diff --git a/advisories/unreviewed/2023/04/GHSA-2cpf-9p54-p35p/GHSA-2cpf-9p54-p35p.json b/advisories/unreviewed/2023/04/GHSA-2cpf-9p54-p35p/GHSA-2cpf-9p54-p35p.json new file mode 100644 index 00000000000..3ca0a15af35 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-2cpf-9p54-p35p/GHSA-2cpf-9p54-p35p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cpf-9p54-p35p", + "modified": "2023-04-14T15:30:28Z", + "published": "2023-04-14T15:30:28Z", + "aliases": [ + "CVE-2023-28085" + ], + "details": "An HPE OneView Global Dashboard (OVGD) appliance dump may expose OVGD user account credentials", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28085" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04468en_us" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-33xg-34rg-xc37/GHSA-33xg-34rg-xc37.json b/advisories/unreviewed/2023/04/GHSA-33xg-34rg-xc37/GHSA-33xg-34rg-xc37.json new file mode 100644 index 00000000000..73f66328bff --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-33xg-34rg-xc37/GHSA-33xg-34rg-xc37.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33xg-34rg-xc37", + "modified": "2023-04-14T15:30:29Z", + "published": "2023-04-14T15:30:29Z", + "aliases": [ + "CVE-2022-45175" + ], + "details": "An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Insecure Direct Object Reference can occur under the 5.6.5-3/doc/{ID-FILE]/c/{N]/{C]/websocket endpoint. A malicious unauthenticated user can access cached files in the OnlyOffice backend of other users by guessing the file ID of a target file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45175" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-3p52-6fj7-58jh/GHSA-3p52-6fj7-58jh.json b/advisories/unreviewed/2023/04/GHSA-3p52-6fj7-58jh/GHSA-3p52-6fj7-58jh.json index 110fa32ba6c..0562cd2c726 100644 --- a/advisories/unreviewed/2023/04/GHSA-3p52-6fj7-58jh/GHSA-3p52-6fj7-58jh.json +++ b/advisories/unreviewed/2023/04/GHSA-3p52-6fj7-58jh/GHSA-3p52-6fj7-58jh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3p52-6fj7-58jh", - "modified": "2023-04-07T18:30:50Z", + "modified": "2023-04-14T15:30:30Z", "published": "2023-04-07T18:30:50Z", "aliases": [ "CVE-2023-1940" ], "details": "A vulnerability classified as critical was found in SourceCodester Simple and Beautiful Shopping Cart System 1.0. This vulnerability affects unknown code of the file delete_user_query.php. The manipulation of the argument user_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-225316.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-07T18:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-3p6j-m8j2-m6rc/GHSA-3p6j-m8j2-m6rc.json b/advisories/unreviewed/2023/04/GHSA-3p6j-m8j2-m6rc/GHSA-3p6j-m8j2-m6rc.json new file mode 100644 index 00000000000..a707118c1c2 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-3p6j-m8j2-m6rc/GHSA-3p6j-m8j2-m6rc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p6j-m8j2-m6rc", + "modified": "2023-04-14T15:30:30Z", + "published": "2023-04-14T15:30:30Z", + "aliases": [ + "CVE-2022-45174" + ], + "details": "An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/challenge endpoint. The correctness of the TOTP is not checked properly, and can be bypassed by passing any string as the backup code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45174" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-3qvc-cqxx-gjpr/GHSA-3qvc-cqxx-gjpr.json b/advisories/unreviewed/2023/04/GHSA-3qvc-cqxx-gjpr/GHSA-3qvc-cqxx-gjpr.json new file mode 100644 index 00000000000..39a4c8a3a82 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-3qvc-cqxx-gjpr/GHSA-3qvc-cqxx-gjpr.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qvc-cqxx-gjpr", + "modified": "2023-04-14T15:30:30Z", + "published": "2023-04-14T15:30:30Z", + "aliases": [ + "CVE-2023-2054" + ], + "details": "A vulnerability, which was classified as critical, was found in Campcodes Advanced Online Voting System 1.0. This affects an unknown part of the file /admin/positions_delete.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225939.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2054" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Advanced%20Online%20Voting%20System/Advanced%20Online%20Voting%20System%20-%20vuln%208.