From a4d46e993bfd4a4d618365cb574453b7b3f89b6a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 27 Nov 2023 18:32:28 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-233r-fmgw-36jr.json | 43 +++++++++++++++++++ .../GHSA-28c2-wq95-3f9j.json | 35 +++++++++++++++ .../GHSA-2r79-jc6j-hh65.json | 35 +++++++++++++++ .../GHSA-3v9m-2r3c-48wc.json | 35 +++++++++++++++ .../GHSA-44x4-c385-mp6p.json | 35 +++++++++++++++ .../GHSA-4pp4-2f6f-77qm.json | 35 +++++++++++++++ .../GHSA-4q47-vc82-p724.json | 35 +++++++++++++++ .../GHSA-4rfx-692g-gc7w.json | 11 +++-- .../GHSA-4xpq-wqf9-p6mv.json | 38 ++++++++++++++++ .../GHSA-589p-x4q3-2jh3.json | 35 +++++++++++++++ .../GHSA-5c7f-c4vf-5xcw.json | 35 +++++++++++++++ .../GHSA-5mpg-rwcj-r8cj.json | 38 ++++++++++++++++ .../GHSA-63fm-6c9f-hvf6.json | 4 ++ .../GHSA-64vp-2fr6-5cqq.json | 11 +++-- .../GHSA-6mpw-r8r8-xcw2.json | 35 +++++++++++++++ .../GHSA-6vrh-99q9-hcxv.json | 11 +++-- .../GHSA-732v-mmfh-p7hp.json | 35 +++++++++++++++ .../GHSA-7862-qcxg-7h4c.json | 35 +++++++++++++++ .../GHSA-79r8-2qh7-xqp4.json | 38 ++++++++++++++++ .../GHSA-8993-7526-7h8g.json | 35 +++++++++++++++ .../GHSA-8r4v-g8rr-6r96.json | 35 +++++++++++++++ .../GHSA-8w35-mhqw-h887.json | 35 +++++++++++++++ .../GHSA-973j-jf94-fmwp.json | 38 ++++++++++++++++ .../GHSA-9gj5-q54r-hcpr.json | 38 ++++++++++++++++ .../GHSA-9jjv-7crp-6rr2.json | 38 ++++++++++++++++ .../GHSA-c2rj-9j4x-57r6.json | 35 +++++++++++++++ .../GHSA-cfc9-f8qw-f5wh.json | 38 ++++++++++++++++ .../GHSA-cjmg-pmr3-7c35.json | 35 +++++++++++++++ .../GHSA-cp7x-wvvh-9jrh.json | 35 +++++++++++++++ .../GHSA-f9vh-fjmh-q969.json | 11 +++-- .../GHSA-hgwf-985j-mh3j.json | 35 +++++++++++++++ .../GHSA-hj52-659r-887v.json | 35 +++++++++++++++ .../GHSA-hx6v-27f6-jgp7.json | 11 +++-- .../GHSA-j833-mj9j-x2pj.json | 35 +++++++++++++++ .../GHSA-jpr7-q523-hx25.json | 39 +++++++++++++++++ .../GHSA-mgqv-g9mm-hg88.json | 35 +++++++++++++++ .../GHSA-mpgc-x575-hg38.json | 35 +++++++++++++++ .../GHSA-mpqx-f5wx-h649.json | 11 +++-- .../GHSA-p7pg-xwv6-5rhh.json | 35 +++++++++++++++ .../GHSA-pjgh-f3xj-rv83.json | 38 ++++++++++++++++ .../GHSA-px94-47v9-w45x.json | 35 +++++++++++++++ .../GHSA-q5h6-hfv2-xr6w.json | 38 ++++++++++++++++ .../GHSA-q5h7-rxc2-vj98.json | 35 +++++++++++++++ .../GHSA-qfcq-5rf4-6g68.json | 11 +++-- .../GHSA-qhh4-w7cp-9j2f.json | 11 +++-- .../GHSA-r4pf-qg69-h279.json | 11 +++-- .../GHSA-rq8c-6g4c-3q78.json | 35 +++++++++++++++ .../GHSA-v88m-92x2-qxm5.json | 11 +++-- .../GHSA-vpf6-j6mv-p249.json | 35 +++++++++++++++ .../GHSA-vxxj-38m8-46gm.json | 38 ++++++++++++++++ .../GHSA-x5r2-jq66-4ccq.json | 38 ++++++++++++++++ .../GHSA-xg5j-3w2m-6rhx.json | 35 +++++++++++++++ .../GHSA-xh5j-9mr3-45mv.json | 43 +++++++++++++++++++ .../GHSA-xrp3-cvwg-fc64.json | 35 +++++++++++++++ .../GHSA-xvc2-6386-99x8.json | 11 +++-- 55 files changed, 1639 insertions(+), 44 deletions(-) create mode 100644 advisories/unreviewed/2023/11/GHSA-233r-fmgw-36jr/GHSA-233r-fmgw-36jr.json create mode 100644 advisories/unreviewed/2023/11/GHSA-28c2-wq95-3f9j/GHSA-28c2-wq95-3f9j.json create mode 100644 advisories/unreviewed/2023/11/GHSA-2r79-jc6j-hh65/GHSA-2r79-jc6j-hh65.json create mode 100644 advisories/unreviewed/2023/11/GHSA-3v9m-2r3c-48wc/GHSA-3v9m-2r3c-48wc.json create mode 100644 advisories/unreviewed/2023/11/GHSA-44x4-c385-mp6p/GHSA-44x4-c385-mp6p.json create mode 100644 advisories/unreviewed/2023/11/GHSA-4pp4-2f6f-77qm/GHSA-4pp4-2f6f-77qm.json create mode 100644 advisories/unreviewed/2023/11/GHSA-4q47-vc82-p724/GHSA-4q47-vc82-p724.json create mode 100644 advisories/unreviewed/2023/11/GHSA-4xpq-wqf9-p6mv/GHSA-4xpq-wqf9-p6mv.json create mode 100644 advisories/unreviewed/2023/11/GHSA-589p-x4q3-2jh3/GHSA-589p-x4q3-2jh3.json create mode 100644 advisories/unreviewed/2023/11/GHSA-5c7f-c4vf-5xcw/GHSA-5c7f-c4vf-5xcw.json create mode 100644 advisories/unreviewed/2023/11/GHSA-5mpg-rwcj-r8cj/GHSA-5mpg-rwcj-r8cj.json create mode 100644 advisories/unreviewed/2023/11/GHSA-6mpw-r8r8-xcw2/GHSA-6mpw-r8r8-xcw2.json create mode 100644 advisories/unreviewed/2023/11/GHSA-732v-mmfh-p7hp/GHSA-732v-mmfh-p7hp.json create mode 100644 advisories/unreviewed/2023/11/GHSA-7862-qcxg-7h4c/GHSA-7862-qcxg-7h4c.json create mode 100644 advisories/unreviewed/2023/11/GHSA-79r8-2qh7-xqp4/GHSA-79r8-2qh7-xqp4.json create mode 100644 advisories/unreviewed/2023/11/GHSA-8993-7526-7h8g/GHSA-8993-7526-7h8g.json create mode 100644 advisories/unreviewed/2023/11/GHSA-8r4v-g8rr-6r96/GHSA-8r4v-g8rr-6r96.json create mode 100644 advisories/unreviewed/2023/11/GHSA-8w35-mhqw-h887/GHSA-8w35-mhqw-h887.json create mode 100644 advisories/unreviewed/2023/11/GHSA-973j-jf94-fmwp/GHSA-973j-jf94-fmwp.json create mode 100644 advisories/unreviewed/2023/11/GHSA-9gj5-q54r-hcpr/GHSA-9gj5-q54r-hcpr.json create mode 100644 advisories/unreviewed/2023/11/GHSA-9jjv-7crp-6rr2/GHSA-9jjv-7crp-6rr2.json create mode 100644 advisories/unreviewed/2023/11/GHSA-c2rj-9j4x-57r6/GHSA-c2rj-9j4x-57r6.json create mode 100644 advisories/unreviewed/2023/11/GHSA-cfc9-f8qw-f5wh/GHSA-cfc9-f8qw-f5wh.json create mode 100644 advisories/unreviewed/2023/11/GHSA-cjmg-pmr3-7c35/GHSA-cjmg-pmr3-7c35.json create mode 100644 advisories/unreviewed/2023/11/GHSA-cp7x-wvvh-9jrh/GHSA-cp7x-wvvh-9jrh.json create mode 100644 advisories/unreviewed/2023/11/GHSA-hgwf-985j-mh3j/GHSA-hgwf-985j-mh3j.json create mode 100644 advisories/unreviewed/2023/11/GHSA-hj52-659r-887v/GHSA-hj52-659r-887v.json create mode 100644 advisories/unreviewed/2023/11/GHSA-j833-mj9j-x2pj/GHSA-j833-mj9j-x2pj.json create mode 100644 advisories/unreviewed/2023/11/GHSA-jpr7-q523-hx25/GHSA-jpr7-q523-hx25.json create mode 100644 advisories/unreviewed/2023/11/GHSA-mgqv-g9mm-hg88/GHSA-mgqv-g9mm-hg88.json create mode 100644 advisories/unreviewed/2023/11/GHSA-mpgc-x575-hg38/GHSA-mpgc-x575-hg38.json create mode 100644 advisories/unreviewed/2023/11/GHSA-p7pg-xwv6-5rhh/GHSA-p7pg-xwv6-5rhh.json create mode 100644 advisories/unreviewed/2023/11/GHSA-pjgh-f3xj-rv83/GHSA-pjgh-f3xj-rv83.json create mode 100644 advisories/unreviewed/2023/11/GHSA-px94-47v9-w45x/GHSA-px94-47v9-w45x.json create mode 100644 advisories/unreviewed/2023/11/GHSA-q5h6-hfv2-xr6w/GHSA-q5h6-hfv2-xr6w.json create mode 100644 advisories/unreviewed/2023/11/GHSA-q5h7-rxc2-vj98/GHSA-q5h7-rxc2-vj98.json create mode 100644 advisories/unreviewed/2023/11/GHSA-rq8c-6g4c-3q78/GHSA-rq8c-6g4c-3q78.json create mode 100644 advisories/unreviewed/2023/11/GHSA-vpf6-j6mv-p249/GHSA-vpf6-j6mv-p249.json create mode 100644 advisories/unreviewed/2023/11/GHSA-vxxj-38m8-46gm/GHSA-vxxj-38m8-46gm.json create mode 100644 advisories/unreviewed/2023/11/GHSA-x5r2-jq66-4ccq/GHSA-x5r2-jq66-4ccq.