Publish Advisories

GHSA-4qf6-pw5g-fjgf
GHSA-8p42-7597-p2f6
GHSA-jq6r-qxvf-4wrv
GHSA-pw3q-4wqj-24pp
This commit is contained in:
advisory-database[bot]
2024-04-27 09:31:55 +00:00
parent bee0ba8a67
commit 903ea3751d
4 changed files with 196 additions and 0 deletions
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4qf6-pw5g-fjgf",
"modified": "2024-04-27T09:30:33Z",
"published": "2024-04-27T09:30:33Z",
"aliases": [
"CVE-2024-4245"
],
"details": "A vulnerability, which was classified as critical, has been found in Tenda i21 1.0.0.14(4656). Affected by this issue is the function formQosManageDouble_user. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack may be launched remotely. The identifier of this vulnerability is VDB-262136. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4245"
},
{
"type": "WEB",
"url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/i/i21/formQosManageDouble_auto.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.262136"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.262136"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.319830"
}
],
"database_specific": {
"cwe_ids": [
"CWE-121"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-27T08:15:06Z"
}
}
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8p42-7597-p2f6",
"modified": "2024-04-27T09:30:33Z",
"published": "2024-04-27T09:30:33Z",
"aliases": [
"CVE-2023-1000"
],
"details": "A vulnerability was found in cyanomiko dcnnt-py up to 0.9.0. It has been classified as critical. Affected is the function main of the file dcnnt/plugins/notifications.py of the component Notification Handler. The manipulation leads to command injection. It is possible to launch the attack remotely. Upgrading to version 0.9.1 is able to address this issue. The patch is identified as b4021d784a97e25151a5353aa763a741e9a148f5. It is recommended to upgrade the affected component. VDB-262230 is the identifier assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1000"
},
{
"type": "WEB",
"url": "https://github.com/cyanomiko/dcnnt-py/pull/23"
},
{
"type": "WEB",
"url": "https://github.com/cyanomiko/dcnnt-py/commit/b4021d784a97e25151a5353aa763a741e9a148f5"
},
{
"type": "WEB",
"url": "https://github.com/cyanomiko/dcnnt-py/releases/tag/0.9.1"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.262230"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.262230"
}
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-27T09:15:08Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jq6r-qxvf-4wrv",
"modified": "2024-04-27T09:30:34Z",
"published": "2024-04-27T09:30:34Z",
"aliases": [
"CVE-2024-4246"
],
"details": "A vulnerability, which was classified as critical, was found in Tenda i21 1.0.0.14(4656). This affects the function formQosManageDouble_auto. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The identifier VDB-262137 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4246"
},
{
"type": "WEB",
"url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/i/i21/formQosManageDouble_user.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.262137"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.262137"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.319831"
}
],
"database_specific": {
"cwe_ids": [
"CWE-121"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-27T09:15:09Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pw3q-4wqj-24pp",
"modified": "2024-04-27T09:30:34Z",
"published": "2024-04-27T09:30:34Z",
"aliases": [
"CVE-2024-3342"
],
"details": "The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attribute of the 'mp-timetable' shortcode in all versions up to, and including, 2.4.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3342"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3077596/mp-timetable/trunk/classes/models/class-events.php"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9670bd32-34ce-48b1-82d9-62ab8869a89b?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-27T09:15:09Z"
}
}