Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2023-12-18 21:31:34 +00:00
parent 88af5b7f74
commit 8b9c19db74
58 changed files with 783 additions and 77 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2255-f3p6-4fv3",
"modified": "2023-12-14T00:30:26Z",
"modified": "2023-12-18T21:30:22Z",
"published": "2023-12-14T00:30:26Z",
"aliases": [
"CVE-2023-41621"
],
"details": "A Cross Site Scripting (XSS) vulnerability was discovered in Emlog Pro v2.1.14 via the component /admin/store.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-13T23:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-24r5-xw2j-9h9x",
"modified": "2023-12-14T09:30:19Z",
"modified": "2023-12-18T21:30:23Z",
"published": "2023-12-14T09:30:19Z",
"aliases": [
"CVE-2023-40628"
],
"details": "A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-14T09:15:41Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2m47-7r27-xh85",
"modified": "2023-12-14T09:30:19Z",
"modified": "2023-12-18T21:30:23Z",
"published": "2023-12-14T09:30:19Z",
"aliases": [
"CVE-2023-25644"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2q88-68x3-v4pp",
"modified": "2023-12-18T21:30:28Z",
"published": "2023-12-18T21:30:28Z",
"aliases": [
"CVE-2023-6203"
],
"details": "The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6203"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/229273e6-e849-447f-a95a-0730969ecdae"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-18T20:15:08Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-44xq-r8h3-q4q6",
"modified": "2023-12-18T21:30:26Z",
"published": "2023-12-18T21:30:26Z",
"aliases": [
"CVE-2023-51384"
],
"details": "In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51384"
},
{
"type": "WEB",
"url": "https://www.openssh.com/txt/release-9.6"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2023/12/18/2"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-18T19:15:08Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4c5v-86xf-p6j6",
"modified": "2023-12-18T21:30:27Z",
"published": "2023-12-18T21:30:27Z",
"aliases": [
"CVE-2023-47741"
],
"details": "\nIBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using common browser tools before the memory is garbage collected. A malicious actor with access to the victim's PC could exploit this vulnerability to gain access to the IBM i operating system. IBM X-Force ID: 272532.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47741"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7097785"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7097801"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-18T20:15:08Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4ppj-757r-h8qc",
"modified": "2023-12-14T03:30:53Z",
"modified": "2023-12-18T21:30:22Z",
"published": "2023-12-14T03:30:53Z",
"aliases": [
"CVE-2023-31546"
],
"details": "Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-14T01:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-52q9-9jfh-88p5",
"modified": "2023-12-14T00:30:26Z",
"modified": "2023-12-18T21:30:22Z",
"published": "2023-12-14T00:30:26Z",
"aliases": [
"CVE-2023-40921"
],
"details": "SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to obtain sensitive information via the lat and lng parameters.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-14T00:15:43Z"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5mq4-x9g5-4vc4",
"modified": "2023-12-18T21:30:27Z",
"published": "2023-12-18T21:30:27Z",
"aliases": [
"CVE-2023-51385"
],
"details": "In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51385"
},
{
"type": "WEB",
"url": "https://www.openssh.com/txt/release-9.6"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2023/12/18/2"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-18T19:15:08Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-65mr-mxqp-9fgc",
"modified": "2023-12-14T18:30:20Z",
"modified": "2023-12-18T21:30:24Z",
"published": "2023-12-14T18:30:20Z",
"aliases": [
"CVE-2023-49172"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-67qp-jc76-wwrg",
"modified": "2023-12-12T21:31:12Z",
"modified": "2023-12-18T21:30:21Z",
"published": "2023-12-12T21:31:12Z",
"aliases": [
"CVE-2023-34064"
],
"details": "Workspace ONE Launcher contains a Privilege Escalation Vulnerability. A malicious actor with physical access to Workspace ONE Launcher could utilize the Edge Panel feature to bypass setup to gain access to sensitive information.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-12T20:15:06Z"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-73xg-5xg9-crjv",
"modified": "2023-12-18T21:30:27Z",
"published": "2023-12-18T21:30:27Z",
"aliases": [
"CVE-2023-6077"
],
"details": "The Slider WordPress plugin before 3.5.12 does not ensure that posts to be accessed via an AJAX action are slides and can be viewed by the user making the request, allowing any authenticated users, such as subscriber to access the content arbitrary post such as private, draft and password protected",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6077"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/1afc0e4a-f712-47d4-bf29-7719ccbbbb1b"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-18T20:15:08Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-77gw-gm6r-6m2p",
"modified": "2023-12-15T12:30:29Z",
"modified": "2023-12-18T21:30:26Z",
"published": "2023-12-15T12:30:29Z",
"aliases": [
"CVE-2023-48530"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7cr4-32jg-hwx2",
"modified": "2023-12-18T21:30:27Z",
"published": "2023-12-18T21:30:27Z",
"aliases": [
"CVE-2023-5005"
],
"details": "The Autocomplete Location field Contact Form 7 WordPress plugin before 3.0, autocomplete-location-field-contact-form-7-pro WordPress plugin before 2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5005"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/bfb174d4-7658-4883-a682-d06bda89ec44"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-18T20:15:08Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7j57-9v54-xwjr",
"modified": "2023-12-14T09:30:19Z",
"modified": "2023-12-18T21:30:23Z",
"published": "2023-12-14T09:30:19Z",
"aliases": [
"CVE-2023-48925"
],
"details": "SQL injection vulnerability in Buy Addons bavideotab before version 1.0.6, allows attackers to escalate privileges and obtain sensitive information via the component BaVideoTabSaveVideoModuleFrontController::run().",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-14T09:15:42Z"
@@ -40,7 +40,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-276"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7x7j-52gx-4h55",
"modified": "2023-12-18T21:30:27Z",
"published": "2023-12-18T21:30:27Z",
"aliases": [
"CVE-2023-4311"
],
"details": "The Vrm 360 3D Model Viewer WordPress plugin through 1.2.1 is vulnerable to arbitrary file upload due to insufficient checks in a plugin shortcode.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4311"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/21950116-1a69-4848-9da0-e912096c0fce"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-18T20:15:08Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7xp2-7hw7-rv8q",
"modified": "2023-12-18T21:30:27Z",
"published": "2023-12-18T21:30:27Z",
"aliases": [
"CVE-2023-5882"
],
"details": "The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers to make logged in users perform unwanted actions leading to remote code execution.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5882"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/72be4b5c-21be-46af-a3f4-08b4c190a7e2"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-18T20:15:08Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8f5w-6f56-pffq",
"modified": "2023-12-14T15:30:22Z",
"modified": "2023-12-18T21:30:23Z",
"published": "2023-12-14T15:30:22Z",
"aliases": [
"CVE-2023-50369"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8r5w-j8rm-886w",
"modified": "2023-12-13T21:30:31Z",
"modified": "2023-12-18T21:30:22Z",
"published": "2023-12-13T21:30:31Z",
"aliases": [
"CVE-2023-6790"

Some files were not shown because too many files have changed in this diff Show More