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xg5j-3w2m-6rhx/GHSA-xg5j-3w2m-6rhx.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xh5j-9mr3-45mv/GHSA-xh5j-9mr3-45mv.json create mode 100644 advisories/unreviewed/2023/11/GHSA-xrp3-cvwg-fc64/GHSA-xrp3-cvwg-fc64.json diff --git a/advisories/unreviewed/2023/11/GHSA-233r-fmgw-36jr/GHSA-233r-fmgw-36jr.json b/advisories/unreviewed/2023/11/GHSA-233r-fmgw-36jr/GHSA-233r-fmgw-36jr.json new file mode 100644 index 00000000000..b3df31383d6 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-233r-fmgw-36jr/GHSA-233r-fmgw-36jr.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-233r-fmgw-36jr", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-49028" + ], + "details": "Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitrary code via the user parameter in the lock/lock.php file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49028" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Chiaki2333/d132c4b169b55bd7cd50e73dbe20c410" + }, + { + "type": "WEB", + "url": "https://github.com/Chiaki2333/vulnerability/blob/main/smpn1smg-absis-XSS-lock.php-user.md" + }, + { + "type": "WEB", + "url": "https://github.com/smpn1smg/absis" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-28c2-wq95-3f9j/GHSA-28c2-wq95-3f9j.json b/advisories/unreviewed/2023/11/GHSA-28c2-wq95-3f9j/GHSA-28c2-wq95-3f9j.json new file mode 100644 index 00000000000..ed8a02b0e5b --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-28c2-wq95-3f9j/GHSA-28c2-wq95-3f9j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28c2-wq95-3f9j", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-2707" + ], + "details": "The gAppointments WordPress plugin through 1.9.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2707" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/e5664da4-5b78-4e42-be6b-e0d7b73a85b0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-2r79-jc6j-hh65/GHSA-2r79-jc6j-hh65.json b/advisories/unreviewed/2023/11/GHSA-2r79-jc6j-hh65/GHSA-2r79-jc6j-hh65.json new file mode 100644 index 00000000000..c5f4f921226 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-2r79-jc6j-hh65/GHSA-2r79-jc6j-hh65.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r79-jc6j-hh65", + "modified": "2023-11-27T18:31:14Z", + "published": "2023-11-27T18:31:14Z", + "aliases": [ + "CVE-2023-5958" + ], + "details": "The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the backend, allowing an unauthenticated attacker to perform XSS attacks against highly privileged users.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5958" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/22fa478d-e42e-488d-9b4b-a8720dec7cee" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-3v9m-2r3c-48wc/GHSA-3v9m-2r3c-48wc.json b/advisories/unreviewed/2023/11/GHSA-3v9m-2r3c-48wc/GHSA-3v9m-2r3c-48wc.json new file mode 100644 index 00000000000..597b1f4904d --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-3v9m-2r3c-48wc/GHSA-3v9m-2r3c-48wc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3v9m-2r3c-48wc", + "modified": "2023-11-27T18:31:14Z", + "published": "2023-11-27T18:31:14Z", + "aliases": [ + "CVE-2023-5560" + ], + "details": "The WP-UserOnline WordPress plugin before 2.88.3 does not sanitise and escape the X-Forwarded-For header before outputting its content on the page, which allows unauthenticated users to perform Cross-Site Scripting attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5560" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/55d23184-fc5a-4090-b079-142407b59b05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-44x4-c385-mp6p/GHSA-44x4-c385-mp6p.json b/advisories/unreviewed/2023/11/GHSA-44x4-c385-mp6p/GHSA-44x4-c385-mp6p.json new file mode 100644 index 00000000000..d09c8e6fe20 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-44x4-c385-mp6p/GHSA-44x4-c385-mp6p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44x4-c385-mp6p", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-49040" + ], + "details": "An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPwd parameter in the form_fast_setting_internet_set function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49040" + }, + { + "type": "WEB", + "url": "https://github.com/Anza2001/IOT_VULN/blob/main/Tenda/AX1803/form_fast_setting_internet_set.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-4pp4-2f6f-77qm/GHSA-4pp4-2f6f-77qm.json b/advisories/unreviewed/2023/11/GHSA-4pp4-2f6f-77qm/GHSA-4pp4-2f6f-77qm.json new file mode 100644 index 00000000000..cbbfb24feeb --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-4pp4-2f6f-77qm/GHSA-4pp4-2f6f-77qm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pp4-2f6f-77qm", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-4922" + ], + "details": "The WPB Show Core WordPress plugin through 2.2 is vulnerable to a local file inclusion via the `path` parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4922" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/968d87c0-af60-45ea-b34e-8551313cc8df" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-4q47-vc82-p724/GHSA-4q47-vc82-p724.json b/advisories/unreviewed/2023/11/GHSA-4q47-vc82-p724/GHSA-4q47-vc82-p724.json new file mode 100644 index 00000000000..7305de66e7e --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-4q47-vc82-p724/GHSA-4q47-vc82-p724.