diff --git a/advisories/unreviewed/2024/04/GHSA-4qf6-pw5g-fjgf/GHSA-4qf6-pw5g-fjgf.json b/advisories/unreviewed/2024/04/GHSA-4qf6-pw5g-fjgf/GHSA-4qf6-pw5g-fjgf.json new file mode 100644 index 00000000000..ef68deb92e0 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4qf6-pw5g-fjgf/GHSA-4qf6-pw5g-fjgf.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qf6-pw5g-fjgf", + "modified": "2024-04-27T09:30:33Z", + "published": "2024-04-27T09:30:33Z", + "aliases": [ + "CVE-2024-4245" + ], + "details": "A vulnerability, which was classified as critical, has been found in Tenda i21 1.0.0.14(4656). Affected by this issue is the function formQosManageDouble_user. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack may be launched remotely. The identifier of this vulnerability is VDB-262136. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4245" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/i/i21/formQosManageDouble_auto.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.262136" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.262136" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.319830" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-27T08:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8p42-7597-p2f6/GHSA-8p42-7597-p2f6.json b/advisories/unreviewed/2024/04/GHSA-8p42-7597-p2f6/GHSA-8p42-7597-p2f6.json new file mode 100644 index 00000000000..c0ac4b38927 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8p42-7597-p2f6/GHSA-8p42-7597-p2f6.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p42-7597-p2f6", + "modified": "2024-04-27T09:30:33Z", + "published": "2024-04-27T09:30:33Z", + "aliases": [ + "CVE-2023-1000" + ], + "details": "A vulnerability was found in cyanomiko dcnnt-py up to 0.9.0. It has been classified as critical. Affected is the function main of the file dcnnt/plugins/notifications.py of the component Notification Handler. The manipulation leads to command injection. It is possible to launch the attack remotely. Upgrading to version 0.9.1 is able to address this issue. The patch is identified as b4021d784a97e25151a5353aa763a741e9a148f5. It is recommended to upgrade the affected component. VDB-262230 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1000" + }, + { + "type": "WEB", + "url": "https://github.com/cyanomiko/dcnnt-py/pull/23" + }, + { + "type": "WEB", + "url": "https://github.com/cyanomiko/dcnnt-py/commit/b4021d784a97e25151a5353aa763a741e9a148f5" + }, + { + "type": "WEB", + "url": "https://github.com/cyanomiko/dcnnt-py/releases/tag/0.9.1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.262230" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.262230" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-27T09:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jq6r-qxvf-4wrv/GHSA-jq6r-qxvf-4wrv.json b/advisories/unreviewed/2024/04/GHSA-jq6r-qxvf-4wrv/GHSA-jq6r-qxvf-4wrv.json new file mode 100644 index 00000000000..83c9e52a526 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jq6r-qxvf-4wrv/GHSA-jq6r-qxvf-4wrv.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq6r-qxvf-4wrv", + "modified": "2024-04-27T09:30:34Z", + "published": "2024-04-27T09:30:34Z", + "aliases": [ + "CVE-2024-4246" + ], + "details": "A vulnerability, which was classified as critical, was found in Tenda i21 1.0.0.14(4656). This affects the function formQosManageDouble_auto. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The identifier VDB-262137 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4246" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/i/i21/formQosManageDouble_user.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.262137" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.262137" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.319831" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-27T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pw3q-4wqj-24pp/GHSA-pw3q-4wqj-24pp.json b/advisories/unreviewed/2024/04/GHSA-pw3q-4wqj-24pp/GHSA-pw3q-4wqj-24pp.json new file mode 100644 index 00000000000..1c9049a57d3 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pw3q-4wqj-24pp/GHSA-pw3q-4wqj-24pp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw3q-4wqj-24pp", + "modified": "2024-04-27T09:30:34Z", + "published": "2024-04-27T09:30:34Z", + "aliases": [ + "CVE-2024-3342" + ], + "details": "The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attribute of the 'mp-timetable' shortcode in all versions up to, and including, 2.4.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3342" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3077596/mp-timetable/trunk/classes/models/class-events.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9670bd32-34ce-48b1-82d9-62ab8869a89b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-27T09:15:09Z" + } +} \ No newline at end of file