From a749fbef9230dbf2a9b656a9dd05b8f1e7ef8714 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 26 Jul 2024 03:32:12 +0000 Subject: [PATCH] Publish Advisories GHSA-78g2-8477-w94x GHSA-f2gm-j9fh-5jr9 GHSA-rvf2-p9hg-7mvf GHSA-whhx-238v-wr87 --- .../GHSA-78g2-8477-w94x.json | 54 +++++++++++++++++++ .../GHSA-f2gm-j9fh-5jr9.json | 54 +++++++++++++++++++ .../GHSA-rvf2-p9hg-7mvf.json | 54 +++++++++++++++++++ .../GHSA-whhx-238v-wr87.json | 38 +++++++++++++ 4 files changed, 200 insertions(+) create mode 100644 advisories/unreviewed/2024/07/GHSA-78g2-8477-w94x/GHSA-78g2-8477-w94x.json create mode 100644 advisories/unreviewed/2024/07/GHSA-f2gm-j9fh-5jr9/GHSA-f2gm-j9fh-5jr9.json create mode 100644 advisories/unreviewed/2024/07/GHSA-rvf2-p9hg-7mvf/GHSA-rvf2-p9hg-7mvf.json create mode 100644 advisories/unreviewed/2024/07/GHSA-whhx-238v-wr87/GHSA-whhx-238v-wr87.json diff --git a/advisories/unreviewed/2024/07/GHSA-78g2-8477-w94x/GHSA-78g2-8477-w94x.json b/advisories/unreviewed/2024/07/GHSA-78g2-8477-w94x/GHSA-78g2-8477-w94x.json new file mode 100644 index 00000000000..4219ab8c49d --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-78g2-8477-w94x/GHSA-78g2-8477-w94x.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78g2-8477-w94x", + "modified": "2024-07-26T03:30:46Z", + "published": "2024-07-26T03:30:46Z", + "aliases": [ + "CVE-2024-7114" + ], + "details": "A vulnerability was found in Tianchoy Blog up to 1.8.8. It has been classified as critical. This affects an unknown part of the file /so.php. The manipulation of the argument search leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272445 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7114" + }, + { + "type": "WEB", + "url": "https://github.com/topsky979/Security-Collections/tree/main/cve5" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.272445" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.272445" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.376851" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-26T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-f2gm-j9fh-5jr9/GHSA-f2gm-j9fh-5jr9.json b/advisories/unreviewed/2024/07/GHSA-f2gm-j9fh-5jr9/GHSA-f2gm-j9fh-5jr9.json new file mode 100644 index 00000000000..158e7d30614 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-f2gm-j9fh-5jr9/GHSA-f2gm-j9fh-5jr9.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2gm-j9fh-5jr9", + "modified": "2024-07-26T03:30:47Z", + "published": "2024-07-26T03:30:46Z", + "aliases": [ + "CVE-2024-7116" + ], + "details": "A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It has been rated as critical. This issue affects some unknown processing of the file /branch_viewmore.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The associated identifier of this vulnerability is VDB-272447. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7116" + }, + { + "type": "WEB", + "url": "https://github.com/topsky979/Security-Collections/tree/main/cve7" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.272447" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.272447" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.376887" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-26T03:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-rvf2-p9hg-7mvf/GHSA-rvf2-p9hg-7mvf.json b/advisories/unreviewed/2024/07/GHSA-rvf2-p9hg-7mvf/GHSA-rvf2-p9hg-7mvf.json new file mode 100644 index 00000000000..60b23daaebb --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-rvf2-p9hg-7mvf/GHSA-rvf2-p9hg-7mvf.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvf2-p9hg-7mvf", + "modified": "2024-07-26T03:30:46Z", + "published": "2024-07-26T03:30:46Z", + "aliases": [ + "CVE-2024-7115" + ], + "details": "A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It has been declared as critical. This vulnerability affects unknown code of the file /designation_viewmore.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. VDB-272446 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7115" + }, + { + "type": "WEB", + "url": "https://github.com/topsky979/Security-Collections/tree/main/cve6" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.272446" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.272446" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.376885" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-26T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-whhx-238v-wr87/GHSA-whhx-238v-wr87.json b/advisories/unreviewed/2024/07/GHSA-whhx-238v-wr87/GHSA-whhx-238v-wr87.json new file mode 100644 index 00000000000..6740ee0e661 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-whhx-238v-wr87/GHSA-whhx-238v-wr87.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whhx-238v-wr87", + "modified": "2024-07-26T03:30:46Z", + "published": "2024-07-26T03:30:46Z", + "aliases": [ + "CVE-2024-4447" + ], + "details": "In the System → Maintenance tool, the Logged Users tab surfaces sessionId data for all users via the Direct Web Remoting API (UserSessionAjax.getSessionList.dwr) calls. While this is information that would and should be available to admins who possess \"Sign In As\" powers, admins who otherwise lack this privilege would still be able to utilize the session IDs to imitate other users.\n\n\nWhile this is a very small attack vector that requires very high permissions to execute, its danger lies principally in obfuscating attribution; all Sign In As operations are attributed appropriately in the log files, and a malicious administrator could use this information to render their dealings untraceable — including those admins who have not been granted this ability — such as by using a session ID to generate an API token.\n\nFixed in: 24.07.12 / 23.01.20 LTS / 23.10.24v13 LTS / 24.04.24v5 LTS", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4447" + }, + { + "type": "WEB", + "url": "https://auth.dotcms.com/security/SI-72" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-26T02:15:10Z" + } +} \ No newline at end of file