diff --git a/advisories/unreviewed/2022/05/GHSA-76jq-2jjj-76w4/GHSA-76jq-2jjj-76w4.json b/advisories/unreviewed/2022/05/GHSA-76jq-2jjj-76w4/GHSA-76jq-2jjj-76w4.json index 692d66cf76f..b7191b09a95 100644 --- a/advisories/unreviewed/2022/05/GHSA-76jq-2jjj-76w4/GHSA-76jq-2jjj-76w4.json +++ b/advisories/unreviewed/2022/05/GHSA-76jq-2jjj-76w4/GHSA-76jq-2jjj-76w4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-76jq-2jjj-76w4", - "modified": "2022-05-24T19:11:04Z", + "modified": "2024-03-06T03:30:28Z", "published": "2022-05-24T19:11:04Z", "aliases": [ "CVE-2021-36380" ], "details": "Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/06/GHSA-qhm9-gg74-g6m6/GHSA-qhm9-gg74-g6m6.json b/advisories/unreviewed/2023/06/GHSA-qhm9-gg74-g6m6/GHSA-qhm9-gg74-g6m6.json index 3ee991eaf5a..57f574ed3c0 100644 --- a/advisories/unreviewed/2023/06/GHSA-qhm9-gg74-g6m6/GHSA-qhm9-gg74-g6m6.json +++ b/advisories/unreviewed/2023/06/GHSA-qhm9-gg74-g6m6/GHSA-qhm9-gg74-g6m6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qhm9-gg74-g6m6", - "modified": "2023-07-06T15:30:32Z", + "modified": "2024-03-06T03:30:28Z", "published": "2023-06-28T18:30:27Z", "aliases": [ "CVE-2023-21237" @@ -30,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-06-28T18:15:16Z" diff --git a/advisories/unreviewed/2024/02/GHSA-5p54-7x9q-259p/GHSA-5p54-7x9q-259p.json b/advisories/unreviewed/2024/02/GHSA-5p54-7x9q-259p/GHSA-5p54-7x9q-259p.json index d32e893f0ba..0819de2536f 100644 --- a/advisories/unreviewed/2024/02/GHSA-5p54-7x9q-259p/GHSA-5p54-7x9q-259p.json +++ b/advisories/unreviewed/2024/02/GHSA-5p54-7x9q-259p/GHSA-5p54-7x9q-259p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5p54-7x9q-259p", - "modified": "2024-03-03T03:30:23Z", + "modified": "2024-03-06T03:30:29Z", "published": "2024-02-29T03:33:17Z", "aliases": [ "CVE-2024-1938" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://issues.chromium.org/issues/324596281" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FGWSP5MIK7CDWJQHN2SJJX2YGSSS7E4O" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L6KJCEJWJR5Z54Z75LRJGELDNMFDKLZG" diff --git a/advisories/unreviewed/2024/02/GHSA-7f39-34rh-fghp/GHSA-7f39-34rh-fghp.json b/advisories/unreviewed/2024/02/GHSA-7f39-34rh-fghp/GHSA-7f39-34rh-fghp.json index 779ba8e4eaf..5fc3a70359b 100644 --- a/advisories/unreviewed/2024/02/GHSA-7f39-34rh-fghp/GHSA-7f39-34rh-fghp.json +++ b/advisories/unreviewed/2024/02/GHSA-7f39-34rh-fghp/GHSA-7f39-34rh-fghp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7f39-34rh-fghp", - "modified": "2024-03-03T03:30:23Z", + "modified": "2024-03-06T03:30:29Z", "published": "2024-02-29T03:33:17Z", "aliases": [ "CVE-2024-1939" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://issues.chromium.org/issues/323694592" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FGWSP5MIK7CDWJQHN2SJJX2YGSSS7E4O" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L6KJCEJWJR5Z54Z75LRJGELDNMFDKLZG" diff --git a/advisories/unreviewed/2024/03/GHSA-2m9w-4gr5-v6pv/GHSA-2m9w-4gr5-v6pv.json b/advisories/unreviewed/2024/03/GHSA-2m9w-4gr5-v6pv/GHSA-2m9w-4gr5-v6pv.json new file mode 100644 index 00000000000..5dc2228e2b2 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-2m9w-4gr5-v6pv/GHSA-2m9w-4gr5-v6pv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2m9w-4gr5-v6pv", + "modified": "2024-03-06T03:30:29Z", + "published": "2024-03-06T03:30:29Z", + "aliases": [ + "CVE-2023-49977" + ], + "details": "A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the address parameter at /customer_support/index.php?page=new_customer.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49977" + }, + { + "type": "WEB", + "url": "https://github.com/geraldoalcantara/CVE-2023-49977" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com/php/14587/customer-support-system-using-phpmysqli-source-code.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-06T01:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-832m-mwp6-jcr3/GHSA-832m-mwp6-jcr3.json b/advisories/unreviewed/2024/03/GHSA-832m-mwp6-jcr3/GHSA-832m-mwp6-jcr3.json new file mode 100644 index 00000000000..54c5e83e821 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-832m-mwp6-jcr3/GHSA-832m-mwp6-jcr3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-832m-mwp6-jcr3", + "modified": "2024-03-06T03:30:29Z", + "published": "2024-03-06T03:30:29Z", + "aliases": [ + "CVE-2023-49974" + ], + "details": "A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the contact parameter at /customer_support/index.php?page=customer_list.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49974" + }, + { + "type": "WEB", + "url": "https://github.com/geraldoalcantara/CVE-2023-49974" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com/php/14587/customer-support-system-using-phpmysqli-source-code.