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.225939" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.225939" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-48vw-436h-p87m/GHSA-48vw-436h-p87m.json b/advisories/unreviewed/2023/04/GHSA-48vw-436h-p87m/GHSA-48vw-436h-p87m.json index 29070ca2cd4..d77b4f2b95b 100644 --- a/advisories/unreviewed/2023/04/GHSA-48vw-436h-p87m/GHSA-48vw-436h-p87m.json +++ b/advisories/unreviewed/2023/04/GHSA-48vw-436h-p87m/GHSA-48vw-436h-p87m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-48vw-436h-p87m", - "modified": "2023-04-10T15:30:25Z", + "modified": "2023-04-14T15:30:28Z", "published": "2023-04-10T15:30:25Z", "aliases": [ "CVE-2022-39048" ], "details": "ServiceNow Tokyo allows XSS.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-10T14:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-4jpf-xppp-j95v/GHSA-4jpf-xppp-j95v.json b/advisories/unreviewed/2023/04/GHSA-4jpf-xppp-j95v/GHSA-4jpf-xppp-j95v.json index 8c0446766f8..7ab463ff70a 100644 --- a/advisories/unreviewed/2023/04/GHSA-4jpf-xppp-j95v/GHSA-4jpf-xppp-j95v.json +++ b/advisories/unreviewed/2023/04/GHSA-4jpf-xppp-j95v/GHSA-4jpf-xppp-j95v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4jpf-xppp-j95v", - "modified": "2023-04-11T15:30:28Z", + "modified": "2023-04-14T15:30:30Z", "published": "2023-04-11T15:30:28Z", "aliases": [ "CVE-2023-26846" ], "details": "A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the city parameter at opencats/index.php?m=candidates.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-11T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-5828-hcm2-wmj6/GHSA-5828-hcm2-wmj6.json b/advisories/unreviewed/2023/04/GHSA-5828-hcm2-wmj6/GHSA-5828-hcm2-wmj6.json new file mode 100644 index 00000000000..0d491fcbdc4 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-5828-hcm2-wmj6/GHSA-5828-hcm2-wmj6.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5828-hcm2-wmj6", + "modified": "2023-04-14T15:30:30Z", + "published": "2023-04-14T15:30:30Z", + "aliases": [ + "CVE-2023-2055" + ], + "details": "A vulnerability has been found in Campcodes Advanced Online Voting System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/config_save.php. The manipulation of the argument title leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-225940.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2055" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Advanced%20Online%20Voting%20System/Advanced%20Online%20Voting%20System%20-%20vuln%209.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.225940" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.225940" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-5jcc-wrcp-3mxc/GHSA-5jcc-wrcp-3mxc.json b/advisories/unreviewed/2023/04/GHSA-5jcc-wrcp-3mxc/GHSA-5jcc-wrcp-3mxc.json new file mode 100644 index 00000000000..15517983853 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-5jcc-wrcp-3mxc/GHSA-5jcc-wrcp-3mxc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jcc-wrcp-3mxc", + "modified": "2023-04-14T15:30:29Z", + "published": "2023-04-14T15:30:29Z", + "aliases": [ + "CVE-2023-29850" + ], + "details": "SENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded images. This allows attackers to obtain information such as the user's geolocation and device information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29850" + }, + { + "type": "WEB", + "url": "https://github.com/slims/slims9_bulian/issues/186" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-69vx-3fgc-566q/GHSA-69vx-3fgc-566q.json b/advisories/unreviewed/2023/04/GHSA-69vx-3fgc-566q/GHSA-69vx-3fgc-566q.json new file mode 100644 index 00000000000..2872c513599 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-69vx-3fgc-566q/GHSA-69vx-3fgc-566q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69vx-3fgc-566q", + "modified": "2023-04-14T15:30:29Z", + "published": "2023-04-14T15:30:29Z", + "aliases": [ + "CVE-2022-45178" + ], + "details": "An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdeskintegration/saml/user/createorupdate endpoint, the /settings/guest-settings endpoint, the /settings/samlusers-settings endpoint, and the /settings/users-settings endpoint. A malicious user (already logged in as a SAML User) is able to achieve privilege escalation from a low-privilege user (FGM user) to an administrative user (GGU user), including the administrator, or create new users even without an admin role.