diff --git a/advisories/github-reviewed/2024/05/GHSA-x7g6-rwhc-g7mj/GHSA-x7g6-rwhc-g7mj.json b/advisories/github-reviewed/2024/05/GHSA-x7g6-rwhc-g7mj/GHSA-x7g6-rwhc-g7mj.json index 61d0a6796a3..4e4bdf815c4 100644 --- a/advisories/github-reviewed/2024/05/GHSA-x7g6-rwhc-g7mj/GHSA-x7g6-rwhc-g7mj.json +++ b/advisories/github-reviewed/2024/05/GHSA-x7g6-rwhc-g7mj/GHSA-x7g6-rwhc-g7mj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x7g6-rwhc-g7mj", - "modified": "2024-05-03T20:11:59Z", + "modified": "2024-10-15T03:30:42Z", "published": "2024-05-02T15:30:35Z", "aliases": [ "CVE-2024-4029" @@ -40,6 +40,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4029" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8075" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8076" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8077" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:8080" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-4029" diff --git a/advisories/unreviewed/2024/10/GHSA-3hwm-xx77-96rq/GHSA-3hwm-xx77-96rq.json b/advisories/unreviewed/2024/10/GHSA-3hwm-xx77-96rq/GHSA-3hwm-xx77-96rq.json new file mode 100644 index 00000000000..4c568d39d80 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3hwm-xx77-96rq/GHSA-3hwm-xx77-96rq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hwm-xx77-96rq", + "modified": "2024-10-15T03:30:42Z", + "published": "2024-10-15T03:30:42Z", + "aliases": [ + "CVE-2024-6757" + ], + "details": "The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract either excerpt data or titles of private or password-protected posts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6757" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/elementor/tags/3.23.0/includes/controls/media.php#L413" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/96fa9ed7-6c13-4356-8a25-8a309be2b0e9?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T02:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jvhc-5rmh-2pc8/GHSA-jvhc-5rmh-2pc8.json b/advisories/unreviewed/2024/10/GHSA-jvhc-5rmh-2pc8/GHSA-jvhc-5rmh-2pc8.json new file mode 100644 index 00000000000..5611085e09d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jvhc-5rmh-2pc8/GHSA-jvhc-5rmh-2pc8.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvhc-5rmh-2pc8", + "modified": "2024-10-15T03:30:42Z", + "published": "2024-10-15T03:30:42Z", + "aliases": [ + "CVE-2024-9952" + ], + "details": "A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/?page=system_info/contact_info of the component Contact Information Page. The manipulation of the argument Address leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9952" + }, + { + "type": "WEB", + "url": "https://gist.github.com/higordiego/bedd395e74a335f0145872c96d7cb92d" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.280319" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.280319" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.423229" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T02:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q47f-prmv-x9hp/GHSA-q47f-prmv-x9hp.json b/advisories/unreviewed/2024/10/GHSA-q47f-prmv-x9hp/GHSA-q47f-prmv-x9hp.json new file mode 100644 index 00000000000..8c6576da42e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q47f-prmv-x9hp/GHSA-q47f-prmv-x9hp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q47f-prmv-x9hp", + "modified": "2024-10-15T03:30:42Z", + "published": "2024-10-15T03:30:42Z", + "aliases": [ + "CVE-2024-9968" + ], + "details": "WebEIP v3.0 from \n\nNewType does not properly validate user input, allowing remote attackers with regular privilege to inject SQL commands to read, modify, and delete data stored in database. The affected product is no longer maintained. It is recommended to upgrade to the new product.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9968" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-8133-2cc3a-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-8132-160bb-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T03:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rfxp-9x8m-jfw8/GHSA-rfxp-9x8m-jfw8.json b/advisories/unreviewed/2024/10/GHSA-rfxp-9x8m-jfw8/GHSA-rfxp-9x8m-jfw8.json new file mode 100644 index 00000000000..e5a0aa54d11 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rfxp-9x8m-jfw8/GHSA-rfxp-9x8m-jfw8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfxp-9x8m-jfw8", + "modified": "2024-10-15T03:30:42Z", + "published": "2024-10-15T03:30:42Z", + "aliases": [ + "CVE-2024-9687" + ], + "details": "The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0. This is due to insufficient validation of the user-controlled key on the 'validate_tg' action. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to log in as any existing user on the site, such as an administrator.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9687" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/two-factor-login-telegram/tags/3.0/includes/class-wp-factor-telegram-plugin.php#L244" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/13b5292f-4484-498b-b6b7-2895871ab794?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T02:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-x23h-whff-jxq7/GHSA-x23h-whff-jxq7.json b/advisories/unreviewed/2024/10/GHSA-x23h-whff-jxq7/GHSA-x23h-whff-jxq7.json new file mode 100644 index 00000000000..3474bf72010 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-x23h-whff-jxq7/GHSA-x23h-whff-jxq7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x23h-whff-jxq7", + "modified": "2024-10-15T03:30:42Z", + "published": "2024-10-15T03:30:42Z", + "aliases": [ + "CVE-2024-9820" + ], + "details": "The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, which makes it possible to bypass two-factor authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9820" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/two-factor-login-telegram/tags/3.0/includes/class-wp-factor-telegram-plugin.php#L228" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ccd73030-7185-4302-b3fd-29cbbe716e3e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-784" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T02:15:03Z" + } +} \ No newline at end of file