From aaaae0d914a11673bda3e7b922075c2822592bda Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 11 Jul 2023 09:32:10 +0000 Subject: [PATCH] Publish Advisories GHSA-2p68-5cjx-px9g GHSA-368p-325h-g73p GHSA-3x6f-9g7f-wqvm GHSA-43wh-669h-5r23 GHSA-564x-7996-vpjv GHSA-5f99-wch4-5w2c GHSA-5frc-5hff-63hp GHSA-6v94-wxf8-92qh GHSA-8h69-jgr4-jvv3 GHSA-9wxg-5rf6-cr33 GHSA-fc54-jgr7-hvmx GHSA-g4gx-3833-vp8m GHSA-j567-3wwc-g5q2 GHSA-m55q-7qj6-v5m6 GHSA-m562-w2v4-chp8 GHSA-pggp-wpfc-2w3c GHSA-qmwh-f68f-3hfj GHSA-r35g-jc2r-7x2p GHSA-vcgf-cp2m-h8gw GHSA-x8x7-j36c-mp3c GHSA-xgh2-wjm9-43xj --- .../GHSA-2p68-5cjx-px9g.json | 38 +++++++++++++++++ .../GHSA-368p-325h-g73p.json | 38 +++++++++++++++++ .../GHSA-3x6f-9g7f-wqvm.json | 38 +++++++++++++++++ .../GHSA-43wh-669h-5r23.json | 38 +++++++++++++++++ .../GHSA-564x-7996-vpjv.json | 38 +++++++++++++++++ .../GHSA-5f99-wch4-5w2c.json | 42 +++++++++++++++++++ .../GHSA-5frc-5hff-63hp.json | 38 +++++++++++++++++ .../GHSA-6v94-wxf8-92qh.json | 38 +++++++++++++++++ .../GHSA-8h69-jgr4-jvv3.json | 38 +++++++++++++++++ .../GHSA-9wxg-5rf6-cr33.json | 38 +++++++++++++++++ .../GHSA-fc54-jgr7-hvmx.json | 38 +++++++++++++++++ .../GHSA-g4gx-3833-vp8m.json | 38 +++++++++++++++++ .../GHSA-j567-3wwc-g5q2.json | 38 +++++++++++++++++ .../GHSA-m55q-7qj6-v5m6.json | 38 +++++++++++++++++ .../GHSA-m562-w2v4-chp8.json | 42 +++++++++++++++++++ .../GHSA-pggp-wpfc-2w3c.json | 42 +++++++++++++++++++ .../GHSA-qmwh-f68f-3hfj.json | 38 +++++++++++++++++ .../GHSA-r35g-jc2r-7x2p.json | 38 +++++++++++++++++ .../GHSA-vcgf-cp2m-h8gw.json | 38 +++++++++++++++++ .../GHSA-x8x7-j36c-mp3c.json | 42 +++++++++++++++++++ .../GHSA-xgh2-wjm9-43xj.json | 38 +++++++++++++++++ 21 files changed, 814 insertions(+) create mode 100644 advisories/unreviewed/2023/07/GHSA-2p68-5cjx-px9g/GHSA-2p68-5cjx-px9g.json create mode 100644 advisories/unreviewed/2023/07/GHSA-368p-325h-g73p/GHSA-368p-325h-g73p.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3x6f-9g7f-wqvm/GHSA-3x6f-9g7f-wqvm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-43wh-669h-5r23/GHSA-43wh-669h-5r23.json create mode 100644 advisories/unreviewed/2023/07/GHSA-564x-7996-vpjv/GHSA-564x-7996-vpjv.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5f99-wch4-5w2c/GHSA-5f99-wch4-5w2c.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5frc-5hff-63hp/GHSA-5frc-5hff-63hp.json create mode 100644 advisories/unreviewed/2023/07/GHSA-6v94-wxf8-92qh/GHSA-6v94-wxf8-92qh.json create mode 100644 advisories/unreviewed/2023/07/GHSA-8h69-jgr4-jvv3/GHSA-8h69-jgr4-jvv3.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9wxg-5rf6-cr33/GHSA-9wxg-5rf6-cr33.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fc54-jgr7-hvmx/GHSA-fc54-jgr7-hvmx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-g4gx-3833-vp8m/GHSA-g4gx-3833-vp8m.json create mode 100644 advisories/unreviewed/2023/07/GHSA-j567-3wwc-g5q2/GHSA-j567-3wwc-g5q2.json create mode 100644 advisories/unreviewed/2023/07/GHSA-m55q-7qj6-v5m6/GHSA-m55q-7qj6-v5m6.json create mode 100644 advisories/unreviewed/2023/07/GHSA-m562-w2v4-chp8/GHSA-m562-w2v4-chp8.json create mode 100644 advisories/unreviewed/2023/07/GHSA-pggp-wpfc-2w3c/GHSA-pggp-wpfc-2w3c.json create mode 100644 advisories/unreviewed/2023/07/GHSA-qmwh-f68f-3hfj/GHSA-qmwh-f68f-3hfj.json create mode 100644 advisories/unreviewed/2023/07/GHSA-r35g-jc2r-7x2p/GHSA-r35g-jc2r-7x2p.json create mode 100644 advisories/unreviewed/2023/07/GHSA-vcgf-cp2m-h8gw/GHSA-vcgf-cp2m-h8gw.json create mode 100644 advisories/unreviewed/2023/07/GHSA-x8x7-j36c-mp3c/GHSA-x8x7-j36c-mp3c.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xgh2-wjm9-43xj/GHSA-xgh2-wjm9-43xj.json diff --git a/advisories/unreviewed/2023/07/GHSA-2p68-5cjx-px9g/GHSA-2p68-5cjx-px9g.json b/advisories/unreviewed/2023/07/GHSA-2p68-5cjx-px9g/GHSA-2p68-5cjx-px9g.json new file mode 100644 index 00000000000..fedea7f9608 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2p68-5cjx-px9g/GHSA-2p68-5cjx-px9g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2p68-5cjx-px9g", + "modified": "2023-07-11T09:30:39Z", + "published": "2023-07-11T09:30:39Z", + "aliases": [ + "CVE-2023-23704" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.6 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23704" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/comments-ratings/wordpress-comments-ratings-plugin-1-1-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-368p-325h-g73p/GHSA-368p-325h-g73p.json b/advisories/unreviewed/2023/07/GHSA-368p-325h-g73p/GHSA-368p-325h-g73p.json new file mode 100644 index 00000000000..29238a361df --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-368p-325h-g73p/GHSA-368p-325h-g73p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-368p-325h-g73p", + "modified": "2023-07-11T09:30:40Z", + "published": "2023-07-11T09:30:40Z", + "aliases": [ + "CVE-2023-25051" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Denishua Comment Reply Notification plugin <= 1.4 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25051" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/comment-reply-notification/wordpress-comment-reply-notification-plugin-1-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3x6f-9g7f-wqvm/GHSA-3x6f-9g7f-wqvm.json b/advisories/unreviewed/2023/07/GHSA-3x6f-9g7f-wqvm/GHSA-3x6f-9g7f-wqvm.json new file mode 100644 index 00000000000..39e469c3f6c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3x6f-9g7f-wqvm/GHSA-3x6f-9g7f-wqvm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x6f-9g7f-wqvm", + "modified": "2023-07-11T09:30:40Z", + "published": "2023-07-11T09:30:40Z", + "aliases": [ + "CVE-2023-35774" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in LWS LWS Tools plugin <= 2.4.1 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35774" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/lws-tools/wordpress-lws-tools-plugin-2-4-1-multiple-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-43wh-669h-5r23/GHSA-43wh-669h-5r23.json b/advisories/unreviewed/2023/07/GHSA-43wh-669h-5r23/GHSA-43wh-669h-5r23.json new file mode 100644 index 00000000000..3b9888b04e6 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-43wh-669h-5r23/GHSA-43wh-669h-5r23.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43wh-669h-5r23", + "modified": "2023-07-11T09:30:40Z", + "published": "2023-07-11T09:30:40Z", + "aliases": [ + "CVE-2023-25468" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Reservation.Studio Reservation.Studio widget plugin <= 1.0.11 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25468" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/reservation-studio-widget/wordpress-reservation-studio-widget-plugin-1-0-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-564x-7996-vpjv/GHSA-564x-7996-vpjv.json b/advisories/unreviewed/2023/07/GHSA-564x-7996-vpjv/GHSA-564x-7996-vpjv.json new file mode 100644 index 00000000000..f9f5c9c75cd --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-564x-7996-vpjv/GHSA-564x-7996-vpjv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-564x-7996-vpjv", + "modified": "2023-07-11T09:30:40Z", + "published": "2023-07-11T09:30:40Z", + "aliases": [ + "CVE-2023-35913" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in OOPSpam OOPSpam Anti-Spam plugin <= 1.1.44 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35913" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/oopspam-anti-spam/wordpress-oopspam-anti-spam-plugin-1-1-44-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5f99-wch4-5w2c/GHSA-5f99-wch4-5w2c.json b/advisories/unreviewed/2023/07/GHSA-5f99-wch4-5w2c/GHSA-5f99-wch4-5w2c.json new file mode 100644 index 00000000000..48dc3ba6b01 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5f99-wch4-5w2c/GHSA-5f99-wch4-5w2c.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f99-wch4-5w2c", + "modified": "2023-07-11T09:30:40Z", + "published": "2023-07-11T09:30:40Z", + "aliases": [ + "CVE-2023-31191" + ], + "details": "DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an information loss vulnerability through traffic injection.\n\nAn attacker can exploit this vulnerability by injecting, on carefully selected channels, high power spoofed Open Drone ID (ODID) messages which force the DroneScout ds230 Remote ID receiver to drop real Remote ID (RID) information and, instead, generate and transmit JSON encoded MQTT messages containing crafted RID information. Consequently, the MQTT broker, typically operated by a system integrator, will have no access to the drones’ real RID information.\n\nThis issue affects the adjacent channel suppression algorithm present in DroneScout ds230 firmware from version 20211210-1627 through 20230329-1042.