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45178" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-7546-wrqf-3fph/GHSA-7546-wrqf-3fph.json b/advisories/unreviewed/2023/04/GHSA-7546-wrqf-3fph/GHSA-7546-wrqf-3fph.json new file mode 100644 index 00000000000..2ccf9f1bd8b --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-7546-wrqf-3fph/GHSA-7546-wrqf-3fph.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7546-wrqf-3fph", + "modified": "2023-04-14T15:30:29Z", + "published": "2023-04-14T15:30:29Z", + "aliases": [ + "CVE-2023-29847" + ], + "details": "AeroCMS v0.0.1 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the comment_author and comment_content parameters at /post.php. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29847" + }, + { + "type": "WEB", + "url": "https://github.com/MegaTKC/AeroCMS/issues/11" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-7gcr-m3c2-5x75/GHSA-7gcr-m3c2-5x75.json b/advisories/unreviewed/2023/04/GHSA-7gcr-m3c2-5x75/GHSA-7gcr-m3c2-5x75.json new file mode 100644 index 00000000000..feba19b94ec --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-7gcr-m3c2-5x75/GHSA-7gcr-m3c2-5x75.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gcr-m3c2-5x75", + "modified": "2023-04-14T15:30:29Z", + "published": "2023-04-14T15:30:29Z", + "aliases": [ + "CVE-2023-29798" + ], + "details": "TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29798" + }, + { + "type": "WEB", + "url": "https://sore-pail-31b.notion.site/Command-Injection-4-ea4969f635f54fe5b2f575e93443a4e0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-896q-x84x-h2x9/GHSA-896q-x84x-h2x9.json b/advisories/unreviewed/2023/04/GHSA-896q-x84x-h2x9/GHSA-896q-x84x-h2x9.json new file mode 100644 index 00000000000..169621c86b1 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-896q-x84x-h2x9/GHSA-896q-x84x-h2x9.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-896q-x84x-h2x9", + "modified": "2023-04-14T15:30:29Z", + "published": "2023-04-14T15:30:29Z", + "aliases": [ + "CVE-2023-2057" + ], + "details": "A vulnerability was found in EyouCms 1.5.4. It has been classified as problematic. Affected is an unknown function of the file login.php?m=admin&c=Arctype&a=edit of the component New Picture Handler. The manipulation of the argument litpic_loca leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-225942 is the identifier assigned to this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2057" + }, + { + "type": "WEB", + "url": "https://github.com/sleepyvv/vul_report/blob/main/EYOUCMS/XSS1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.225942" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.225942" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-8p96-wcgc-fx6f/GHSA-8p96-wcgc-fx6f.json b/advisories/unreviewed/2023/04/GHSA-8p96-wcgc-fx6f/GHSA-8p96-wcgc-fx6f.json index 6de6d01ece5..8703f40ddfb 100644 --- a/advisories/unreviewed/2023/04/GHSA-8p96-wcgc-fx6f/GHSA-8p96-wcgc-fx6f.json +++ b/advisories/unreviewed/2023/04/GHSA-8p96-wcgc-fx6f/GHSA-8p96-wcgc-fx6f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8p96-wcgc-fx6f", - "modified": "2023-04-07T18:30:49Z", + "modified": "2023-04-14T15:30:28Z", "published": "2023-04-07T18:30:49Z", "aliases": [ "CVE-2023-1942" ], "details": "A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/?page=user of the component Avatar Handler. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225319.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-434" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-07T18:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-95ph-3qjx-jqrq/GHSA-95ph-3qjx-jqrq.json b/advisories/unreviewed/2023/04/GHSA-95ph-3qjx-jqrq/GHSA-95ph-3qjx-jqrq.json index ac16d3f062b..ed6d40be654 100644 --- a/advisories/unreviewed/2023/04/GHSA-95ph-3qjx-jqrq/GHSA-95ph-3qjx-jqrq.json +++ b/advisories/unreviewed/2023/04/GHSA-95ph-3qjx-jqrq/GHSA-95ph-3qjx-jqrq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-95ph-3qjx-jqrq", - "modified": "2023-04-11T15:30:27Z", + "modified": "2023-04-14T15:30:29Z", "published": "2023-04-11T15:30:27Z", "aliases": [ "CVE-2023-26847" ], "details": "A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the state parameter at opencats/index.php?m=candidates.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-11T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-9879-9fjg-rj74/GHSA-9879-9fjg-rj74.json b/advisories/unreviewed/2023/04/GHSA-9879-9fjg-rj74/GHSA-9879-9fjg-rj74.json index e3acfaa702e..a21569996cb 100644 --- a/advisories/unreviewed/2023/04/GHSA-9879-9fjg-rj74/GHSA-9879-9fjg-rj74.json +++ b/advisories/unreviewed/2023/04/GHSA-9879-9fjg-rj74/GHSA-9879-9fjg-rj74.