From 838459171b72b31dd2180eb662705b00bdafcb46 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 29 Aug 2024 12:32:27 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-4vhj-98r6-424h.json | 6 +- .../GHSA-2296-mr6j-mwf8.json | 38 ++++++++++++ .../GHSA-3576-xfx7-vjx5.json | 58 +++++++++++++++++++ .../GHSA-364p-86w3-x6rv.json | 38 ++++++++++++ .../GHSA-3cjp-4q2p-v3mg.json | 38 ++++++++++++ .../GHSA-3wrg-6mg5-jg2v.json | 54 +++++++++++++++++ .../GHSA-436p-pp82-ppwq.json | 43 ++++++++++++++ .../GHSA-4fx5-v359-c5hv.json | 38 ++++++++++++ .../GHSA-4mp9-r2w3-x435.json | 46 +++++++++++++++ .../GHSA-5hc2-jrv8-rj7h.json | 38 ++++++++++++ .../GHSA-65w4-w734-528c.json | 35 +++++++++++ .../GHSA-6qr3-hrff-mm2p.json | 42 ++++++++++++++ .../GHSA-7467-fqhh-vvx5.json | 38 ++++++++++++ .../GHSA-7xcm-586q-jcgq.json | 58 +++++++++++++++++++ .../GHSA-8423-fqh5-4pfr.json | 38 ++++++++++++ .../GHSA-87x7-pxqw-4gff.json | 50 ++++++++++++++++ .../GHSA-8m69-ggwv-26ff.json | 38 ++++++++++++ .../GHSA-c6g9-x2pg-x53c.json | 38 ++++++++++++ .../GHSA-f24r-9c3w-mjj9.json | 38 ++++++++++++ .../GHSA-f9pf-68jx-89j3.json | 51 ++++++++++++++++ .../GHSA-gmfg-97fg-3325.json | 38 ++++++++++++ .../GHSA-gv48-7crg-mcfr.json | 35 +++++++++++ .../GHSA-mg8j-w93w-xjgc.json | 35 +++++++++++ .../GHSA-mvj8-h6fp-pcrp.json | 38 ++++++++++++ .../GHSA-pf5c-h4wr-qw37.json | 42 ++++++++++++++ .../GHSA-phj6-qr2m-q4vq.json | 38 ++++++++++++ .../GHSA-q57h-cpxr-m8w6.json | 42 ++++++++++++++ .../GHSA-qhm7-j2q7-2p2f.json | 42 ++++++++++++++ .../GHSA-v5h9-4559-8f5h.json | 38 ++++++++++++ .../GHSA-vp4h-4vxh-9wx5.json | 35 +++++++++++ .../GHSA-w747-vcv4-jwcx.json | 38 ++++++++++++ .../GHSA-w95j-wcx9-78cv.json | 50 ++++++++++++++++ .../GHSA-x6xm-9hw6-q7gc.json | 38 ++++++++++++ .../GHSA-xj8p-vpqc-xj39.json | 50 ++++++++++++++++ .../GHSA-xxqw-83c7-r24r.json | 54 +++++++++++++++++ 35 files changed, 1435 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-2296-mr6j-mwf8/GHSA-2296-mr6j-mwf8.json create mode 100644 advisories/unreviewed/2024/08/GHSA-3576-xfx7-vjx5/GHSA-3576-xfx7-vjx5.json create mode 100644 advisories/unreviewed/2024/08/GHSA-364p-86w3-x6rv/GHSA-364p-86w3-x6rv.json create mode 100644 advisories/unreviewed/2024/08/GHSA-3cjp-4q2p-v3mg/GHSA-3cjp-4q2p-v3mg.json create mode 100644 advisories/unreviewed/2024/08/GHSA-3wrg-6mg5-jg2v/GHSA-3wrg-6mg5-jg2v.json create mode 100644 advisories/unreviewed/2024/08/GHSA-436p-pp82-ppwq/GHSA-436p-pp82-ppwq.json create mode 100644 advisories/unreviewed/2024/08/GHSA-4fx5-v359-c5hv/GHSA-4fx5-v359-c5hv.json create mode 100644 advisories/unreviewed/2024/08/GHSA-4mp9-r2w3-x435/GHSA-4mp9-r2w3-x435.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5hc2-jrv8-rj7h/GHSA-5hc2-jrv8-rj7h.json create mode 100644 advisories/unreviewed/2024/08/GHSA-65w4-w734-528c/GHSA-65w4-w734-528c.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6qr3-hrff-mm2p/GHSA-6qr3-hrff-mm2p.json create mode 100644 advisories/unreviewed/2024/08/GHSA-7467-fqhh-vvx5/GHSA-7467-fqhh-vvx5.json create mode 100644 advisories/unreviewed/2024/08/GHSA-7xcm-586q-jcgq/GHSA-7xcm-586q-jcgq.json create mode 100644 advisories/unreviewed/2024/08/GHSA-8423-fqh5-4pfr/GHSA-8423-fqh5-4pfr.json create mode 100644 advisories/unreviewed/2024/08/GHSA-87x7-pxqw-4gff/GHSA-87x7-pxqw-4gff.json create mode 100644 advisories/unreviewed/2024/08/GHSA-8m69-ggwv-26ff/GHSA-8m69-ggwv-26ff.json create mode 100644 advisories/unreviewed/2024/08/GHSA-c6g9-x2pg-x53c/GHSA-c6g9-x2pg-x53c.json create mode 100644 advisories/unreviewed/2024/08/GHSA-f24r-9c3w-mjj9/GHSA-f24r-9c3w-mjj9.json create mode 100644 advisories/unreviewed/2024/08/GHSA-f9pf-68jx-89j3/GHSA-f9pf-68jx-89j3.json create mode 100644 advisories/unreviewed/2024/08/GHSA-gmfg-97fg-3325/GHSA-gmfg-97fg-3325.json create mode 100644 advisories/unreviewed/2024/08/GHSA-gv48-7crg-mcfr/GHSA-gv48-7crg-mcfr.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mg8j-w93w-xjgc/GHSA-mg8j-w93w-xjgc.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mvj8-h6fp-pcrp/GHSA-mvj8-h6fp-pcrp.json create mode 100644 advisories/unreviewed/2024/08/GHSA-pf5c-h4wr-qw37/GHSA-pf5c-h4wr-qw37.json create mode 100644 advisories/unreviewed/2024/08/GHSA-phj6-qr2m-q4vq/GHSA-phj6-qr2m-q4vq.json create mode 100644 advisories/unreviewed/2024/08/GHSA-q57h-cpxr-m8w6/GHSA-q57h-cpxr-m8w6.