From 837f210e3c7a181abe0c494ef5cf5f5b15f00f54 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 29 Jan 2024 00:31:32 +0000 Subject: [PATCH] Publish Advisories GHSA-2f9q-qvgh-8gvv GHSA-2jx2-r7f9-93pw GHSA-h86h-5wxq-fv48 GHSA-v9pc-9fc9-4ff8 --- .../GHSA-2f9q-qvgh-8gvv.json | 46 +++++++++++++++++++ .../GHSA-2jx2-r7f9-93pw.json | 39 ++++++++++++++++ .../GHSA-h86h-5wxq-fv48.json | 46 +++++++++++++++++++ .../GHSA-v9pc-9fc9-4ff8.json | 46 +++++++++++++++++++ 4 files changed, 177 insertions(+) create mode 100644 advisories/unreviewed/2024/01/GHSA-2f9q-qvgh-8gvv/GHSA-2f9q-qvgh-8gvv.json create mode 100644 advisories/unreviewed/2024/01/GHSA-2jx2-r7f9-93pw/GHSA-2jx2-r7f9-93pw.json create mode 100644 advisories/unreviewed/2024/01/GHSA-h86h-5wxq-fv48/GHSA-h86h-5wxq-fv48.json create mode 100644 advisories/unreviewed/2024/01/GHSA-v9pc-9fc9-4ff8/GHSA-v9pc-9fc9-4ff8.json diff --git a/advisories/unreviewed/2024/01/GHSA-2f9q-qvgh-8gvv/GHSA-2f9q-qvgh-8gvv.json b/advisories/unreviewed/2024/01/GHSA-2f9q-qvgh-8gvv/GHSA-2f9q-qvgh-8gvv.json new file mode 100644 index 00000000000..baf18573a96 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2f9q-qvgh-8gvv/GHSA-2f9q-qvgh-8gvv.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f9q-qvgh-8gvv", + "modified": "2024-01-29T00:30:17Z", + "published": "2024-01-29T00:30:17Z", + "aliases": [ + "CVE-2024-0987" + ], + "details": "A vulnerability classified as critical has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected is an unknown function of the file /runtime/log. The manipulation leads to improper output neutralization for logs. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252252. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0987" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/mhLwGOcLxYfP" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252252" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252252" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-117" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T00:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-2jx2-r7f9-93pw/GHSA-2jx2-r7f9-93pw.json b/advisories/unreviewed/2024/01/GHSA-2jx2-r7f9-93pw/GHSA-2jx2-r7f9-93pw.json new file mode 100644 index 00000000000..3d6701c6c70 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2jx2-r7f9-93pw/GHSA-2jx2-r7f9-93pw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jx2-r7f9-93pw", + "modified": "2024-01-29T00:30:17Z", + "published": "2024-01-29T00:30:17Z", + "aliases": [ + "CVE-2024-23782" + ], + "details": "Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier versions. If this vulnerability is exploited, a user with a contributor or higher privilege may execute an arbitrary script on the web browser of the user who accessed the website using the product.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23782" + }, + { + "type": "WEB", + "url": "https://developer.a-blogcms.jp/blog/news/JVN-34565930.html" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN34565930/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-28T23:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-h86h-5wxq-fv48/GHSA-h86h-5wxq-fv48.json b/advisories/unreviewed/2024/01/GHSA-h86h-5wxq-fv48/GHSA-h86h-5wxq-fv48.json new file mode 100644 index 00000000000..f49833bc158 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-h86h-5wxq-fv48/GHSA-h86h-5wxq-fv48.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h86h-5wxq-fv48", + "modified": "2024-01-29T00:30:17Z", + "published": "2024-01-29T00:30:17Z", + "aliases": [ + "CVE-2024-0988" + ], + "details": "A vulnerability classified as critical was found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this vulnerability is the function checklogin of the file /application/index/common.php. The manipulation of the argument App_User_id/App_user_Token leads to improper authentication. The exploit has been disclosed to the public and may be used. The identifier VDB-252253 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0988" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/2dBOnquxgCDl" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252253" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252253" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T00:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-v9pc-9fc9-4ff8/GHSA-v9pc-9fc9-4ff8.json b/advisories/unreviewed/2024/01/GHSA-v9pc-9fc9-4ff8/GHSA-v9pc-9fc9-4ff8.json new file mode 100644 index 00000000000..a27e44ae276 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-v9pc-9fc9-4ff8/GHSA-v9pc-9fc9-4ff8.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9pc-9fc9-4ff8", + "modified": "2024-01-29T00:30:17Z", + "published": "2024-01-29T00:30:17Z", + "aliases": [ + "CVE-2024-0986" + ], + "details": "A vulnerability was found in Issabel PBX 4.0.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php?menu=asterisk_cli of the component Asterisk-Cli. The manipulation of the argument Command leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252251. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0986" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/10BYLQ7Rk4oag96afLZouSvDDPvsO7SoJ/view?usp=drive_link" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252251" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252251" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-29T00:15:07Z" + } +} \ No newline at end of file