diff --git a/advisories/unreviewed/2024/06/GHSA-p7rq-f88g-ghwx/GHSA-p7rq-f88g-ghwx.json b/advisories/unreviewed/2024/06/GHSA-p7rq-f88g-ghwx/GHSA-p7rq-f88g-ghwx.json index ceb6cbe5383..0205f63407b 100644 --- a/advisories/unreviewed/2024/06/GHSA-p7rq-f88g-ghwx/GHSA-p7rq-f88g-ghwx.json +++ b/advisories/unreviewed/2024/06/GHSA-p7rq-f88g-ghwx/GHSA-p7rq-f88g-ghwx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p7rq-f88g-ghwx", - "modified": "2024-06-06T21:30:37Z", + "modified": "2024-11-03T18:30:30Z", "published": "2024-06-06T21:30:37Z", "aliases": [ "CVE-2024-5248" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5248" }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/7f24ec1c3588992a07fd70573c43a0897eb523a2" + }, { "type": "WEB", "url": "https://huntr.com/bounties/4ec75087-5630-4813-952b-88ccabe6d117" diff --git a/advisories/unreviewed/2024/11/GHSA-98w9-g388-4g49/GHSA-98w9-g388-4g49.json b/advisories/unreviewed/2024/11/GHSA-98w9-g388-4g49/GHSA-98w9-g388-4g49.json new file mode 100644 index 00000000000..349634a673e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-98w9-g388-4g49/GHSA-98w9-g388-4g49.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98w9-g388-4g49", + "modified": "2024-11-03T18:30:30Z", + "published": "2024-11-03T18:30:30Z", + "aliases": [ + "CVE-2024-10738" + ], + "details": "A vulnerability classified as critical was found in itsourcecode Farm Management System 1.0. Affected by this vulnerability is an unknown functionality of the file manage-breed.php. The manipulation of the argument breed leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10738" + }, + { + "type": "WEB", + "url": "https://github.com/Nightmaremassacre/cve/issues/3" + }, + { + "type": "WEB", + "url": "https://itsourcecode.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282907" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282907" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.435539" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-03T17:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mmvw-c88f-x2wm/GHSA-mmvw-c88f-x2wm.json b/advisories/unreviewed/2024/11/GHSA-mmvw-c88f-x2wm/GHSA-mmvw-c88f-x2wm.json new file mode 100644 index 00000000000..7acbf129299 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mmvw-c88f-x2wm/GHSA-mmvw-c88f-x2wm.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmvw-c88f-x2wm", + "modified": "2024-11-03T18:30:30Z", + "published": "2024-11-03T18:30:30Z", + "aliases": [ + "CVE-2024-10739" + ], + "details": "A vulnerability, which was classified as critical, has been found in code-projects E-Health Care System 1.0. Affected by this issue is some unknown functionality of the file /Admin/adminlogin.php. The manipulation of the argument email/admin_pswd as part of String leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter \"email\" to be affected. But it must be assumed that parameter \"admin_pswd\" is affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10739" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/UnrealdDei/cve/blob/main/sql11.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.282908" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.282908" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.436014" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-03T18:15:02Z" + } +} \ No newline at end of file