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qhm7-j2q7-2p2f/GHSA-qhm7-j2q7-2p2f.json create mode 100644 advisories/unreviewed/2024/08/GHSA-v5h9-4559-8f5h/GHSA-v5h9-4559-8f5h.json create mode 100644 advisories/unreviewed/2024/08/GHSA-vp4h-4vxh-9wx5/GHSA-vp4h-4vxh-9wx5.json create mode 100644 advisories/unreviewed/2024/08/GHSA-w747-vcv4-jwcx/GHSA-w747-vcv4-jwcx.json create mode 100644 advisories/unreviewed/2024/08/GHSA-w95j-wcx9-78cv/GHSA-w95j-wcx9-78cv.json create mode 100644 advisories/unreviewed/2024/08/GHSA-x6xm-9hw6-q7gc/GHSA-x6xm-9hw6-q7gc.json create mode 100644 advisories/unreviewed/2024/08/GHSA-xj8p-vpqc-xj39/GHSA-xj8p-vpqc-xj39.json create mode 100644 advisories/unreviewed/2024/08/GHSA-xxqw-83c7-r24r/GHSA-xxqw-83c7-r24r.json diff --git a/advisories/github-reviewed/2018/10/GHSA-4vhj-98r6-424h/GHSA-4vhj-98r6-424h.json b/advisories/github-reviewed/2018/10/GHSA-4vhj-98r6-424h/GHSA-4vhj-98r6-424h.json index 31e8a20236d..2cbc875f045 100644 --- a/advisories/github-reviewed/2018/10/GHSA-4vhj-98r6-424h/GHSA-4vhj-98r6-424h.json +++ b/advisories/github-reviewed/2018/10/GHSA-4vhj-98r6-424h/GHSA-4vhj-98r6-424h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4vhj-98r6-424h", - "modified": "2024-05-14T14:47:31Z", + "modified": "2024-08-29T12:31:04Z", "published": "2018-10-17T16:23:26Z", "aliases": [ "CVE-2016-1000338" @@ -79,6 +79,10 @@ "type": "PACKAGE", "url": "https://github.com/bcgit/bc-java" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451@%3Csolr-user.lucene.apache.org%3E" diff --git a/advisories/unreviewed/2024/08/GHSA-2296-mr6j-mwf8/GHSA-2296-mr6j-mwf8.json b/advisories/unreviewed/2024/08/GHSA-2296-mr6j-mwf8/GHSA-2296-mr6j-mwf8.json new file mode 100644 index 00000000000..62265aa1425 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2296-mr6j-mwf8/GHSA-2296-mr6j-mwf8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2296-mr6j-mwf8", + "modified": "2024-08-29T12:31:04Z", + "published": "2024-08-29T12:31:04Z", + "aliases": [ + "CVE-2024-29724" + ], + "details": "SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/ax/registerSp/, parameter idDesafio.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29724" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-sportsnet" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3576-xfx7-vjx5/GHSA-3576-xfx7-vjx5.json b/advisories/unreviewed/2024/08/GHSA-3576-xfx7-vjx5/GHSA-3576-xfx7-vjx5.json new file mode 100644 index 00000000000..73878d7d9cc --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3576-xfx7-vjx5/GHSA-3576-xfx7-vjx5.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3576-xfx7-vjx5", + "modified": "2024-08-29T12:31:05Z", + "published": "2024-08-29T12:31:05Z", + "aliases": [ + "CVE-2024-7895" + ], + "details": "The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘type’ parameter in all versions up to, and including, 2.8.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7895" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/beaver-builder-lite-version/trunk/modules/button-group/button-group.php#L195" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/beaver-builder-lite-version/trunk/modules/button-group/includes/frontend.php#L2" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3143080%40beaver-builder-lite-version&new=3143080%40beaver-builder-lite-version&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/beaver-builder-lite-version/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f83db067-843f-4dd8-b5d1-83e95c6c88cc?source=cve" + }, + { + "type": "WEB", + "url": "https://www.wpbeaverbuilder.com/change-logs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-364p-86w3-x6rv/GHSA-364p-86w3-x6rv.json b/advisories/unreviewed/2024/08/GHSA-364p-86w3-x6rv/GHSA-364p-86w3-x6rv.json new file mode 100644 index 00000000000..65c29eee3d7 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-364p-86w3-x6rv/GHSA-364p-86w3-x6rv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-364p-86w3-x6rv", + "modified": "2024-08-29T12:31:05Z", + "published": "2024-08-29T12:31:05Z", + "aliases": [ + "CVE-2024-5622" + ], + "details": "An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may allow an authenticated local attacker to execute arbitrary code with elevated privileges.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5622" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/SA24P2014_Multiple_vulnerabilities_in_BR_APROL.pdf-367290ae.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3cjp-4q2p-v3mg/GHSA-3cjp-4q2p-v3mg.json b/advisories/unreviewed/2024/08/GHSA-3cjp-4q2p-v3mg/GHSA-3cjp-4q2p-v3mg.json new file mode 100644 index 00000000000..4b52833f974 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3cjp-4q2p-v3mg/GHSA-3cjp-4q2p-v3mg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cjp-4q2p-v3mg", + "modified": "2024-08-29T12:31:04Z", + "published": "2024-08-29T12:31:04Z", + "aliases": [ + "CVE-2024-29727" + ], + "details": "SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/sendParticipationRemember/ , parameter send.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29727" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-sportsnet" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3wrg-6mg5-jg2v/GHSA-3wrg-6mg5-jg2v.json b/advisories/unreviewed/2024/08/GHSA-3wrg-6mg5-jg2v/GHSA-3wrg-6mg5-jg2v.json new file mode 100644 index 00000000000..eade5490c2c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3wrg-6mg5-jg2v/GHSA-3wrg-6mg5-jg2v.