issue affects The School Management – Education & Learning Management: from n/a through 4.1.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47430" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/school-management-system/wordpress-the-school-management-plugin-4-1-sql-injection?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T08:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-v9wj-35hg-7vg8/GHSA-v9wj-35hg-7vg8.json b/advisories/unreviewed/2023/11/GHSA-v9wj-35hg-7vg8/GHSA-v9wj-35hg-7vg8.json new file mode 100644 index 00000000000..1a23fc55c0e --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-v9wj-35hg-7vg8/GHSA-v9wj-35hg-7vg8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9wj-35hg-7vg8", + "modified": "2023-11-06T09:30:15Z", + "published": "2023-11-06T09:30:15Z", + "aliases": [ + "CVE-2023-45046" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pressference Pressference Exporter allows SQL Injection.This issue affects Pressference Exporter: from n/a through 1.0.3.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45046" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pressference-exporter/wordpress-pressference-exporter-plugin-1-0-3-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-vp68-65xj-g24v/GHSA-vp68-65xj-g24v.json b/advisories/unreviewed/2023/11/GHSA-vp68-65xj-g24v/GHSA-vp68-65xj-g24v.json new file mode 100644 index 00000000000..5639c82f484 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-vp68-65xj-g24v/GHSA-vp68-65xj-g24v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp68-65xj-g24v", + "modified": "2023-11-06T09:30:14Z", + "published": "2023-11-06T09:30:14Z", + "aliases": [ + "CVE-2022-47428" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpDevArt Booking calendar, Appointment Booking System allows SQL Injection.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.7.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47428" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/booking-calendar/wordpress-booking-calendar-appointment-booking-system-plugin-3-2-6-sql-injection?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-06T08:15:21Z" + } +} \ No newline at end of file