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9879-9fjg-rj74", - "modified": "2023-04-07T18:30:50Z", + "modified": "2023-04-14T15:30:30Z", "published": "2023-04-07T18:30:50Z", "aliases": [ "CVE-2023-1909" ], "details": "A vulnerability, which was classified as critical, was found in PHPGurukul BP Monitoring Management System 1.0. Affected is an unknown function of the file profile.php of the component User Profile Update Handler. The manipulation of the argument name/mobno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-225318 is the identifier assigned to this vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-07T17:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-9hm7-rv43-3chf/GHSA-9hm7-rv43-3chf.json b/advisories/unreviewed/2023/04/GHSA-9hm7-rv43-3chf/GHSA-9hm7-rv43-3chf.json new file mode 100644 index 00000000000..3ade66d73e5 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-9hm7-rv43-3chf/GHSA-9hm7-rv43-3chf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hm7-rv43-3chf", + "modified": "2023-04-14T15:30:29Z", + "published": "2023-04-14T15:30:29Z", + "aliases": [ + "CVE-2023-1803" + ], + "details": "Authentication Bypass by Alternate Name vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass.This issue affects Redline Router: before 7.17.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1803" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-23-0227" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-289" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-c2vc-v83f-58c3/GHSA-c2vc-v83f-58c3.json b/advisories/unreviewed/2023/04/GHSA-c2vc-v83f-58c3/GHSA-c2vc-v83f-58c3.json new file mode 100644 index 00000000000..10d1975abea --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-c2vc-v83f-58c3/GHSA-c2vc-v83f-58c3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2vc-v83f-58c3", + "modified": "2023-04-14T15:30:28Z", + "published": "2023-04-14T15:30:28Z", + "aliases": [ + "CVE-2023-30459" + ], + "details": "SmartPTT SCADA 1.1.0.0 allows remote code execution (when the attacker has administrator privileges) by writing a malicious C# script and executing it on the server (via server settings in the administrator control panel on port 8101, by default).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30459" + }, + { + "type": "WEB", + "url": "https://github.com/Toxich4/CVE-2023-30459" + }, + { + "type": "WEB", + "url": "https://smartptt.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-f938-mprp-hxgv/GHSA-f938-mprp-hxgv.json b/advisories/unreviewed/2023/04/GHSA-f938-mprp-hxgv/GHSA-f938-mprp-hxgv.json new file mode 100644 index 00000000000..4b9e3243b15 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-f938-mprp-hxgv/GHSA-f938-mprp-hxgv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f938-mprp-hxgv", + "modified": "2023-04-14T15:30:29Z", + "published": "2023-04-14T15:30:29Z", + "aliases": [ + "CVE-2023-29802" + ], + "details": "TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29802" + }, + { + "type": "WEB", + "url": "https://sore-pail-31b.notion.site/Command-Injection-3-8eb94b608bcd48f8aa4e983d2d1c4526" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-fc8v-777q-r95w/GHSA-fc8v-777q-r95w.json b/advisories/unreviewed/2023/04/GHSA-fc8v-777q-r95w/GHSA-fc8v-777q-r95w.json new file mode 100644 index 00000000000..23b28e18fba --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-fc8v-777q-r95w/GHSA-fc8v-777q-r95w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc8v-777q-r95w", + "modified": "2023-04-14T15:30:28Z", + "published": "2023-04-14T15:30:28Z", + "aliases": [ + "CVE-2023-28091" + ], + "details": "HPE OneView virtual appliance \"Migrate server hardware\" option may expose sensitive information in an HPE OneView support dump", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28091" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04467en_us" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-fmw4-39xw-jjw4/GHSA-fmw4-39xw-jjw4.json b/advisories/unreviewed/2023/04/GHSA-fmw4-39xw-jjw4/GHSA-fmw4-39xw-jjw4.json new file mode 100644 index 00000000000..12c629bb8fe --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-fmw4-39xw-jjw4/GHSA-fmw4-39xw-jjw4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmw4-39xw-jjw4", + "modified": "2023-04-14T15:30:30Z", + "published": "2023-04-14T15:30:30Z", + "aliases": [ + "CVE-2022-45173" + ], + "details": "An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successful, an attacker can modify the response, and fool the application into concluding that the TOTP was correct.