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wrg-6mg5-jg2v", + "modified": "2024-08-29T12:31:05Z", + "published": "2024-08-29T12:31:05Z", + "aliases": [ + "CVE-2024-8295" + ], + "details": "A vulnerability has been found in FeehiCMS up to 2.1.1 and classified as critical. This vulnerability affects the function createBanner of the file /admin/index.php?r=banner%2Fbanner-create. The manipulation of the argument BannerForm[img] leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8295" + }, + { + "type": "WEB", + "url": "https://gitee.com/A0kooo/cve_article/blob/master/feehi_cms/file_upload2/Fichkems%20banner%20file%20upload%20vulnerability.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276070" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276070" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.394560" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T12:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-436p-pp82-ppwq/GHSA-436p-pp82-ppwq.json b/advisories/unreviewed/2024/08/GHSA-436p-pp82-ppwq/GHSA-436p-pp82-ppwq.json new file mode 100644 index 00000000000..5f8cf8d520c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-436p-pp82-ppwq/GHSA-436p-pp82-ppwq.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-436p-pp82-ppwq", + "modified": "2024-08-29T12:31:04Z", + "published": "2024-08-29T12:31:04Z", + "aliases": [ + "CVE-2024-43700" + ], + "details": "xfpt versions prior to 1.01 fails to handle appropriately some parameters inside the input data, resulting in a stack-based buffer overflow vulnerability. When a user of the affected product is tricked to process a specially crafted file, arbitrary code may be executed on the user's environment.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43700" + }, + { + "type": "WEB", + "url": "https://github.com/PhilipHazel/xfpt/commit/a690304bbd3fd19e9dfdad50dcc87ad829f744e4" + }, + { + "type": "WEB", + "url": "https://github.com/PhilipHazel/xfpt" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU96498690" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4fx5-v359-c5hv/GHSA-4fx5-v359-c5hv.json b/advisories/unreviewed/2024/08/GHSA-4fx5-v359-c5hv/GHSA-4fx5-v359-c5hv.json new file mode 100644 index 00000000000..9980c3f60a6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4fx5-v359-c5hv/GHSA-4fx5-v359-c5hv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fx5-v359-c5hv", + "modified": "2024-08-29T12:31:04Z", + "published": "2024-08-29T12:31:04Z", + "aliases": [ + "CVE-2024-29729" + ], + "details": "SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/generateShortURL/, parameter url.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29729" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-sportsnet" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4mp9-r2w3-x435/GHSA-4mp9-r2w3-x435.json b/advisories/unreviewed/2024/08/GHSA-4mp9-r2w3-x435/GHSA-4mp9-r2w3-x435.json new file mode 100644 index 00000000000..bc86b3edb40 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4mp9-r2w3-x435/GHSA-4mp9-r2w3-x435.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mp9-r2w3-x435", + "modified": "2024-08-29T12:31:04Z", + "published": "2024-08-29T12:31:04Z", + "aliases": [ + "CVE-2022-2440" + ], + "details": "The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' parameter in versions up to, and including 2.8. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2440" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/theme-editor/trunk/ms_child_theme_editor.php#L495" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3142694" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/88fe46bf-8e85-4550-92ad-bdd426e5a745?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5hc2-jrv8-rj7h/GHSA-5hc2-jrv8-rj7h.json b/advisories/unreviewed/2024/08/GHSA-5hc2-jrv8-rj7h/GHSA-5hc2-jrv8-rj7h.json new file mode 100644 index 00000000000..73daacf1683 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5hc2-jrv8-rj7h/GHSA-5hc2-jrv8-rj7h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hc2-jrv8-rj7h", + "modified": "2024-08-29T12:31:04Z", + "published": "2024-08-29T12:31:04Z", + "aliases": [ + "CVE-2024-29730" + ], + "details": "SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query:  https://XXXXXXX.saludydesafio.com/app/ax/consejoRandom/ , parameter idCat;.