diff --git a/advisories/unreviewed/2023/03/GHSA-58jw-58x8-342p/GHSA-58jw-58x8-342p.json b/advisories/unreviewed/2023/03/GHSA-58jw-58x8-342p/GHSA-58jw-58x8-342p.json index c70496b8506..f2b4f85a4cb 100644 --- a/advisories/unreviewed/2023/03/GHSA-58jw-58x8-342p/GHSA-58jw-58x8-342p.json +++ b/advisories/unreviewed/2023/03/GHSA-58jw-58x8-342p/GHSA-58jw-58x8-342p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-58jw-58x8-342p", - "modified": "2023-03-16T18:30:31Z", + "modified": "2024-03-25T06:30:23Z", "published": "2023-03-10T21:30:22Z", "aliases": [ "CVE-2022-40540" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40540" }, + { + "type": "WEB", + "url": "https://bugzilla.suse.com/show_bug.cgi?id=1209597" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230616-0001" diff --git a/advisories/unreviewed/2024/03/GHSA-37x3-hqf8-5w7p/GHSA-37x3-hqf8-5w7p.json b/advisories/unreviewed/2024/03/GHSA-37x3-hqf8-5w7p/GHSA-37x3-hqf8-5w7p.json new file mode 100644 index 00000000000..659b802e9b8 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-37x3-hqf8-5w7p/GHSA-37x3-hqf8-5w7p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37x3-hqf8-5w7p", + "modified": "2024-03-25T06:30:24Z", + "published": "2024-03-25T06:30:24Z", + "aliases": [ + "CVE-2024-1232" + ], + "details": "The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete downloads via a CSRF attack", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1232" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/2a29b509-4cd5-43c8-84f4-f86251dd28f8" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-3wjc-g785-xjp8/GHSA-3wjc-g785-xjp8.json b/advisories/unreviewed/2024/03/GHSA-3wjc-g785-xjp8/GHSA-3wjc-g785-xjp8.json new file mode 100644 index 00000000000..f7977d3c1dd --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3wjc-g785-xjp8/GHSA-3wjc-g785-xjp8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wjc-g785-xjp8", + "modified": "2024-03-25T06:30:24Z", + "published": "2024-03-25T06:30:24Z", + "aliases": [ + "CVE-2023-37885" + ], + "details": "Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37885" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/realhomes/wordpress-realhomes-theme-4-0-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-6fc3-8g79-3f39/GHSA-6fc3-8g79-3f39.json b/advisories/unreviewed/2024/03/GHSA-6fc3-8g79-3f39/GHSA-6fc3-8g79-3f39.json new file mode 100644 index 00000000000..cd31a16a4a6 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-6fc3-8g79-3f39/GHSA-6fc3-8g79-3f39.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fc3-8g79-3f39", + "modified": "2024-03-25T06:30:24Z", + "published": "2024-03-25T06:30:24Z", + "aliases": [ + "CVE-2024-1962" + ], + "details": "The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins edit downloads via a CSRF attack", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1962" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/469486d4-7677-4d66-83c0-a6b9ac7c503b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-87qp-7cw8-8q9c/GHSA-87qp-7cw8-8q9c.json b/advisories/unreviewed/2024/03/GHSA-87qp-7cw8-8q9c/GHSA-87qp-7cw8-8q9c.json new file mode 100644 index 00000000000..dc07d00b45c --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-87qp-7cw8-8q9c/GHSA-87qp-7cw8-8q9c.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87qp-7cw8-8q9c", + "modified": "2024-03-25T06:30:24Z", + "published": "2024-03-25T06:30:24Z", + "aliases": [ + "CVE-2024-21505" + ], + "details": "Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge.\nAn attacker can manipulate an object's prototype, potentially leading to the alteration of the behavior of all objects inheriting from the affected prototype by passing specially crafted input to these functions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21505" + }, + { + "type": "WEB", + "url": "https://github.com/web3/web3.js/commit/8ed041c6635d807b3da8960ad49e125e3d1b0e80" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-JS-WEB3UTILS-6229337" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-8jm2-4r4f-748v/GHSA-8jm2-4r4f-748v.json b/advisories/unreviewed/2024/03/GHSA-8jm2-4r4f-748v/GHSA-8jm2-4r4f-748v.json new file mode 100644 index 00000000000..7346e4c7235 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-8jm2-4r4f-748v/GHSA-8jm2-4r4f-748v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jm2-4r4f-748v", + "modified": "2024-03-25T06:30:23Z", + "published": "2024-03-25T06:30:23Z", + "aliases": [ + "CVE-2024-29071" + ], + "details": "HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change the system settings.