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45173" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-g733-c497-r4hx/GHSA-g733-c497-r4hx.json b/advisories/unreviewed/2023/04/GHSA-g733-c497-r4hx/GHSA-g733-c497-r4hx.json new file mode 100644 index 00000000000..1e86e9f8535 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-g733-c497-r4hx/GHSA-g733-c497-r4hx.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g733-c497-r4hx", + "modified": "2023-04-14T15:30:28Z", + "published": "2023-04-14T15:30:28Z", + "aliases": [ + "CVE-2023-2059" + ], + "details": "A vulnerability was found in DedeCMS 5.7.87. It has been rated as problematic. Affected by this issue is some unknown functionality of the file uploads/include/dialog/select_templets.php. The manipulation leads to path traversal: '..\\filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-225944.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2059" + }, + { + "type": "WEB", + "url": "https://github.com/ATZXC-RedTeam/cve/blob/main/dedecms.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.225944" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.225944" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-28" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-gg23-627q-9hpv/GHSA-gg23-627q-9hpv.json b/advisories/unreviewed/2023/04/GHSA-gg23-627q-9hpv/GHSA-gg23-627q-9hpv.json new file mode 100644 index 00000000000..d05b4b7da20 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-gg23-627q-9hpv/GHSA-gg23-627q-9hpv.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gg23-627q-9hpv", + "modified": "2023-04-14T15:30:30Z", + "published": "2023-04-14T15:30:30Z", + "aliases": [ + "CVE-2023-2053" + ], + "details": "A vulnerability, which was classified as critical, has been found in Campcodes Advanced Online Voting System 1.0. Affected by this issue is some unknown functionality of the file /admin/candidates_row.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-225938 is the identifier assigned to this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2053" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Advanced%20Online%20Voting%20System/Advanced%20Online%20Voting%20System%20-%20vuln%207.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.225938" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.225938" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-gx8h-h4pj-j52p/GHSA-gx8h-h4pj-j52p.json b/advisories/unreviewed/2023/04/GHSA-gx8h-h4pj-j52p/GHSA-gx8h-h4pj-j52p.json new file mode 100644 index 00000000000..cb3d14ecc8f --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-gx8h-h4pj-j52p/GHSA-gx8h-h4pj-j52p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx8h-h4pj-j52p", + "modified": "2023-04-14T15:30:29Z", + "published": "2023-04-14T15:30:29Z", + "aliases": [ + "CVE-2023-22949" + ], + "details": "An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requests are logged by TigerGraph in multiple places. Each request includes both the username and password of the user in an easily decodable base64 form. That could allow a TigerGraph administrator to effectively harvest usernames/passwords.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22949" + }, + { + "type": "WEB", + "url": "https://dev.tigergraph.com/forum/c/tg-community/announcements/35" + }, + { + "type": "WEB", + "url": "https://neo4j.com/security/cve-2023-22949/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-hgj6-375x-j5r9/GHSA-hgj6-375x-j5r9.json b/advisories/unreviewed/2023/04/GHSA-hgj6-375x-j5r9/GHSA-hgj6-375x-j5r9.json index 0fc3bfe09a2..02a63e8bb73 100644 --- a/advisories/unreviewed/2023/04/GHSA-hgj6-375x-j5r9/GHSA-hgj6-375x-j5r9.json +++ b/advisories/unreviewed/2023/04/GHSA-hgj6-375x-j5r9/GHSA-hgj6-375x-j5r9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hgj6-375x-j5r9", - "modified": "2023-04-11T15:30:28Z", + "modified": "2023-04-14T15:30:29Z", "published": "2023-04-11T15:30:28Z", "aliases": [ "CVE-2023-26845" ], "details": "A Cross-Site Request Forgery (CSRF) in OpenCATS 0.9.7 allows attackers to force users into submitting web requests via unspecified vectors.