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29730" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-sportsnet" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-65w4-w734-528c/GHSA-65w4-w734-528c.json b/advisories/unreviewed/2024/08/GHSA-65w4-w734-528c/GHSA-65w4-w734-528c.json new file mode 100644 index 00000000000..77ce230bf59 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-65w4-w734-528c/GHSA-65w4-w734-528c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65w4-w734-528c", + "modified": "2024-08-29T12:31:05Z", + "published": "2024-08-29T12:31:05Z", + "aliases": [ + "CVE-2024-7132" + ], + "details": "The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of its block, which could allow users with the capability to publish posts (editor and admin by default) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7132" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/16deb743-6fe9-43a2-9586-d92cfe1daa17" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6qr3-hrff-mm2p/GHSA-6qr3-hrff-mm2p.json b/advisories/unreviewed/2024/08/GHSA-6qr3-hrff-mm2p/GHSA-6qr3-hrff-mm2p.json new file mode 100644 index 00000000000..310e5d19e0c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6qr3-hrff-mm2p/GHSA-6qr3-hrff-mm2p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qr3-hrff-mm2p", + "modified": "2024-08-29T12:31:05Z", + "published": "2024-08-29T12:31:05Z", + "aliases": [ + "CVE-2024-5987" + ], + "details": "The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_contrast_variations' and 'save_empty_contrast_variations' functions in all versions up to, and including, 0.6.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit or delete contrast settings. Please note these issues were patched in 0.6.2.8, though it broke functionality and the vendor has not responded to our follow-ups.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5987" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3117664%40wp-accessibility-helper&new=3117664%40wp-accessibility-helper&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d3beee75-0480-4504-a177-45f8cd32cf36?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7467-fqhh-vvx5/GHSA-7467-fqhh-vvx5.json b/advisories/unreviewed/2024/08/GHSA-7467-fqhh-vvx5/GHSA-7467-fqhh-vvx5.json new file mode 100644 index 00000000000..bacf9ab26c1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7467-fqhh-vvx5/GHSA-7467-fqhh-vvx5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7467-fqhh-vvx5", + "modified": "2024-08-29T12:31:04Z", + "published": "2024-08-29T12:31:04Z", + "aliases": [ + "CVE-2024-29731" + ], + "details": "SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query:  https://XXXXXXX.saludydesafio.com/app/ax/checkBlindFields/ , parameters idChallenge and idEmpresa.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29731" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-sportsnet" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7xcm-586q-jcgq/GHSA-7xcm-586q-jcgq.json b/advisories/unreviewed/2024/08/GHSA-7xcm-586q-jcgq/GHSA-7xcm-586q-jcgq.json new file mode 100644 index 00000000000..d1af74737bd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7xcm-586q-jcgq/GHSA-7xcm-586q-jcgq.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xcm-586q-jcgq", + "modified": "2024-08-29T12:31:05Z", + "published": "2024-08-29T12:31:05Z", + "aliases": [ + "CVE-2024-7607" + ], + "details": "The Front End Users plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 3.2.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7607" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/front-end-only-users/trunk/html/UsersPage.php#L42" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/front-end-only-users/trunk/html/UsersPage.php#L60" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/front-end-only-users/trunk/html/UsersPage.php#L63" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/front-end-only-users/trunk/html/UsersPage.php#L76" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3142978" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ec162cdc-d4cd-47d9-b941-24bfee6c48fd?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8423-fqh5-4pfr/GHSA-8423-fqh5-4pfr.json b/advisories/unreviewed/2024/08/GHSA-8423-fqh5-4pfr/GHSA-8423-fqh5-4pfr.json new file mode 100644 index 00000000000..38f97e76156 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8423-fqh5-4pfr/GHSA-8423-fqh5-4pfr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8423-fqh5-4pfr", + "modified": "2024-08-29T12:31:05Z", + "published": "2024-08-29T12:31:05Z", + "aliases": [ + "CVE-2024-5624" + ], + "details": "Reflected Cross-Site Scripting (XSS) in Shift Logbook application of B&R APROL <= R 4.4-00P3 may allow a network-based attacker to execute arbitrary JavaScript code in the context of the user's browser session", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5624" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/SA24P2014_Multiple_vulnerabilities_in_BR_APROL.pdf-367290ae.