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4q47-vc82-p724", + "modified": "2023-11-27T18:31:14Z", + "published": "2023-11-27T18:31:14Z", + "aliases": [ + "CVE-2023-5653" + ], + "details": "The WassUp Real Time Analytics WordPress plugin through 1.9.4.5 does not escape IP address provided via some headers before outputting them back in an admin page, allowing unauthenticated users to perform Stored XSS attacks against logged in admins", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5653" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/76316621-1987-44ea-83e5-6ca884bdd1c0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-4rfx-692g-gc7w/GHSA-4rfx-692g-gc7w.json b/advisories/unreviewed/2023/11/GHSA-4rfx-692g-gc7w/GHSA-4rfx-692g-gc7w.json index 556b12c10fd..2a890d845f4 100644 --- a/advisories/unreviewed/2023/11/GHSA-4rfx-692g-gc7w/GHSA-4rfx-692g-gc7w.json +++ b/advisories/unreviewed/2023/11/GHSA-4rfx-692g-gc7w/GHSA-4rfx-692g-gc7w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4rfx-692g-gc7w", - "modified": "2023-11-20T21:31:03Z", + "modified": "2023-11-27T18:31:13Z", "published": "2023-11-20T21:31:03Z", "aliases": [ "CVE-2023-5609" ], "details": "The Seraphinite Accelerator WordPress plugin before 2.2.29 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-20T19:15:09Z" diff --git a/advisories/unreviewed/2023/11/GHSA-4xpq-wqf9-p6mv/GHSA-4xpq-wqf9-p6mv.json b/advisories/unreviewed/2023/11/GHSA-4xpq-wqf9-p6mv/GHSA-4xpq-wqf9-p6mv.json new file mode 100644 index 00000000000..0c67fc03c97 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-4xpq-wqf9-p6mv/GHSA-4xpq-wqf9-p6mv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xpq-wqf9-p6mv", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-42000" + ], + "details": "Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can exploit it to upload arbitrary files to any location on the file system where the UDP agent is installed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42000" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/research/tra-2023-37" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-589p-x4q3-2jh3/GHSA-589p-x4q3-2jh3.json b/advisories/unreviewed/2023/11/GHSA-589p-x4q3-2jh3/GHSA-589p-x4q3-2jh3.json new file mode 100644 index 00000000000..59c8b47ae50 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-589p-x4q3-2jh3/GHSA-589p-x4q3-2jh3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-589p-x4q3-2jh3", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-5239" + ], + "details": "The Security & Malware scan by CleanTalk WordPress plugin before 2.121 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass bruteforce protection.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5239" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/1d748f91-773b-49d6-8f68-a27d397713c3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5c7f-c4vf-5xcw/GHSA-5c7f-c4vf-5xcw.json b/advisories/unreviewed/2023/11/GHSA-5c7f-c4vf-5xcw/GHSA-5c7f-c4vf-5xcw.json new file mode 100644 index 00000000000..88a3a0d3cfb --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5c7f-c4vf-5xcw/GHSA-5c7f-c4vf-5xcw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c7f-c4vf-5xcw", + "modified": "2023-11-27T18:31:14Z", + "published": "2023-11-27T18:31:14Z", + "aliases": [ + "CVE-2023-5942" + ], + "details": "The Medialist WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5942" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/914559e1-eed5-4a69-8371-a48055835453" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-5mpg-rwcj-r8cj/GHSA-5mpg-rwcj-r8cj.json b/advisories/unreviewed/2023/11/GHSA-5mpg-rwcj-r8cj/GHSA-5mpg-rwcj-r8cj.json new file mode 100644 index 00000000000..71b9e1b170f --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-5mpg-rwcj-r8cj/GHSA-5mpg-rwcj-r8cj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mpg-rwcj-r8cj", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-41999" + ], + "details": "An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifier that allows them to authenticate to the management console and perform tasks that require authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41999" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/research/tra-2023-37" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-63fm-6c9f-hvf6/GHSA-63fm-6c9f-hvf6.json b/advisories/unreviewed/2023/11/GHSA-63fm-6c9f-hvf6/GHSA-63fm-6c9f-hvf6.json index 8fd67bddae7..11e12a8bbce 100644 --- a/advisories/unreviewed/2023/11/GHSA-63fm-6c9f-hvf6/GHSA-63fm-6c9f-hvf6.json +++ b/advisories/unreviewed/2023/11/GHSA-63fm-6c9f-hvf6/GHSA-63fm-6c9f-hvf6.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://vuldb.com/?id.246122" + }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/175925/osCommerce-4-Cross-Site-Scripting.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-64vp-2fr6-5cqq/GHSA-64vp-2fr6-5cqq.json b/advisories/unreviewed/2023/11/GHSA-64vp-2fr6-5cqq/GHSA-64vp-2fr6-5cqq.json index 6675821dd78..ab0217ff810 100644 --- a/advisories/unreviewed/2023/11/GHSA-64vp-2fr6-5cqq/GHSA-64vp-2fr6-5cqq.json +++ b/advisories/unreviewed/2023/11/GHSA-64vp-2fr6-5cqq/GHSA-64vp-2fr6-5cqq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-64vp-2fr6-5cqq", - "modified": "2023-11-20T21:31:02Z", + "modified": "2023-11-27T18:31:12Z", "published": "2023-11-20T21:31:02Z", "aliases": [ "CVE-2023-5119" ], "details": "The Forminator WordPress plugin before 1.27.0 does not properly sanitize the redirect-url field in the form submission settings, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-20T19:15:09Z" diff --git a/advisories/unreviewed/2023/11/GHSA-6mpw-r8r8-xcw2/GHSA-6mpw-r8r8-xcw2.json b/advisories/unreviewed/2023/11/GHSA-6mpw-r8r8-xcw2/GHSA-6mpw-r8r8-xcw2.json new file mode 100644 index 00000000000..dc5671734b2 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-6mpw-r8r8-xcw2/GHSA-6mpw-r8r8-xcw2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mpw-r8r8-xcw2", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-49042" + ], + "details": "Heap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the schedStartTime parameter or the schedEndTime parameter in the function setSchedWifi.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49042" + }, + { + "type": "WEB", + "url": "https://github.com/Anza2001/IOT_VULN/blob/main/Tenda/AX1803/setSchedWifi.