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-11T15:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-hx37-3fvj-x3vr/GHSA-hx37-3fvj-x3vr.json b/advisories/unreviewed/2023/04/GHSA-hx37-3fvj-x3vr/GHSA-hx37-3fvj-x3vr.json new file mode 100644 index 00000000000..58bf3de2831 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-hx37-3fvj-x3vr/GHSA-hx37-3fvj-x3vr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx37-3fvj-x3vr", + "modified": "2023-04-14T15:30:30Z", + "published": "2023-04-14T15:30:30Z", + "aliases": [ + "CVE-2022-45170" + ], + "details": "An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the /api/v1/vencrypt/decrypt/file endpoint. A malicious user, logged into a victim's account, is able to decipher a file without knowing the key set by the user.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45170" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-j4wq-wqr7-wp9j/GHSA-j4wq-wqr7-wp9j.json b/advisories/unreviewed/2023/04/GHSA-j4wq-wqr7-wp9j/GHSA-j4wq-wqr7-wp9j.json new file mode 100644 index 00000000000..45350194525 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-j4wq-wqr7-wp9j/GHSA-j4wq-wqr7-wp9j.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4wq-wqr7-wp9j", + "modified": "2023-04-14T15:30:28Z", + "published": "2023-04-14T15:30:28Z", + "aliases": [ + "CVE-2022-3748" + ], + "details": "Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass.This issue affects Access Management: from 6.5.0 through 7.2.0.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-3748" + }, + { + "type": "WEB", + "url": "https://backstage.forgerock.com/downloads/browse/am/all/productId:am" + }, + { + "type": "WEB", + "url": "https://backstage.forgerock.com/knowledge/kb/article/a34332318" + }, + { + "type": "WEB", + "url": "https://backstage.forgerock.com/knowledge/kb/article/a92134872" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-jvv6-jf53-h7v7/GHSA-jvv6-jf53-h7v7.json b/advisories/unreviewed/2023/04/GHSA-jvv6-jf53-h7v7/GHSA-jvv6-jf53-h7v7.json new file mode 100644 index 00000000000..fdc1b4f80e9 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-jvv6-jf53-h7v7/GHSA-jvv6-jf53-h7v7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvv6-jf53-h7v7", + "modified": "2023-04-14T15:30:29Z", + "published": "2023-04-14T15:30:29Z", + "aliases": [ + "CVE-2023-29804" + ], + "details": "WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29804" + }, + { + "type": "WEB", + "url": "https://sore-pail-31b.notion.site/command-injection-WFS-SR03-7cddf0ac85e54f8ba81d9b26b00ca5cd" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-m5vc-m25p-pq4q/GHSA-m5vc-m25p-pq4q.json b/advisories/unreviewed/2023/04/GHSA-m5vc-m25p-pq4q/GHSA-m5vc-m25p-pq4q.json new file mode 100644 index 00000000000..0bbdcd88e1c --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-m5vc-m25p-pq4q/GHSA-m5vc-m25p-pq4q.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5vc-m25p-pq4q", + "modified": "2023-04-14T15:30:29Z", + "published": "2023-04-14T15:30:29Z", + "aliases": [ + "CVE-2023-29800" + ], + "details": "TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29800" + }, + { + "type": "WEB", + "url": "https://sore-pail-31b.notion.site/Command-Injection-5-e88b72309a3c4e20b7469b3679c0c7d9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-m87r-j77f-7wpr/GHSA-m87r-j77f-7wpr.json b/advisories/unreviewed/2023/04/GHSA-m87r-j77f-7wpr/GHSA-m87r-j77f-7wpr.json new file mode 100644 index 00000000000..0c338a86da1 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-m87r-j77f-7wpr/GHSA-m87r-j77f-7wpr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m87r-j77f-7wpr", + "modified": "2023-04-14T15:30:29Z", + "published": "2023-04-14T15:30:29Z", + "aliases": [ + "CVE-2023-29803" + ], + "details": "TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the pid parameter in the disconnectVPN function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29803" + }, + { + "type": "WEB", + "url": "https://sore-pail-31b.notion.site/Command-Inject-1-4a37b0679f69478285d1ba640e5f0897" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-m9j2-ffm7-xfgg/GHSA-m9j2-ffm7-xfgg.json b/advisories/unreviewed/2023/04/GHSA-m9j2-ffm7-xfgg/GHSA-m9j2-ffm7-xfgg.json new file mode 100644 index 00000000000..f294e629048 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-m9j2-ffm7-xfgg/GHSA-m9j2-ffm7-xfgg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9j2-ffm7-xfgg", + "modified": "2023-04-14T15:30:29Z", + "published": "2023-04-14T15:30:29Z", + "aliases": [ + "CVE-2022-45180" + ], + "details": "An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdesk_{DOMAIN]/export endpoint. A malicious user, authenticated to the product without any specific privilege, can use the API for exporting information about all users of the system (an operation intended to only be available to the system administrator).