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-87x7-pxqw-4gff/GHSA-87x7-pxqw-4gff.json b/advisories/unreviewed/2024/08/GHSA-87x7-pxqw-4gff/GHSA-87x7-pxqw-4gff.json new file mode 100644 index 00000000000..23103890bc3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-87x7-pxqw-4gff/GHSA-87x7-pxqw-4gff.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87x7-pxqw-4gff", + "modified": "2024-08-29T12:31:05Z", + "published": "2024-08-29T12:31:05Z", + "aliases": [ + "CVE-2024-7606" + ], + "details": "The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'user-search' shortcode in all versions up to, and including, 3.2.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7606" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/front-end-only-users/trunk/Shortcodes/Insert_User_Search.php#L106" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/front-end-only-users/trunk/Shortcodes/Insert_User_Search.php#L80" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3142978" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/048ea84c-0d53-434b-ae49-d804ec1de8c4?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8m69-ggwv-26ff/GHSA-8m69-ggwv-26ff.json b/advisories/unreviewed/2024/08/GHSA-8m69-ggwv-26ff/GHSA-8m69-ggwv-26ff.json new file mode 100644 index 00000000000..d1690e23165 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8m69-ggwv-26ff/GHSA-8m69-ggwv-26ff.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m69-ggwv-26ff", + "modified": "2024-08-29T12:31:04Z", + "published": "2024-08-29T12:31:04Z", + "aliases": [ + "CVE-2024-29723" + ], + "details": "SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/conexiones/ax/openTracExt/, parameter categoria;.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29723" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-sportsnet" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c6g9-x2pg-x53c/GHSA-c6g9-x2pg-x53c.json b/advisories/unreviewed/2024/08/GHSA-c6g9-x2pg-x53c/GHSA-c6g9-x2pg-x53c.json new file mode 100644 index 00000000000..a0ebb85bfce --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c6g9-x2pg-x53c/GHSA-c6g9-x2pg-x53c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6g9-x2pg-x53c", + "modified": "2024-08-29T12:31:04Z", + "published": "2024-08-29T12:31:04Z", + "aliases": [ + "CVE-2024-29728" + ], + "details": "SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/inscribeUsuario/ , parameter idDesafio.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29728" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-sportsnet" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f24r-9c3w-mjj9/GHSA-f24r-9c3w-mjj9.json b/advisories/unreviewed/2024/08/GHSA-f24r-9c3w-mjj9/GHSA-f24r-9c3w-mjj9.json new file mode 100644 index 00000000000..23c3b32d62f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f24r-9c3w-mjj9/GHSA-f24r-9c3w-mjj9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f24r-9c3w-mjj9", + "modified": "2024-08-29T12:31:04Z", + "published": "2024-08-29T12:31:04Z", + "aliases": [ + "CVE-2024-38304" + ], + "details": "Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38304" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000228137/dsa-2024-310-security-update-for-dell-poweredge-server-for-access-of-memory-location-after-end-of-buffer-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-788" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f9pf-68jx-89j3/GHSA-f9pf-68jx-89j3.json b/advisories/unreviewed/2024/08/GHSA-f9pf-68jx-89j3/GHSA-f9pf-68jx-89j3.json new file mode 100644 index 00000000000..1c2fc8c9100 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f9pf-68jx-89j3/GHSA-f9pf-68jx-89j3.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9pf-68jx-89j3", + "modified": "2024-08-29T12:31:04Z", + "published": "2024-08-29T12:31:04Z", + "aliases": [ + "CVE-2021-4442" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: add sanity tests to TCP_QUEUE_SEQ\n\nQingyu Li reported a syzkaller bug where the repro\nchanges RCV SEQ _after_ restoring data in the receive queue.\n\nmprotect(0x4aa000, 12288, PROT_READ) = 0\nmmap(0x1ffff000, 4096, PROT_NONE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x1ffff000\nmmap(0x20000000, 16777216, PROT_READ|PROT_WRITE|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x20000000\nmmap(0x21000000, 4096, PROT_NONE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x21000000\nsocket(AF_INET6, SOCK_STREAM, IPPROTO_IP) = 3\nsetsockopt(3, SOL_TCP, TCP_REPAIR, [1], 4) = 0\nconnect(3, {sa_family=AF_INET6, sin6_port=htons(0), sin6_flowinfo=htonl(0), inet_pton(AF_INET6, \"::1\", &sin6_addr), sin6_scope_id=0}, 28) = 0\nsetsockopt(3, SOL_TCP, TCP_REPAIR_QUEUE, [1], 4) = 0\nsendmsg(3, {msg_name=NULL, msg_namelen=0, msg_iov=[{iov_base=\"0x0000000000000003\\0\\0\", iov_len=20}], msg_iovlen=1, msg_controllen=0, msg_flags=0}, 0) = 20\nsetsockopt(3, SOL_TCP, TCP_REPAIR, [0], 4) = 0\nsetsockopt(3, SOL_TCP, TCP_QUEUE_SEQ, [128], 4) = 0\nrecvfrom(3, NULL, 20, 0, NULL, NULL) = -1 ECONNRESET (Connection reset by peer)\n\nsyslog shows:\n[ 111.205099] TCP recvmsg seq # bug 2: copied 80, seq 0, rcvnxt 80, fl 0\n[ 111.207894] WARNING: CPU: 1 PID: 356 at net/ipv4/tcp.c:2343 tcp_recvmsg_locked+0x90e/0x29a0\n\nThis should not be allowed. TCP_QUEUE_SEQ should only be used\nwhen queues are empty.