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-6vrh-99q9-hcxv/GHSA-6vrh-99q9-hcxv.json b/advisories/unreviewed/2023/11/GHSA-6vrh-99q9-hcxv/GHSA-6vrh-99q9-hcxv.json index fe8b0755976..48cc22fe55d 100644 --- a/advisories/unreviewed/2023/11/GHSA-6vrh-99q9-hcxv/GHSA-6vrh-99q9-hcxv.json +++ b/advisories/unreviewed/2023/11/GHSA-6vrh-99q9-hcxv/GHSA-6vrh-99q9-hcxv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6vrh-99q9-hcxv", - "modified": "2023-11-20T21:31:03Z", + "modified": "2023-11-27T18:31:13Z", "published": "2023-11-20T21:31:03Z", "aliases": [ "CVE-2023-5652" ], "details": "The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing unauthenticated users to perform SQL injections", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-20T19:15:10Z" diff --git a/advisories/unreviewed/2023/11/GHSA-732v-mmfh-p7hp/GHSA-732v-mmfh-p7hp.json b/advisories/unreviewed/2023/11/GHSA-732v-mmfh-p7hp/GHSA-732v-mmfh-p7hp.json new file mode 100644 index 00000000000..5048e69c777 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-732v-mmfh-p7hp/GHSA-732v-mmfh-p7hp.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-732v-mmfh-p7hp", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-4297" + ], + "details": "The Mmm Simple File List WordPress plugin through 2.3 does not validate the generated path to list files from, allowing any authenticated users, such as subscribers, to list the content of arbitrary directories.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4297" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/9ff85b06-819c-459e-90a9-6151bfd70978" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-7862-qcxg-7h4c/GHSA-7862-qcxg-7h4c.json b/advisories/unreviewed/2023/11/GHSA-7862-qcxg-7h4c/GHSA-7862-qcxg-7h4c.json new file mode 100644 index 00000000000..f2a16315d93 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-7862-qcxg-7h4c/GHSA-7862-qcxg-7h4c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7862-qcxg-7h4c", + "modified": "2023-11-27T18:31:14Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-5604" + ], + "details": "The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5604" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/4ce69d71-87bf-4d95-90f2-63d558c78b69" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-79r8-2qh7-xqp4/GHSA-79r8-2qh7-xqp4.json b/advisories/unreviewed/2023/11/GHSA-79r8-2qh7-xqp4/GHSA-79r8-2qh7-xqp4.json new file mode 100644 index 00000000000..b37563d7ef2 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-79r8-2qh7-xqp4/GHSA-79r8-2qh7-xqp4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79r8-2qh7-xqp4", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-41257" + ], + "details": "A type confusion vulnerability exists in the way Foxit Reader 12.1.2.15356 handles field value properties. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41257" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1838" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-8993-7526-7h8g/GHSA-8993-7526-7h8g.json b/advisories/unreviewed/2023/11/GHSA-8993-7526-7h8g/GHSA-8993-7526-7h8g.json new file mode 100644 index 00000000000..d795564c29f --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-8993-7526-7h8g/GHSA-8993-7526-7h8g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8993-7526-7h8g", + "modified": "2023-11-27T18:31:14Z", + "published": "2023-11-27T18:31:14Z", + "aliases": [ + "CVE-2023-5611" + ], + "details": "The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting and importing its settings, allowing unauthenticated users to reset them", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5611" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/8cb8a5e9-2ab6-4d9b-9ffc-ef530e346f8d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-8r4v-g8rr-6r96/GHSA-8r4v-g8rr-6r96.json b/advisories/unreviewed/2023/11/GHSA-8r4v-g8rr-6r96/GHSA-8r4v-g8rr-6r96.json new file mode 100644 index 00000000000..020c3266df2 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-8r4v-g8rr-6r96/GHSA-8r4v-g8rr-6r96.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r4v-g8rr-6r96", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-49046" + ], + "details": "Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the devName parameter in the function formAddMacfilterRule.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49046" + }, + { + "type": "WEB", + "url": "https://github.com/Anza2001/IOT_VULN/blob/main/Tenda/AX1803/formAddMacfilterRule.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-8w35-mhqw-h887/GHSA-8w35-mhqw-h887.json b/advisories/unreviewed/2023/11/GHSA-8w35-mhqw-h887/GHSA-8w35-mhqw-h887.json new file mode 100644 index 00000000000..22887446c89 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-8w35-mhqw-h887/GHSA-8w35-mhqw-h887.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w35-mhqw-h887", + "modified": "2023-11-27T18:31:14Z", + "published": "2023-11-27T18:31:14Z", + "aliases": [ + "CVE-2023-5325" + ], + "details": "The Woocommerce Vietnam Checkout WordPress plugin before 2.0.6 does not escape the custom shipping phone field no the checkout form leading to XSS", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5325" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/e93841ef-e113-41d3-9fa1-b21af85bd812" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-973j-jf94-fmwp/GHSA-973j-jf94-fmwp.json b/advisories/unreviewed/2023/11/GHSA-973j-jf94-fmwp/GHSA-973j-jf94-fmwp.json new file mode 100644 index 00000000000..1409937fd76 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-973j-jf94-fmwp/GHSA-973j-jf94-fmwp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-973j-jf94-fmwp", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-40194" + ], + "details": "An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to mistreatment of whitespace characters. A specially crafted malicious file can create files at arbitrary locations, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40194" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1833" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9gj5-q54r-hcpr/GHSA-9gj5-q54r-hcpr.json b/advisories/unreviewed/2023/11/GHSA-9gj5-q54r-hcpr/GHSA-9gj5-q54r-hcpr.json new file mode 100644 index 00000000000..16a021fd1fe --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-9gj5-q54r-hcpr/GHSA-9gj5-q54r-hcpr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gj5-q54r-hcpr", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-35985" + ], + "details": "An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to a failure to properly validate a dangerous extension. A specially crafted malicious file can create files at arbitrary locations, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially-crafted malicious site if the browser plugin extension is enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35985" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1834" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T16:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-9jjv-7crp-6rr2/GHSA-9jjv-7crp-6rr2.json b/advisories/unreviewed/2023/11/GHSA-9jjv-7crp-6rr2/GHSA-9jjv-7crp-6rr2.json new file mode 100644 index 00000000000..71119c04691 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-9jjv-7crp-6rr2/GHSA-9jjv-7crp-6rr2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jjv-7crp-6rr2", + "modified": "2023-11-27T18:31:14Z", + "published": "2023-11-27T18:31:14Z", + "aliases": [ + "CVE-2023-6329" + ], + "details": "[PROBLEMTYPE] in [COMPONENT] in [VENDOR] [PRODUCT] [VERSION] on [PLATFORMS] allows [ATTACKER] to [IMPACT] via [VECTOR]", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6329" + }, + { + "type": "WEB", + "url": "https://tenable.com/security/research/tra-2023-36" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-c2rj-9j4x-57r6/GHSA-c2rj-9j4x-57r6.json b/advisories/unreviewed/2023/11/GHSA-c2rj-9j4x-57r6/GHSA-c2rj-9j4x-57r6.json new file mode 100644 index 00000000000..64f1b506be9 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-c2rj-9j4x-57r6/GHSA-c2rj-9j4x-57r6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2rj-9j4x-57r6", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-49047" + ], + "details": "Tenda AX1803 v1.0.0.1 contains a stack overflow via the devName parameter in the function formSetDeviceName.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49047" + }, + { + "type": "WEB", + "url": "https://github.com/Anza2001/IOT_VULN/blob/main/Tenda/AX1803/formSetDeviceName.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-cfc9-f8qw-f5wh/GHSA-cfc9-f8qw-f5wh.json b/advisories/unreviewed/2023/11/GHSA-cfc9-f8qw-f5wh/GHSA-cfc9-f8qw-f5wh.json new file mode 100644 index 00000000000..8aa5b4cfdd0 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cfc9-f8qw-f5wh/GHSA-cfc9-f8qw-f5wh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfc9-f8qw-f5wh", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-31275" + ], + "details": "An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elements in an Excel file. A specially crafted malformed file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31275" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1748" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T16:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-cjmg-pmr3-7c35/GHSA-cjmg-pmr3-7c35.json b/advisories/unreviewed/2023/11/GHSA-cjmg-pmr3-7c35/GHSA-cjmg-pmr3-7c35.json new file mode 100644 index 00000000000..016b480ecdf --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cjmg-pmr3-7c35/GHSA-cjmg-pmr3-7c35.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjmg-pmr3-7c35", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-4252" + ], + "details": "The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attacker to purchase bookings without payment.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4252" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d2019e59-db6c-4014-8057-0644c9a00665" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-cp7x-wvvh-9jrh/GHSA-cp7x-wvvh-9jrh.json b/advisories/unreviewed/2023/11/GHSA-cp7x-wvvh-9jrh/GHSA-cp7x-wvvh-9jrh.json new file mode 100644 index 00000000000..802f4395c00 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-cp7x-wvvh-9jrh/GHSA-cp7x-wvvh-9jrh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp7x-wvvh-9jrh", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-49043" + ], + "details": "Buffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the wpapsk_crypto parameter in the function fromSetWirelessRepeat.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49043" + }, + { + "type": "WEB", + "url": "https://github.com/Anza2001/IOT_VULN/blob/main/Tenda/AX1803/fromSetWirelessRepeat.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-f9vh-fjmh-q969/GHSA-f9vh-fjmh-q969.json b/advisories/unreviewed/2023/11/GHSA-f9vh-fjmh-q969/GHSA-f9vh-fjmh-q969.json index 78f7386ce37..1c94044b51e 100644 --- a/advisories/unreviewed/2023/11/GHSA-f9vh-fjmh-q969/GHSA-f9vh-fjmh-q969.json +++ b/advisories/unreviewed/2023/11/GHSA-f9vh-fjmh-q969/GHSA-f9vh-fjmh-q969.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f9vh-fjmh-q969", - "modified": "2023-11-20T21:31:03Z", + "modified": "2023-11-27T18:31:13Z", "published": "2023-11-20T21:31:03Z", "aliases": [ "CVE-2023-5651" ], "details": "The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensure that the package to be deleted is a package, allowing any authenticated users, such as subscriber to delete arbitrary posts", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-732" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-20T19:15:09Z" diff --git a/advisories/unreviewed/2023/11/GHSA-hgwf-985j-mh3j/GHSA-hgwf-985j-mh3j.json b/advisories/unreviewed/2023/11/GHSA-hgwf-985j-mh3j/GHSA-hgwf-985j-mh3j.json new file mode 100644 index 00000000000..f85b10114cd --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-hgwf-985j-mh3j/GHSA-hgwf-985j-mh3j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgwf-985j-mh3j", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-5209" + ], + "details": "The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5209" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/dea6077a-81ee-451f-b049-3749a2252c88" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-hj52-659r-887v/GHSA-hj52-659r-887v.json b/advisories/unreviewed/2023/11/GHSA-hj52-659r-887v/GHSA-hj52-659r-887v.json new file mode 100644 index 00000000000..87d1e5f8322 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-hj52-659r-887v/GHSA-hj52-659r-887v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hj52-659r-887v", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-4642" + ], + "details": "The kk Star Ratings WordPress plugin before 5.4.6 does not implement atomic operations, allowing one user vote multiple times on a poll due to a Race Condition.