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45180" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-m9vc-392h-6mjx/GHSA-m9vc-392h-6mjx.json b/advisories/unreviewed/2023/04/GHSA-m9vc-392h-6mjx/GHSA-m9vc-392h-6mjx.json new file mode 100644 index 00000000000..0cdab5becb5 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-m9vc-392h-6mjx/GHSA-m9vc-392h-6mjx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9vc-392h-6mjx", + "modified": "2023-04-14T15:30:29Z", + "published": "2023-04-14T15:30:29Z", + "aliases": [ + "CVE-2023-1833" + ], + "details": "Authentication Bypass by Primary Weakness vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass.This issue affects Redline Router: before 7.17.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1833" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-23-0227" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-305" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-q7gw-cx2f-mh8f/GHSA-q7gw-cx2f-mh8f.json b/advisories/unreviewed/2023/04/GHSA-q7gw-cx2f-mh8f/GHSA-q7gw-cx2f-mh8f.json new file mode 100644 index 00000000000..96038cd52f3 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-q7gw-cx2f-mh8f/GHSA-q7gw-cx2f-mh8f.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7gw-cx2f-mh8f", + "modified": "2023-04-14T15:30:30Z", + "published": "2023-04-14T15:30:30Z", + "aliases": [ + "CVE-2023-26980" + ], + "details": "PAX Technology PAX A920 Pro PayDroid 8.1suffers from a Race Condition vulnerability, which allows attackers to bypass the payment software and force the OS to boot directly to Android during the boot process.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26980" + }, + { + "type": "WEB", + "url": "https://docs.google.com/document/d/189b1494s8RF8ksaOijKhKb-3B8gj3pLUmgn0dqg-jqs/edit" + }, + { + "type": "WEB", + "url": "https://drive.google.com/drive/u/0/folders/14X-XTYhkiaIVBS3zf68VigG4-imbKEuV" + }, + { + "type": "WEB", + "url": "https://uploads.strikinglycdn.com/files/f1d54bf4-3803-480c-b4d3-0943f7dac76e/A920_EN_20200605.pdf?id=237392" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-qg73-844m-wgxx/GHSA-qg73-844m-wgxx.json b/advisories/unreviewed/2023/04/GHSA-qg73-844m-wgxx/GHSA-qg73-844m-wgxx.json new file mode 100644 index 00000000000..328604d9128 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-qg73-844m-wgxx/GHSA-qg73-844m-wgxx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg73-844m-wgxx", + "modified": "2023-04-14T15:30:29Z", + "published": "2023-04-14T15:30:29Z", + "aliases": [ + "CVE-2023-29805" + ], + "details": "WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29805" + }, + { + "type": "WEB", + "url": "https://sore-pail-31b.notion.site/Command-Injection-2-WFS-SR03-436d09790c2f4e31b197c39711e17775" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-rh6m-58gf-q76q/GHSA-rh6m-58gf-q76q.json b/advisories/unreviewed/2023/04/GHSA-rh6m-58gf-q76q/GHSA-rh6m-58gf-q76q.json new file mode 100644 index 00000000000..f01aeeb26ea --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-rh6m-58gf-q76q/GHSA-rh6m-58gf-q76q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh6m-58gf-q76q", + "modified": "2023-04-14T15:30:30Z", + "published": "2023-04-14T15:30:30Z", + "aliases": [ + "CVE-2023-26559" + ], + "details": "A directory traversal vulnerability in Oxygen XML Web Author before 25.0.0.3 build 2023021715 and Oxygen Content Fusion before 5.0.3 build 2023022015 allows an attacker to read files from a WEB-INF directory via a crafted HTTP request. (XML Web Author 24.1.0.3 build 2023021714 and 23.1.1.4 build 2023021715 are also fixed versions.)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26559" + }, + { + "type": "WEB", + "url": "https://oxygenxml.com" + }, + { + "type": "WEB", + "url": "https://www.oxygenxml.com/security/advisory/SYNC-2023-042301.