\n\nThis patch fixes this case, and the tx path as well.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-4442" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/046f3c1c2ff450fb7ae53650e9a95e0074a61f3e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/319f460237fc2965a80aa9a055044e1da7b3692a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3b72d5a703842f582502d97906f17d6ee122dac2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3bf899438c123c444f6b644a57784dfbb6b15ad6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8811f4a9836e31c14ecdf79d9f3cb7c5d463265d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gmfg-97fg-3325/GHSA-gmfg-97fg-3325.json b/advisories/unreviewed/2024/08/GHSA-gmfg-97fg-3325/GHSA-gmfg-97fg-3325.json new file mode 100644 index 00000000000..f5b745a921f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gmfg-97fg-3325/GHSA-gmfg-97fg-3325.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmfg-97fg-3325", + "modified": "2024-08-29T12:31:04Z", + "published": "2024-08-29T12:31:04Z", + "aliases": [ + "CVE-2024-29725" + ], + "details": "SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/sort_bloques/, parameter list.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29725" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-sportsnet" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gv48-7crg-mcfr/GHSA-gv48-7crg-mcfr.json b/advisories/unreviewed/2024/08/GHSA-gv48-7crg-mcfr/GHSA-gv48-7crg-mcfr.json new file mode 100644 index 00000000000..744570fef02 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gv48-7crg-mcfr/GHSA-gv48-7crg-mcfr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv48-7crg-mcfr", + "modified": "2024-08-29T12:31:05Z", + "published": "2024-08-29T12:31:05Z", + "aliases": [ + "CVE-2024-5417" + ], + "details": "The Gutentor WordPress plugin before 3.3.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5417" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/fb7d6839-9ccb-4a0f-9dca-d6841f666a1b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mg8j-w93w-xjgc/GHSA-mg8j-w93w-xjgc.json b/advisories/unreviewed/2024/08/GHSA-mg8j-w93w-xjgc/GHSA-mg8j-w93w-xjgc.json new file mode 100644 index 00000000000..fbf269f58d1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mg8j-w93w-xjgc/GHSA-mg8j-w93w-xjgc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mg8j-w93w-xjgc", + "modified": "2024-08-29T12:31:05Z", + "published": "2024-08-29T12:31:05Z", + "aliases": [ + "CVE-2024-45440" + ], + "details": "core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of a file that does not exist.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45440" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/project/drupal/issues/3457781" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mvj8-h6fp-pcrp/GHSA-mvj8-h6fp-pcrp.json b/advisories/unreviewed/2024/08/GHSA-mvj8-h6fp-pcrp/GHSA-mvj8-h6fp-pcrp.json new file mode 100644 index 00000000000..f88cb5d929b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mvj8-h6fp-pcrp/GHSA-mvj8-h6fp-pcrp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvj8-h6fp-pcrp", + "modified": "2024-08-29T12:31:05Z", + "published": "2024-08-29T12:31:05Z", + "aliases": [ + "CVE-2024-5623" + ], + "details": "An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get other users to execute arbitrary code under their privileges.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5623" + }, + { + "type": "WEB", + "url": "https://www.br-automation.com/fileadmin/SA24P2014_Multiple_vulnerabilities_in_BR_APROL.pdf-367290ae.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pf5c-h4wr-qw37/GHSA-pf5c-h4wr-qw37.json b/advisories/unreviewed/2024/08/GHSA-pf5c-h4wr-qw37/GHSA-pf5c-h4wr-qw37.json new file mode 100644 index 00000000000..2a304689cb9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pf5c-h4wr-qw37/GHSA-pf5c-h4wr-qw37.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf5c-h4wr-qw37", + "modified": "2024-08-29T12:31:05Z", + "published": "2024-08-29T12:31:05Z", + "aliases": [ + "CVE-2024-6551" + ], + "details": "The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.15.1. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6551" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/give/tags/3.15.1/vendor/vendor-prefixed/symfony/http-foundation/Tests/Fixtures/response-functional/common.inc#L23" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2a13ce09-b312-4186-b0e2-63065c47f15d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-phj6-qr2m-q4vq/GHSA-phj6-qr2m-q4vq.json b/advisories/unreviewed/2024/08/GHSA-phj6-qr2m-q4vq/GHSA-phj6-qr2m-q4vq.json new file mode 100644 index 00000000000..a3e6abb7b3f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-phj6-qr2m-q4vq/GHSA-phj6-qr2m-q4vq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phj6-qr2m-q4vq", + "modified": "2024-08-29T12:31:04Z", + "published": "2024-08-29T12:31:04Z", + "aliases": [ + "CVE-2024-29726" + ], + "details": "SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/setAsRead/, parameter id.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29726" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-sportsnet" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q57h-cpxr-m8w6/GHSA-q57h-cpxr-m8w6.json b/advisories/unreviewed/2024/08/GHSA-q57h-cpxr-m8w6/GHSA-q57h-cpxr-m8w6.json new file mode 100644 index 00000000000..77f8371e0a1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q57h-cpxr-m8w6/GHSA-q57h-cpxr-m8w6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q57h-cpxr-m8w6", + "modified": "2024-08-29T12:31:04Z", + "published": "2024-08-29T12:31:04Z", + "aliases": [ + "CVE-2024-3944" + ], + "details": "The WP To Do plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3944" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-todo/trunk/inc/Base/Model.php#L225" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b36b9b8a-41b0-4b57-92c7-5acebe2b0bae?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qhm7-j2q7-2p2f/GHSA-qhm7-j2q7-2p2f.json b/advisories/unreviewed/2024/08/GHSA-qhm7-j2q7-2p2f/GHSA-qhm7-j2q7-2p2f.json new file mode 100644 index 00000000000..2d8e366d105 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qhm7-j2q7-2p2f/GHSA-qhm7-j2q7-2p2f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhm7-j2q7-2p2f", + "modified": "2024-08-29T12:31:05Z", + "published": "2024-08-29T12:31:05Z", + "aliases": [ + "CVE-2024-5857" + ], + "details": "The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the af2_handel_file_remove AJAX action in all versions up to, and including, 3.7.3.2. This makes it possible for unauthenticated attackers to delete arbitrary media files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5857" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3141470/funnelforms-free/trunk/frontend/frontend.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5cd0e015-abf2-4905-8b42-46b685be2c74?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v5h9-4559-8f5h/GHSA-v5h9-4559-8f5h.json b/advisories/unreviewed/2024/08/GHSA-v5h9-4559-8f5h/GHSA-v5h9-4559-8f5h.json new file mode 100644 index 00000000000..9eff1635f8a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v5h9-4559-8f5h/GHSA-v5h9-4559-8f5h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5h9-4559-8f5h", + "modified": "2024-08-29T12:31:04Z", + "published": "2024-08-29T12:31:04Z", + "aliases": [ + "CVE-2024-38303" + ], + "details": "Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38303" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000228135/dsa-2024-309-security-update-for-dell-poweredge-server-for-improper-input-validation-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vp4h-4vxh-9wx5/GHSA-vp4h-4vxh-9wx5.json b/advisories/unreviewed/2024/08/GHSA-vp4h-4vxh-9wx5/GHSA-vp4h-4vxh-9wx5.json new file mode 100644 index 00000000000..c634179cb1e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vp4h-4vxh-9wx5/GHSA-vp4h-4vxh-9wx5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp4h-4vxh-9wx5", + "modified": "2024-08-29T12:31:05Z", + "published": "2024-08-29T12:31:05Z", + "aliases": [ + "CVE-2024-6927" + ], + "details": "The Viral Signup WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6927" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/05024ff5-4c7a-4941-8dae-c1a8d2d4e202" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w747-vcv4-jwcx/GHSA-w747-vcv4-jwcx.json b/advisories/unreviewed/2024/08/GHSA-w747-vcv4-jwcx/GHSA-w747-vcv4-jwcx.json new file mode 100644 index 00000000000..41669dd72d0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w747-vcv4-jwcx/GHSA-w747-vcv4-jwcx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w747-vcv4-jwcx", + "modified": "2024-08-29T12:31:04Z", + "published": "2024-08-29T12:31:04Z", + "aliases": [ + "CVE-2024-43986" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagePeople Team Taxi Booking Manager for WooCommerce allows Stored XSS.This issue affects Taxi Booking Manager for WooCommerce: through 1.