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4642" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/6f481d34-6feb-4af2-914c-1f3288f69207" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-hx6v-27f6-jgp7/GHSA-hx6v-27f6-jgp7.json b/advisories/unreviewed/2023/11/GHSA-hx6v-27f6-jgp7/GHSA-hx6v-27f6-jgp7.json index 0fa758d12f6..5c04e7f7d2b 100644 --- a/advisories/unreviewed/2023/11/GHSA-hx6v-27f6-jgp7/GHSA-hx6v-27f6-jgp7.json +++ b/advisories/unreviewed/2023/11/GHSA-hx6v-27f6-jgp7/GHSA-hx6v-27f6-jgp7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hx6v-27f6-jgp7", - "modified": "2023-11-20T21:31:03Z", + "modified": "2023-11-27T18:31:13Z", "published": "2023-11-20T21:31:03Z", "aliases": [ "CVE-2023-5610" ], "details": "The Seraphinite Accelerator WordPress plugin before 2.2.29 does not validate the URL to redirect any authenticated user to, leading to an arbitrary redirect", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-20T19:15:09Z" diff --git a/advisories/unreviewed/2023/11/GHSA-j833-mj9j-x2pj/GHSA-j833-mj9j-x2pj.json b/advisories/unreviewed/2023/11/GHSA-j833-mj9j-x2pj/GHSA-j833-mj9j-x2pj.json new file mode 100644 index 00000000000..c22ff2a3535 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-j833-mj9j-x2pj/GHSA-j833-mj9j-x2pj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j833-mj9j-x2pj", + "modified": "2023-11-27T18:31:14Z", + "published": "2023-11-27T18:31:14Z", + "aliases": [ + "CVE-2023-5845" + ], + "details": "The Simple Social Media Share Buttons WordPress plugin before 5.1.1 leaks password-protected post content to unauthenticated visitors in some meta tags", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5845" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/d5b59e9e-85e5-4d26-aebe-64757c8495fa" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-jpr7-q523-hx25/GHSA-jpr7-q523-hx25.json b/advisories/unreviewed/2023/11/GHSA-jpr7-q523-hx25/GHSA-jpr7-q523-hx25.json new file mode 100644 index 00000000000..6ffe3c9e1eb --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-jpr7-q523-hx25/GHSA-jpr7-q523-hx25.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpr7-q523-hx25", + "modified": "2023-11-27T18:31:14Z", + "published": "2023-11-27T18:31:14Z", + "aliases": [ + "CVE-2023-49316" + ], + "details": "In Math/BinaryField.php in phpseclib before 3.0.34, excessively large degrees can lead to a denial of service.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49316" + }, + { + "type": "WEB", + "url": "https://github.com/phpseclib/phpseclib/commit/964d78101a70305df33f442f5490f0adb3b7e77f" + }, + { + "type": "WEB", + "url": "https://github.com/phpseclib/phpseclib/releases/tag/3.0.34" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T18:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-mgqv-g9mm-hg88/GHSA-mgqv-g9mm-hg88.json b/advisories/unreviewed/2023/11/GHSA-mgqv-g9mm-hg88/GHSA-mgqv-g9mm-hg88.json new file mode 100644 index 00000000000..1e386fcc20c --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-mgqv-g9mm-hg88/GHSA-mgqv-g9mm-hg88.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgqv-g9mm-hg88", + "modified": "2023-11-27T18:31:14Z", + "published": "2023-11-27T18:31:14Z", + "aliases": [ + "CVE-2023-5738" + ], + "details": "The WordPress Backup & Migration WordPress plugin before 1.4.4 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5738" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/7f935916-9a1a-40c7-b6d8-efcc46eb8eaf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-mpgc-x575-hg38/GHSA-mpgc-x575-hg38.json b/advisories/unreviewed/2023/11/GHSA-mpgc-x575-hg38/GHSA-mpgc-x575-hg38.json new file mode 100644 index 00000000000..1b6bebf6c21 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-mpgc-x575-hg38/GHSA-mpgc-x575-hg38.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpgc-x575-hg38", + "modified": "2023-11-27T18:31:14Z", + "published": "2023-11-27T18:31:14Z", + "aliases": [ + "CVE-2023-5974" + ], + "details": "The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5974" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c0136057-f420-4fe7-a147-ecbec7e7a9b5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-mpqx-f5wx-h649/GHSA-mpqx-f5wx-h649.json b/advisories/unreviewed/2023/11/GHSA-mpqx-f5wx-h649/GHSA-mpqx-f5wx-h649.json index df21f38e826..160e7b9d5a7 100644 --- a/advisories/unreviewed/2023/11/GHSA-mpqx-f5wx-h649/GHSA-mpqx-f5wx-h649.json +++ b/advisories/unreviewed/2023/11/GHSA-mpqx-f5wx-h649/GHSA-mpqx-f5wx-h649.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mpqx-f5wx-h649", - "modified": "2023-11-20T21:31:03Z", + "modified": "2023-11-27T18:31:13Z", "published": "2023-11-20T21:31:03Z", "aliases": [ "CVE-2023-5640" ], "details": "The Article Analytics WordPress plugin does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-20T19:15:09Z" diff --git a/advisories/unreviewed/2023/11/GHSA-p7pg-xwv6-5rhh/GHSA-p7pg-xwv6-5rhh.json b/advisories/unreviewed/2023/11/GHSA-p7pg-xwv6-5rhh/GHSA-p7pg-xwv6-5rhh.json new file mode 100644 index 00000000000..e6f2b36247d --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-p7pg-xwv6-5rhh/GHSA-p7pg-xwv6-5rhh.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7pg-xwv6-5rhh", + "modified": "2023-11-27T18:31:14Z", + "published": "2023-11-27T18:31:14Z", + "aliases": [ + "CVE-2023-5906" + ], + "details": "The Job Manager & Career WordPress plugin before 1.4.4 contains a vulnerability in the Directory Listings system, which allows an unauthorized user to view and download private files of other users. This vulnerability poses a serious security threat because it allows an attacker to gain access to confidential data and files of other users without their permission.