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-06T01:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-gq76-mjm5-q3g9/GHSA-gq76-mjm5-q3g9.json b/advisories/unreviewed/2024/03/GHSA-gq76-mjm5-q3g9/GHSA-gq76-mjm5-q3g9.json new file mode 100644 index 00000000000..48ed0b314ee --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-gq76-mjm5-q3g9/GHSA-gq76-mjm5-q3g9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq76-mjm5-q3g9", + "modified": "2024-03-06T03:30:29Z", + "published": "2024-03-06T03:30:29Z", + "aliases": [ + "CVE-2023-33677" + ], + "details": "Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at \"?page=items/view&id=*\".", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33677" + }, + { + "type": "WEB", + "url": "https://github.com/ASR511-OO7/CVE-2023-33677/blob/main/CVE-29" + }, + { + "type": "WEB", + "url": "http://wwwsourcecodestercom.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-06T01:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-gwm5-cvp5-fmgc/GHSA-gwm5-cvp5-fmgc.json b/advisories/unreviewed/2024/03/GHSA-gwm5-cvp5-fmgc/GHSA-gwm5-cvp5-fmgc.json new file mode 100644 index 00000000000..c2bbfb5d15a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-gwm5-cvp5-fmgc/GHSA-gwm5-cvp5-fmgc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwm5-cvp5-fmgc", + "modified": "2024-03-06T03:30:29Z", + "published": "2024-03-06T03:30:29Z", + "aliases": [ + "CVE-2023-49973" + ], + "details": "A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter at /customer_support/index.php?page=customer_list.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49973" + }, + { + "type": "WEB", + "url": "https://github.com/geraldoalcantara/CVE-2023-49973" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com/php/14587/customer-support-system-using-phpmysqli-source-code.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-06T01:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-h7pr-3fcx-999q/GHSA-h7pr-3fcx-999q.json b/advisories/unreviewed/2024/03/GHSA-h7pr-3fcx-999q/GHSA-h7pr-3fcx-999q.json new file mode 100644 index 00000000000..22d04e52151 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-h7pr-3fcx-999q/GHSA-h7pr-3fcx-999q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7pr-3fcx-999q", + "modified": "2024-03-06T03:30:29Z", + "published": "2024-03-06T03:30:29Z", + "aliases": [ + "CVE-2024-1220" + ], + "details": "A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and prior allows a remote attacker to exploit the vulnerability by sending crafted payload to the web service. Successful exploitation of the vulnerability could result in denial of service.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1220" + }, + { + "type": "WEB", + "url": "https://www.moxa.com/en/support/product-support/security-advisory/mpsa-238975-nport-w2150a-w2250a-series-web-server-stack-based-buffer-overflow-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-06T02:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p98c-qx6j-cgvx/GHSA-p98c-qx6j-cgvx.json b/advisories/unreviewed/2024/03/GHSA-p98c-qx6j-cgvx/GHSA-p98c-qx6j-cgvx.json new file mode 100644 index 00000000000..8723b26ddcb --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p98c-qx6j-cgvx/GHSA-p98c-qx6j-cgvx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p98c-qx6j-cgvx", + "modified": "2024-03-06T03:30:29Z", + "published": "2024-03-06T03:30:29Z", + "aliases": [ + "CVE-2023-49976" + ], + "details": "A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the subject parameter at /customer_support/index.php?page=new_ticket.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49976" + }, + { + "type": "WEB", + "url": "https://github.com/geraldoalcantara/CVE-2023-49976" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com/php/14587/customer-support-system-using-phpmysqli-source-code.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-06T01:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rxm4-85x6-2778/GHSA-rxm4-85x6-2778.json b/advisories/unreviewed/2024/03/GHSA-rxm4-85x6-2778/GHSA-rxm4-85x6-2778.json new file mode 100644 index 00000000000..a064abbaebc --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rxm4-85x6-2778/GHSA-rxm4-85x6-2778.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxm4-85x6-2778", + "modified": "2024-03-06T03:30:29Z", + "published": "2024-03-06T03:30:29Z", + "aliases": [ + "CVE-2023-49971" + ], + "details": "A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter at /customer_support/index.php?page=customer_list.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49971" + }, + { + "type": "WEB", + "url": "https://github.com/geraldoalcantara/CVE-2023-49971" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com/php/14587/customer-support-system-using-phpmysqli-source-code.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-06T01:15:07Z" + } +} \ No newline at end of file