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43986" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ecab-taxi-booking-manager/wordpress-e-cab-taxi-booking-manager-plugin-1-0-9-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w95j-wcx9-78cv/GHSA-w95j-wcx9-78cv.json b/advisories/unreviewed/2024/08/GHSA-w95j-wcx9-78cv/GHSA-w95j-wcx9-78cv.json new file mode 100644 index 00000000000..5fd9fa934b2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w95j-wcx9-78cv/GHSA-w95j-wcx9-78cv.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w95j-wcx9-78cv", + "modified": "2024-08-29T12:31:05Z", + "published": "2024-08-29T12:31:05Z", + "aliases": [ + "CVE-2024-7418" + ], + "details": "The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.7.11 via the post_query_guten and post_query functions. This makes it possible for authenticated attackers, with contributor-level access and above, to extract information from posts that are not public (i.e. draft, future, etc..).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7418" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3142599/the-post-grid/trunk/app/Controllers/Blocks/BlockBase.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3142599/the-post-grid/trunk/app/Widgets/elementor/rtTPGElementorQuery.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3142599%40the-post-grid&new=3142599%40the-post-grid&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dddecb2e-9ad6-4e44-afce-5eba7da6322d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-x6xm-9hw6-q7gc/GHSA-x6xm-9hw6-q7gc.json b/advisories/unreviewed/2024/08/GHSA-x6xm-9hw6-q7gc/GHSA-x6xm-9hw6-q7gc.json new file mode 100644 index 00000000000..933d1b0d317 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x6xm-9hw6-q7gc/GHSA-x6xm-9hw6-q7gc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6xm-9hw6-q7gc", + "modified": "2024-08-29T12:31:05Z", + "published": "2024-08-29T12:31:05Z", + "aliases": [ + "CVE-2024-4428" + ], + "details": "Improper Privilege Management vulnerability in Menulux Information Technologies Managment Portal allows Collect Data as Provided by Users.This issue affects Managment Portal: through 21.05.2024.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4428" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1356" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xj8p-vpqc-xj39/GHSA-xj8p-vpqc-xj39.json b/advisories/unreviewed/2024/08/GHSA-xj8p-vpqc-xj39/GHSA-xj8p-vpqc-xj39.json new file mode 100644 index 00000000000..00485038b70 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xj8p-vpqc-xj39/GHSA-xj8p-vpqc-xj39.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xj8p-vpqc-xj39", + "modified": "2024-08-29T12:31:05Z", + "published": "2024-08-29T12:31:05Z", + "aliases": [ + "CVE-2024-7856" + ], + "details": "The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on the 'file' parameter in all versions up to, and including, 5.7.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files which can make remote code execution possible when wp-config.php is deleted.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7856" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/mp3-music-player-by-sonaar/tags/5.7.0.1/includes/class-sonaar-music.php#L739" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/mp3-music-player-by-sonaar/tags/5.7.0.1/includes/class-sonaar-music.php#L755" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3142445/mp3-music-player-by-sonaar/trunk/includes/class-sonaar-music.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/43adc9dd-1780-440f-90c2-ff05a22eb084?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xxqw-83c7-r24r/GHSA-xxqw-83c7-r24r.json b/advisories/unreviewed/2024/08/GHSA-xxqw-83c7-r24r/GHSA-xxqw-83c7-r24r.json new file mode 100644 index 00000000000..c6f52caefd6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xxqw-83c7-r24r/GHSA-xxqw-83c7-r24r.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxqw-83c7-r24r", + "modified": "2024-08-29T12:31:05Z", + "published": "2024-08-29T12:31:05Z", + "aliases": [ + "CVE-2024-8294" + ], + "details": "A vulnerability, which was classified as critical, was found in FeehiCMS up to 2.1.1. This affects the function update of the file /admin/index.php?r=friendly-link%2Fupdate. The manipulation of the argument FriendlyLink[image] leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8294" + }, + { + "type": "WEB", + "url": "https://gitee.com/A0kooo/cve_article/blob/master/feehi_cms/Fichkems%20Friendley-Link%20file%20upload%20vulnerability.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.276069" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.276069" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.394556" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-29T11:15:29Z" + } +} \ No newline at end of file