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5906" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/911d495c-3867-4259-a73a-572cd4fccdde" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-pjgh-f3xj-rv83/GHSA-pjgh-f3xj-rv83.json b/advisories/unreviewed/2023/11/GHSA-pjgh-f3xj-rv83/GHSA-pjgh-f3xj-rv83.json new file mode 100644 index 00000000000..557bc3d7532 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-pjgh-f3xj-rv83/GHSA-pjgh-f3xj-rv83.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjgh-f3xj-rv83", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-32616" + ], + "details": "A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles 3D annotations. A specially crafted Javascript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32616" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1837" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T16:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-px94-47v9-w45x/GHSA-px94-47v9-w45x.json b/advisories/unreviewed/2023/11/GHSA-px94-47v9-w45x/GHSA-px94-47v9-w45x.json new file mode 100644 index 00000000000..3d0e98dd4d7 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-px94-47v9-w45x/GHSA-px94-47v9-w45x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px94-47v9-w45x", + "modified": "2023-11-27T18:31:14Z", + "published": "2023-11-27T18:31:14Z", + "aliases": [ + "CVE-2023-5737" + ], + "details": "The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users with a role as low as Subscriber to update some plugin settings.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5737" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c761c67c-eab8-4e1b-a332-c9a45e22bb13" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-q5h6-hfv2-xr6w/GHSA-q5h6-hfv2-xr6w.json b/advisories/unreviewed/2023/11/GHSA-q5h6-hfv2-xr6w/GHSA-q5h6-hfv2-xr6w.json new file mode 100644 index 00000000000..0a954de7443 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-q5h6-hfv2-xr6w/GHSA-q5h6-hfv2-xr6w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5h6-hfv2-xr6w", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-41998" + ], + "details": "Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execute arbitrary files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41998" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/research/tra-2023-37" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-q5h7-rxc2-vj98/GHSA-q5h7-rxc2-vj98.json b/advisories/unreviewed/2023/11/GHSA-q5h7-rxc2-vj98/GHSA-q5h7-rxc2-vj98.json new file mode 100644 index 00000000000..edf28d94204 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-q5h7-rxc2-vj98/GHSA-q5h7-rxc2-vj98.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5h7-rxc2-vj98", + "modified": "2023-11-27T18:31:14Z", + "published": "2023-11-27T18:31:14Z", + "aliases": [ + "CVE-2023-5641" + ], + "details": "The Martins Free & Easy SEO BackLink Link Building Network WordPress plugin before 1.2.30 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5641" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c0a6c253-71f2-415d-a6ec-022f2eafc13b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-qfcq-5rf4-6g68/GHSA-qfcq-5rf4-6g68.json b/advisories/unreviewed/2023/11/GHSA-qfcq-5rf4-6g68/GHSA-qfcq-5rf4-6g68.json index 9e0825345ed..1ffd89c52df 100644 --- a/advisories/unreviewed/2023/11/GHSA-qfcq-5rf4-6g68/GHSA-qfcq-5rf4-6g68.json +++ b/advisories/unreviewed/2023/11/GHSA-qfcq-5rf4-6g68/GHSA-qfcq-5rf4-6g68.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qfcq-5rf4-6g68", - "modified": "2023-11-20T21:31:02Z", + "modified": "2023-11-27T18:31:12Z", "published": "2023-11-20T21:31:02Z", "aliases": [ "CVE-2023-4808" ], "details": "The WP Post Popup WordPress plugin through 3.7.3 does not sanitise and escape some of its inputs, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-20T19:15:09Z" diff --git a/advisories/unreviewed/2023/11/GHSA-qhh4-w7cp-9j2f/GHSA-qhh4-w7cp-9j2f.json b/advisories/unreviewed/2023/11/GHSA-qhh4-w7cp-9j2f/GHSA-qhh4-w7cp-9j2f.json index 4553e661eb2..9f482392789 100644 --- a/advisories/unreviewed/2023/11/GHSA-qhh4-w7cp-9j2f/GHSA-qhh4-w7cp-9j2f.json +++ b/advisories/unreviewed/2023/11/GHSA-qhh4-w7cp-9j2f/GHSA-qhh4-w7cp-9j2f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qhh4-w7cp-9j2f", - "modified": "2023-11-20T21:31:03Z", + "modified": "2023-11-27T18:31:12Z", "published": "2023-11-20T21:31:03Z", "aliases": [ "CVE-2023-5343" ], "details": "The Popup box WordPress plugin before 3.7.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-20T19:15:09Z" diff --git a/advisories/unreviewed/2023/11/GHSA-r4pf-qg69-h279/GHSA-r4pf-qg69-h279.json b/advisories/unreviewed/2023/11/GHSA-r4pf-qg69-h279/GHSA-r4pf-qg69-h279.json index 62923dd4aae..5731ccc0ccb 100644 --- a/advisories/unreviewed/2023/11/GHSA-r4pf-qg69-h279/GHSA-r4pf-qg69-h279.json +++ b/advisories/unreviewed/2023/11/GHSA-r4pf-qg69-h279/GHSA-r4pf-qg69-h279.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r4pf-qg69-h279", - "modified": "2023-11-20T21:31:03Z", + "modified": "2023-11-27T18:31:13Z", "published": "2023-11-20T21:31:03Z", "aliases": [ "CVE-2023-5799" ], "details": "The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing Contributor and above roles to delete posts that do no belong to them", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-20T19:15:10Z" diff --git a/advisories/unreviewed/2023/11/GHSA-rq8c-6g4c-3q78/GHSA-rq8c-6g4c-3q78.json b/advisories/unreviewed/2023/11/GHSA-rq8c-6g4c-3q78/GHSA-rq8c-6g4c-3q78.json new file mode 100644 index 00000000000..0584f5b5029 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-rq8c-6g4c-3q78/GHSA-rq8c-6g4c-3q78.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq8c-6g4c-3q78", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-4514" + ], + "details": "The Mmm Simple File List WordPress plugin through 2.