Publish Advisories

GHSA-2f9q-qvgh-8gvv
GHSA-2jx2-r7f9-93pw
GHSA-h86h-5wxq-fv48
GHSA-v9pc-9fc9-4ff8
This commit is contained in:
advisory-database[bot]
2024-01-29 00:31:32 +00:00
parent c1eb04da19
commit 837f210e3c
4 changed files with 177 additions and 0 deletions
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2f9q-qvgh-8gvv",
"modified": "2024-01-29T00:30:17Z",
"published": "2024-01-29T00:30:17Z",
"aliases": [
"CVE-2024-0987"
],
"details": "A vulnerability classified as critical has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected is an unknown function of the file /runtime/log. The manipulation leads to improper output neutralization for logs. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252252. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0987"
},
{
"type": "WEB",
"url": "https://note.zhaoj.in/share/mhLwGOcLxYfP"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.252252"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.252252"
}
],
"database_specific": {
"cwe_ids": [
"CWE-117"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-29T00:15:08Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2jx2-r7f9-93pw",
"modified": "2024-01-29T00:30:17Z",
"published": "2024-01-29T00:30:17Z",
"aliases": [
"CVE-2024-23782"
],
"details": "Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier versions. If this vulnerability is exploited, a user with a contributor or higher privilege may execute an arbitrary script on the web browser of the user who accessed the website using the product.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23782"
},
{
"type": "WEB",
"url": "https://developer.a-blogcms.jp/blog/news/JVN-34565930.html"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN34565930/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-28T23:15:58Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h86h-5wxq-fv48",
"modified": "2024-01-29T00:30:17Z",
"published": "2024-01-29T00:30:17Z",
"aliases": [
"CVE-2024-0988"
],
"details": "A vulnerability classified as critical was found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this vulnerability is the function checklogin of the file /application/index/common.php. The manipulation of the argument App_User_id/App_user_Token leads to improper authentication. The exploit has been disclosed to the public and may be used. The identifier VDB-252253 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0988"
},
{
"type": "WEB",
"url": "https://note.zhaoj.in/share/2dBOnquxgCDl"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.252253"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.252253"
}
],
"database_specific": {
"cwe_ids": [
"CWE-287"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-29T00:15:08Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v9pc-9fc9-4ff8",
"modified": "2024-01-29T00:30:17Z",
"published": "2024-01-29T00:30:17Z",
"aliases": [
"CVE-2024-0986"
],
"details": "A vulnerability was found in Issabel PBX 4.0.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php?menu=asterisk_cli of the component Asterisk-Cli. The manipulation of the argument Command leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252251. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0986"
},
{
"type": "WEB",
"url": "https://drive.google.com/file/d/10BYLQ7Rk4oag96afLZouSvDDPvsO7SoJ/view?usp=drive_link"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.252251"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.252251"
}
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-29T00:15:07Z"
}
}