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T13:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-rmv6-3gmq-q94g/GHSA-rmv6-3gmq-q94g.json b/advisories/unreviewed/2023/04/GHSA-rmv6-3gmq-q94g/GHSA-rmv6-3gmq-q94g.json index 439bcc895f2..bc8694a733d 100644 --- a/advisories/unreviewed/2023/04/GHSA-rmv6-3gmq-q94g/GHSA-rmv6-3gmq-q94g.json +++ b/advisories/unreviewed/2023/04/GHSA-rmv6-3gmq-q94g/GHSA-rmv6-3gmq-q94g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rmv6-3gmq-q94g", - "modified": "2023-04-11T21:31:02Z", + "modified": "2023-04-14T15:30:28Z", "published": "2023-04-11T21:31:02Z", "aliases": [ "CVE-2023-24935" ], "details": "Microsoft Edge (Chromium-based) Spoofing Vulnerability", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-04-11T21:15:00Z" diff --git a/advisories/unreviewed/2023/04/GHSA-w6cf-v879-2jqv/GHSA-w6cf-v879-2jqv.json b/advisories/unreviewed/2023/04/GHSA-w6cf-v879-2jqv/GHSA-w6cf-v879-2jqv.json new file mode 100644 index 00000000000..c8a3a9bd4be --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-w6cf-v879-2jqv/GHSA-w6cf-v879-2jqv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6cf-v879-2jqv", + "modified": "2023-04-14T15:30:29Z", + "published": "2023-04-14T15:30:29Z", + "aliases": [ + "CVE-2023-29801" + ], + "details": "TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and rtLogServer parameters in the setSyslogCfg function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29801" + }, + { + "type": "WEB", + "url": "https://sore-pail-31b.notion.site/Command-Injection-2-af41252fe96244209589d4e6da9aa7b7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-w6jq-fpcp-h5cr/GHSA-w6jq-fpcp-h5cr.json b/advisories/unreviewed/2023/04/GHSA-w6jq-fpcp-h5cr/GHSA-w6jq-fpcp-h5cr.json new file mode 100644 index 00000000000..4019f89e673 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-w6jq-fpcp-h5cr/GHSA-w6jq-fpcp-h5cr.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6jq-fpcp-h5cr", + "modified": "2023-04-14T15:30:29Z", + "published": "2023-04-14T15:30:29Z", + "aliases": [ + "CVE-2023-2056" + ], + "details": "A vulnerability was found in DedeCMS up to 5.7.87 and classified as critical. This issue affects the function GetSystemFile of the file module_main.php. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-225941 was assigned to this vulnerability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2056" + }, + { + "type": "WEB", + "url": "https://gitee.com/ashe-king/cve/blob/master/dedecms%20rce2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.225941" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.225941" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-wxhc-w2rg-6qcw/GHSA-wxhc-w2rg-6qcw.json b/advisories/unreviewed/2023/04/GHSA-wxhc-w2rg-6qcw/GHSA-wxhc-w2rg-6qcw.json new file mode 100644 index 00000000000..f191566fad5 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-wxhc-w2rg-6qcw/GHSA-wxhc-w2rg-6qcw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxhc-w2rg-6qcw", + "modified": "2023-04-14T15:30:29Z", + "published": "2023-04-14T15:30:29Z", + "aliases": [ + "CVE-2023-29799" + ], + "details": "TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29799" + }, + { + "type": "WEB", + "url": "https://sore-pail-31b.notion.site/Command-Inject-6-3ee0faa243134ae2bc20e6670d80bada" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/04/GHSA-xm22-8c3w-j34x/GHSA-xm22-8c3w-j34x.json b/advisories/unreviewed/2023/04/GHSA-xm22-8c3w-j34x/GHSA-xm22-8c3w-j34x.json new file mode 100644 index 00000000000..bc92148cda5 --- /dev/null +++ b/advisories/unreviewed/2023/04/GHSA-xm22-8c3w-j34x/GHSA-xm22-8c3w-j34x.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xm22-8c3w-j34x", + "modified": "2023-04-14T15:30:29Z", + "published": "2023-04-14T15:30:29Z", + "aliases": [ + "CVE-2023-2058" + ], + "details": "A vulnerability was found in EyouCms up to 1.6.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /yxcms/index.php?r=admin/extendfield/mesedit&tabid=12&id=4 of the component HTTP POST Request Handler. The manipulation of the argument web_ico leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225943.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2058" + }, + { + "type": "WEB", + "url": "https://github.com/sleepyvv/vul_report/blob/main/EYOUCMS/XSS2.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.225943" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.225943" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-04-14T14:15:00Z" + } +} \ No newline at end of file