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4514" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/365b15e6-3755-4ed5-badd-c9dd962bd9fa" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-v88m-92x2-qxm5/GHSA-v88m-92x2-qxm5.json b/advisories/unreviewed/2023/11/GHSA-v88m-92x2-qxm5/GHSA-v88m-92x2-qxm5.json index d5c94cb31d9..a21974bfeec 100644 --- a/advisories/unreviewed/2023/11/GHSA-v88m-92x2-qxm5/GHSA-v88m-92x2-qxm5.json +++ b/advisories/unreviewed/2023/11/GHSA-v88m-92x2-qxm5/GHSA-v88m-92x2-qxm5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v88m-92x2-qxm5", - "modified": "2023-11-20T21:31:03Z", + "modified": "2023-11-27T18:31:12Z", "published": "2023-11-20T21:31:03Z", "aliases": [ "CVE-2023-5340" ], "details": "The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perform PHP Object Injection when a suitable gadget is present on the blog.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-74" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-20T19:15:09Z" diff --git a/advisories/unreviewed/2023/11/GHSA-vpf6-j6mv-p249/GHSA-vpf6-j6mv-p249.json b/advisories/unreviewed/2023/11/GHSA-vpf6-j6mv-p249/GHSA-vpf6-j6mv-p249.json new file mode 100644 index 00000000000..77f4a3232b1 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-vpf6-j6mv-p249/GHSA-vpf6-j6mv-p249.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpf6-j6mv-p249", + "modified": "2023-11-27T18:31:14Z", + "published": "2023-11-27T18:31:14Z", + "aliases": [ + "CVE-2023-5620" + ], + "details": "The Web Push Notifications WordPress plugin before 4.35.0 does not prevent visitors on the site from changing some of the plugin options, some of which may be used to conduct Stored XSS attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5620" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/a03330c2-3ae0-404d-a114-33b18cc47666" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-vxxj-38m8-46gm/GHSA-vxxj-38m8-46gm.json b/advisories/unreviewed/2023/11/GHSA-vxxj-38m8-46gm/GHSA-vxxj-38m8-46gm.json new file mode 100644 index 00000000000..b0bf355f64c --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-vxxj-38m8-46gm/GHSA-vxxj-38m8-46gm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxxj-38m8-46gm", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-38573" + ], + "details": "A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles a signature field. A specially crafted Javascript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38573" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1839" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-x5r2-jq66-4ccq/GHSA-x5r2-jq66-4ccq.json b/advisories/unreviewed/2023/11/GHSA-x5r2-jq66-4ccq/GHSA-x5r2-jq66-4ccq.json new file mode 100644 index 00000000000..1d08c4f12dd --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-x5r2-jq66-4ccq/GHSA-x5r2-jq66-4ccq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5r2-jq66-4ccq", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-39542" + ], + "details": "A code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A specially crafted malformed file can create arbitrary files, which can lead to remote code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39542" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1832" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xg5j-3w2m-6rhx/GHSA-xg5j-3w2m-6rhx.json b/advisories/unreviewed/2023/11/GHSA-xg5j-3w2m-6rhx/GHSA-xg5j-3w2m-6rhx.json new file mode 100644 index 00000000000..606bdaa3c3d --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xg5j-3w2m-6rhx/GHSA-xg5j-3w2m-6rhx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg5j-3w2m-6rhx", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-5559" + ], + "details": "The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5559" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/eba46f7d-e4db-400c-8032-015f21087bbf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xh5j-9mr3-45mv/GHSA-xh5j-9mr3-45mv.json b/advisories/unreviewed/2023/11/GHSA-xh5j-9mr3-45mv/GHSA-xh5j-9mr3-45mv.json new file mode 100644 index 00000000000..49dcf1f7661 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xh5j-9mr3-45mv/GHSA-xh5j-9mr3-45mv.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh5j-9mr3-45mv", + "modified": "2023-11-27T18:31:13Z", + "published": "2023-11-27T18:31:13Z", + "aliases": [ + "CVE-2023-49029" + ], + "details": "Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitrary code via the nama parameter in the lock/lock.php file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49029" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Chiaki2333/717b83b800180e1a4c3ee5f6e49f95c0" + }, + { + "type": "WEB", + "url": "https://github.com/Chiaki2333/vulnerability/blob/main/smpn1smg-absis-XSS-lock.php-nama.md" + }, + { + "type": "WEB", + "url": "https://github.com/smpn1smg/absis" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xrp3-cvwg-fc64/GHSA-xrp3-cvwg-fc64.json b/advisories/unreviewed/2023/11/GHSA-xrp3-cvwg-fc64/GHSA-xrp3-cvwg-fc64.json new file mode 100644 index 00000000000..4e061baaef0 --- /dev/null +++ b/advisories/unreviewed/2023/11/GHSA-xrp3-cvwg-fc64/GHSA-xrp3-cvwg-fc64.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrp3-cvwg-fc64", + "modified": "2023-11-27T18:31:14Z", + "published": "2023-11-27T18:31:14Z", + "aliases": [ + "CVE-2023-5525" + ], + "details": "The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` AJAX action, allowing any user with a valid nonce to toggle the auto-update status of the plugin.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5525" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/654bad15-1c88-446a-b28b-5a412cc0399d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-11-27T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/11/GHSA-xvc2-6386-99x8/GHSA-xvc2-6386-99x8.json b/advisories/unreviewed/2023/11/GHSA-xvc2-6386-99x8/GHSA-xvc2-6386-99x8.json index 4dd5442ccb9..153c1bcb544 100644 --- a/advisories/unreviewed/2023/11/GHSA-xvc2-6386-99x8/GHSA-xvc2-6386-99x8.json +++ b/advisories/unreviewed/2023/11/GHSA-xvc2-6386-99x8/GHSA-xvc2-6386-99x8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xvc2-6386-99x8", - "modified": "2023-11-20T21:31:03Z", + "modified": "2023-11-27T18:31:12Z", "published": "2023-11-20T21:31:03Z", "aliases": [ "CVE-2023-5509" ], "details": "The myStickymenu WordPress plugin before 2.6.5 does not adequately authorize some ajax calls, allowing any logged-in user to perform the actions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-11-20T19:15:09Z"