Publish Advisories

GHSA-3mq5-2hmg-6cr7
GHSA-59g7-q3pq-jv2x
GHSA-7r9m-wfjg-4hqh
GHSA-9xcg-3948-4766
GHSA-c93h-6xwh-xgwm
GHSA-hgrq-77qx-v7gx
GHSA-jc5g-xwm8-wmhj
GHSA-v458-mw3m-m7vg
GHSA-xfjx-x547-fx7v
GHSA-xx63-954p-r9m7
This commit is contained in:
advisory-database[bot]
2023-09-13 21:32:07 +00:00
parent cef8779c81
commit 95b077e726
10 changed files with 266 additions and 10 deletions
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"github_reviewed": false,
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-59g7-q3pq-jv2x",
"modified": "2023-09-13T21:30:56Z",
"published": "2023-09-13T21:30:56Z",
"aliases": [
"CVE-2023-4568"
],
"details": "PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and below are confirmed to be affected, but later versions may also be affected due to lack of a vendor supplied patch.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4568"
},
{
"type": "WEB",
"url": "https://www.tenable.com/security/research/tra-2023-31"
}
],
"database_specific": {
"cwe_ids": [
"CWE-287"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7r9m-wfjg-4hqh",
"modified": "2023-09-13T21:30:56Z",
"published": "2023-09-13T21:30:56Z",
"aliases": [
"CVE-2023-3588"
],
"details": "A stored Cross-site Scripting (XSS) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x allows an attacker to execute arbitrary script code.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3588"
},
{
"type": "WEB",
"url": "https://www.3ds.com/vulnerability/advisories"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9xcg-3948-4766",
"modified": "2023-09-13T21:30:56Z",
"published": "2023-09-13T21:30:56Z",
"aliases": [
"CVE-2023-42468"
],
"details": "The com.cutestudio.colordialer application through 2.1.8-2 for Android allows a remote attacker to initiate phone calls without user consent, because of improper export of the com.cutestudio.dialer.activities.DialerActivity component. A third-party application (without any permissions) can craft an intent targeting com.cutestudio.dialer.activities.DialerActivity via the android.intent.action.CALL action in conjunction with a tel: URI, thereby placing a phone call.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42468"
},
{
"type": "WEB",
"url": "https://github.com/actuator/com.cutestudio.colordialer/blob/main/CWE-284.md"
},
{
"type": "WEB",
"url": "https://github.com/actuator/com.cutestudio.colordialer/blob/main/dial.gif"
},
{
"type": "WEB",
"url": "https://github.com/actuator/com.cutestudio.colordialer/blob/main/dialerPOC.apk"
},
{
"type": "WEB",
"url": "https://github.com/actuator/cve/blob/main/CVE-2023-42468"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c93h-6xwh-xgwm",
"modified": "2023-09-13T21:30:56Z",
"published": "2023-09-13T21:30:56Z",
"aliases": [
"CVE-2023-4887"
],
"details": "The Google Maps Plugin by Intergeo for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'intergeo' shortcode in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4887"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/intergeo-maps/tags/2.3.2/index.php#L1146"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cb6d11ad-0983-4a4b-b52b-824eae8b8e3c?source=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hgrq-77qx-v7gx",
"modified": "2023-09-13T21:30:56Z",
"published": "2023-09-13T21:30:56Z",
"aliases": [
"CVE-2023-40850"
],
"details": "netentsec NS-ASG 6.3 is vulnerable to Incorrect Access Control. There is a file leak in the website source code of the application security gateway.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40850"
},
{
"type": "WEB",
"url": "https://github.com/flyyue2001/cve/blob/main/NS-ASG-bak-leakage.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jc5g-xwm8-wmhj",
"modified": "2023-09-13T21:30:56Z",
"published": "2023-09-13T21:30:56Z",
"aliases": [
"CVE-2023-42469"
],
"details": "The com.full.dialer.top.secure.encrypted application through 1.0.1 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.full.dialer.top.secure.encrypted.activities.DialerActivity component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42469"
},
{
"type": "WEB",
"url": "https://github.com/actuator/com.full.dialer.top.secure.encrypted"
},
{
"type": "WEB",
"url": "https://github.com/actuator/com.full.dialer.top.secure.encrypted/blob/main/dial.gif"
},
{
"type": "WEB",
"url": "https://github.com/actuator/com.full.dialer.top.secure.encrypted/blob/main/poc.apk"
},
{
"type": "WEB",
"url": "https://github.com/actuator/cve/blob/main/CVE-2023-42469"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v458-mw3m-m7vg",
"modified": "2023-09-11T18:31:30Z",
"modified": "2023-09-13T21:30:56Z",
"published": "2023-09-11T18:31:30Z",
"aliases": [
"CVE-2023-30058"
],
"details": "novel-plus 3.6.2 is vulnerable to SQL Injection.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xfjx-x547-fx7v",
"modified": "2023-09-11T21:30:16Z",
"modified": "2023-09-13T21:30:56Z",
"published": "2023-09-11T21:30:16Z",
"aliases": [
"CVE-2020-19323"
],
"details": "An issue was discovered in /bin/mini_upnpd on D-Link DIR-619L 2.06beta devices. There is a heap buffer overflow allowing remote attackers to restart router via the M-search request ST parameter. No authentication required",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -29,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xx63-954p-r9m7",
"modified": "2023-09-11T18:31:30Z",
"modified": "2023-09-13T21:30:56Z",
"published": "2023-09-11T18:31:30Z",
"aliases": [
"CVE-2020-19318"
],
"details": "Buffer Overflow vulnerability in D-Link DIR-605L, hardware version AX, firmware version 1.17beta and below, allows authorized attackers execute arbitrary code via sending crafted data to the webserver service program.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": null,
"github_reviewed": false,