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29071" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93546510" + }, + { + "type": "WEB", + "url": "https://www.au.com/support/service/internet/guide/modem/bl1500hm/firmware" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T04:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-m653-rf8h-79j3/GHSA-m653-rf8h-79j3.json b/advisories/unreviewed/2024/03/GHSA-m653-rf8h-79j3/GHSA-m653-rf8h-79j3.json new file mode 100644 index 00000000000..d8f6089a4ce --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-m653-rf8h-79j3/GHSA-m653-rf8h-79j3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m653-rf8h-79j3", + "modified": "2024-03-25T06:30:24Z", + "published": "2024-03-25T06:30:24Z", + "aliases": [ + "CVE-2024-29009" + ], + "details": "Cross-site request forgery (CSRF) vulnerability in easy-popup-show all versions allows a remote unauthenticated attacker to hijack the authentication of the administrator and to perform unintended operations if the administrator views a malicious page while logged in.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29009" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN86206017" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/easy-popup-show" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-p8fm-626m-mf8v/GHSA-p8fm-626m-mf8v.json b/advisories/unreviewed/2024/03/GHSA-p8fm-626m-mf8v/GHSA-p8fm-626m-mf8v.json new file mode 100644 index 00000000000..4edf33147ae --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-p8fm-626m-mf8v/GHSA-p8fm-626m-mf8v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8fm-626m-mf8v", + "modified": "2024-03-25T06:30:24Z", + "published": "2024-03-25T06:30:24Z", + "aliases": [ + "CVE-2024-1564" + ], + "details": "The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access custom fields on any post regardless of post type or status via a shortcode", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1564" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/ecb1e36f-9c6e-4754-8878-03c97194644d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-q7m5-4xhc-7xfr/GHSA-q7m5-4xhc-7xfr.json b/advisories/unreviewed/2024/03/GHSA-q7m5-4xhc-7xfr/GHSA-q7m5-4xhc-7xfr.json new file mode 100644 index 00000000000..d84f9bf28c6 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-q7m5-4xhc-7xfr/GHSA-q7m5-4xhc-7xfr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7m5-4xhc-7xfr", + "modified": "2024-03-25T06:30:24Z", + "published": "2024-03-25T06:30:24Z", + "aliases": [ + "CVE-2024-21865" + ], + "details": "HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may connect to the product via SSH and use a shell.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21865" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93546510" + }, + { + "type": "WEB", + "url": "https://www.au.com/support/service/internet/guide/modem/bl1500hm/firmware" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qjrx-78jp-x72f/GHSA-qjrx-78jp-x72f.json b/advisories/unreviewed/2024/03/GHSA-qjrx-78jp-x72f/GHSA-qjrx-78jp-x72f.json new file mode 100644 index 00000000000..f209c5d43b2 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qjrx-78jp-x72f/GHSA-qjrx-78jp-x72f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjrx-78jp-x72f", + "modified": "2024-03-25T06:30:23Z", + "published": "2024-03-25T06:30:23Z", + "aliases": [ + "CVE-2024-28041" + ], + "details": "HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28041" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/vu/JVNVU93546510" + }, + { + "type": "WEB", + "url": "https://www.au.com/support/service/internet/guide/modem/bl1500hm/firmware" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T04:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rqhc-7mvg-jchq/GHSA-rqhc-7mvg-jchq.json b/advisories/unreviewed/2024/03/GHSA-rqhc-7mvg-jchq/GHSA-rqhc-7mvg-jchq.json new file mode 100644 index 00000000000..d56198904eb --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rqhc-7mvg-jchq/GHSA-rqhc-7mvg-jchq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqhc-7mvg-jchq", + "modified": "2024-03-25T06:30:24Z", + "published": "2024-03-25T06:30:24Z", + "aliases": [ + "CVE-2023-37886" + ], + "details": "Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37886" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/realhomes/wordpress-realhomes-theme-4-0-2-broken-access-control-vulnerability-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rx84-4w3q-488h/GHSA-rx84-4w3q-488h.json b/advisories/unreviewed/2024/03/GHSA-rx84-4w3q-488h/GHSA-rx84-4w3q-488h.json new file mode 100644 index 00000000000..3cc0cf26b87 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rx84-4w3q-488h/GHSA-rx84-4w3q-488h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx84-4w3q-488h", + "modified": "2024-03-25T06:30:24Z", + "published": "2024-03-25T06:30:24Z", + "aliases": [ + "CVE-2022-36407" + ], + "details": "Insertion of Sensitive Information into Log File vulnerability in Hitachi Virtual Storage Platform, Hitachi Virtual Storage Platform VP9500, Hitachi Virtual Storage Platform G1000, G1500, Hitachi Virtual Storage Platform F1500, Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H, Hitachi Virtual Storage Platform 5200, 5600, 5200H, 5600H, Hitachi Unified Storage VM, Hitachi Virtual Storage Platform G100, G200, G400, G600, G800, Hitachi Virtual Storage Platform F400, F600, F800, Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, Hitachi Virtual Storage Platform F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H allows \n\nlocal users to gain sensitive information.This issue affects Hitachi Virtual Storage Platform: before DKCMAIN Ver. 70-06-74-00/00, SVP Ver. 70-06-58/00; Hitachi Virtual Storage Platform VP9500: before DKCMAIN Ver. 70-06-74-00/00, SVP Ver. 70-06-58/00; Hitachi Virtual Storage Platform G1000, G1500: before DKCMAIN Ver. 80-06-92-00/00, SVP Ver. 80-06-87/00; Hitachi Virtual Storage Platform F1500: before DKCMAIN Ver. 80-06-92-00/00, SVP Ver. 80-06-87/00; Hitachi Virtual Storage Platform 5100, 5500,5100H, 5500H: before DKCMAIN Ver. 90-08-81-00/00, SVP Ver. 90-08-81/00, before DKCMAIN Ver. 90-08-62-00/00, SVP Ver. 90-08-62/00, before DKCMAIN Ver. 90-08-43-00/00, SVP Ver. 90-08-43/00; Hitachi Virtual Storage Platform 5200, 5600,5200H, 5600H: before DKCMAIN Ver. 90-08-81-00/00, SVP Ver. 90-08-81/00, before DKCMAIN Ver. 90-08-62-00/00, SVP Ver. 90-08-62/00, before DKCMAIN Ver. 90-08-43-00/00, SVP Ver. 90-08-43/00; Hitachi Unified Storage VM: before DKCMAIN Ver. 73-03-75-X0/00, SVP Ver. 73-03-74/00, before DKCMAIN Ver. 73(75)-03-75-X0/00, SVP Ver. 73(75)-03-74/00; Hitachi Virtual Storage Platform G100, G200, G400, G600, G800: before DKCMAIN Ver. 83-06-19-X0/00, SVP Ver. 83-06-20-X0/00, before DKCMAIN Ver. 83-05-47-X0/00, SVP Ver. 83-05-51-X0/00; Hitachi Virtual Storage Platform F400, F600, F800: before DKCMAIN Ver. 83-06-19-X0/00, SVP Ver. 83-06-20-X0/00, before DKCMAIN Ver. 83-05-47-X0/00, SVP Ver. 83-05-51-X0/00; Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900: before DKCMAIN Ver. 88-08-09-XX/00, SVP Ver. 88-08-11-X0/02; Hitachi Virtual Storage Platform F350, F370, F700, F900: before DKCMAIN Ver. 88-08-09-XX/00, SVP Ver. 88-08-11-X0/02; Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-06-81-X0/00, SVP Ver. 93-06-81-X0/00, before DKCMAIN Ver. 93-06-62-X0/00, SVP Ver. 93-06-62-X0/00, before DKCMAIN Ver. 93-06-43-X0/00, SVP Ver. 93-06-43-X0/00.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36407" + }, + { + "type": "WEB", + "url": "https://www.hitachi.com/products/it/storage-solutions/sec_info/2024/2022_313.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T06:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-w97v-hmpc-3m55/GHSA-w97v-hmpc-3m55.json b/advisories/unreviewed/2024/03/GHSA-w97v-hmpc-3m55/GHSA-w97v-hmpc-3m55.json new file mode 100644 index 00000000000..aec527029e6 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-w97v-hmpc-3m55/GHSA-w97v-hmpc-3m55.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w97v-hmpc-3m55", + "modified": "2024-03-25T06:30:23Z", + "published": "2024-03-25T06:30:23Z", + "aliases": [ + "CVE-2023-30480" + ], + "details": "Missing Authorization vulnerability in Sparkle WP Educenter.This issue affects Educenter: from n/a through 1.5.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30480" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/educenter/wordpress-educenter-theme-1-5-1-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T05:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-wvw8-hcw4-jwqp/GHSA-wvw8-hcw4-jwqp.json b/advisories/unreviewed/2024/03/GHSA-wvw8-hcw4-jwqp/GHSA-wvw8-hcw4-jwqp.json new file mode 100644 index 00000000000..1bd07bd1504 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-wvw8-hcw4-jwqp/GHSA-wvw8-hcw4-jwqp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvw8-hcw4-jwqp", + "modified": "2024-03-25T06:30:24Z", + "published": "2024-03-25T06:30:24Z", + "aliases": [ + "CVE-2024-1231" + ], + "details": "The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins unpublish downloads via a CSRF attack", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1231" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/7d3968d9-61ed-4c00-8764-0360cf03255e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T05:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-x3j5-x3h2-frf6/GHSA-x3j5-x3h2-frf6.json b/advisories/unreviewed/2024/03/GHSA-x3j5-x3h2-frf6/GHSA-x3j5-x3h2-frf6.json new file mode 100644 index 00000000000..f4c46e6788b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-x3j5-x3h2-frf6/GHSA-x3j5-x3h2-frf6.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3j5-x3h2-frf6", + "modified": "2024-03-25T06:30:24Z", + "published": "2024-03-25T06:30:24Z", + "aliases": [ + "CVE-2023-33923" + ], + "details": "Missing Authorization vulnerability in HashThemes Viral News, HashThemes Viral, HashThemes HashOne.This issue affects Viral News: from n/a through 1.4.5; Viral: from n/a through 1.8.0; HashOne: from n/a through 1.3.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33923" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/hashone/wordpress-hashone-theme-1-3-0-broken-access-control-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/viral-news/wordpress-viral-news-theme-1-4-5-authenticated-arbitrary-plugin-activation-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/viral/wordpress-viral-theme-1-8-0-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T05:15:49Z" + } +} \ No newline at end of file