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31191" + }, + { + "type": "WEB", + "url": "https://download.bluemark.io/dronescout/firmware/history.txt" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-31191/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-221" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5frc-5hff-63hp/GHSA-5frc-5hff-63hp.json b/advisories/unreviewed/2023/07/GHSA-5frc-5hff-63hp/GHSA-5frc-5hff-63hp.json new file mode 100644 index 00000000000..19057b12c28 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5frc-5hff-63hp/GHSA-5frc-5hff-63hp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5frc-5hff-63hp", + "modified": "2023-07-11T09:30:40Z", + "published": "2023-07-11T09:30:40Z", + "aliases": [ + "CVE-2023-36517" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.2 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36517" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-abstracts-manuscripts-manager/wordpress-wp-abstracts-plugin-2-6-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-6v94-wxf8-92qh/GHSA-6v94-wxf8-92qh.json b/advisories/unreviewed/2023/07/GHSA-6v94-wxf8-92qh/GHSA-6v94-wxf8-92qh.json new file mode 100644 index 00000000000..3fe268ba8a6 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-6v94-wxf8-92qh/GHSA-6v94-wxf8-92qh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v94-wxf8-92qh", + "modified": "2023-07-11T09:30:39Z", + "published": "2023-07-11T09:30:39Z", + "aliases": [ + "CVE-2023-23731" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in HasTheme WishSuite plugin <= 1.3.3 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23731" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wishsuite/wordpress-wishsuite-wishlist-for-woocommerce-plugin-1-3-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-8h69-jgr4-jvv3/GHSA-8h69-jgr4-jvv3.json b/advisories/unreviewed/2023/07/GHSA-8h69-jgr4-jvv3/GHSA-8h69-jgr4-jvv3.json new file mode 100644 index 00000000000..fc9bbd7f322 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-8h69-jgr4-jvv3/GHSA-8h69-jgr4-jvv3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h69-jgr4-jvv3", + "modified": "2023-07-11T09:30:40Z", + "published": "2023-07-11T09:30:40Z", + "aliases": [ + "CVE-2023-25487" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade PixTypes plugin <= 1.4.14 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25487" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/pixtypes/wordpress-pixtypes-plugin-1-4-14-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9wxg-5rf6-cr33/GHSA-9wxg-5rf6-cr33.json b/advisories/unreviewed/2023/07/GHSA-9wxg-5rf6-cr33/GHSA-9wxg-5rf6-cr33.json new file mode 100644 index 00000000000..54debe4b79d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9wxg-5rf6-cr33/GHSA-9wxg-5rf6-cr33.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wxg-5rf6-cr33", + "modified": "2023-07-11T09:30:39Z", + "published": "2023-07-11T09:30:39Z", + "aliases": [ + "CVE-2023-23791" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Menu plugin <= 1.2.1 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23791" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ht-menu-lite/wordpress-ht-menu-wordpress-mega-menu-builder-for-elementor-plugin-1-2-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fc54-jgr7-hvmx/GHSA-fc54-jgr7-hvmx.json b/advisories/unreviewed/2023/07/GHSA-fc54-jgr7-hvmx/GHSA-fc54-jgr7-hvmx.json new file mode 100644 index 00000000000..29ac167e421 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fc54-jgr7-hvmx/GHSA-fc54-jgr7-hvmx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc54-jgr7-hvmx", + "modified": "2023-07-11T09:30:40Z", + "published": "2023-07-11T09:30:40Z", + "aliases": [ + "CVE-2023-23777" + ], + "details": "An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.18 and below may allow a privileged attacker to execute arbitrary bash commands via crafted cli backup parameters.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23777" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-22-131" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-g4gx-3833-vp8m/GHSA-g4gx-3833-vp8m.json b/advisories/unreviewed/2023/07/GHSA-g4gx-3833-vp8m/GHSA-g4gx-3833-vp8m.json new file mode 100644 index 00000000000..e5f2ee38f03 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-g4gx-3833-vp8m/GHSA-g4gx-3833-vp8m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g4gx-3833-vp8m", + "modified": "2023-07-11T09:30:40Z", + "published": "2023-07-11T09:30:40Z", + "aliases": [ + "CVE-2023-34015" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in PI Websolution Conditional shipping & Advanced Flat rate shipping rates / Flexible shipping for WooCommerce shipping plugin <= 1.6.4.4 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34015" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/advanced-free-flat-shipping-woocommerce/wordpress-advanced-flat-rate-shipping-woocommerce-plugin-1-6-4-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-j567-3wwc-g5q2/GHSA-j567-3wwc-g5q2.json b/advisories/unreviewed/2023/07/GHSA-j567-3wwc-g5q2/GHSA-j567-3wwc-g5q2.json new file mode 100644 index 00000000000..9ef87ada3bb --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-j567-3wwc-g5q2/GHSA-j567-3wwc-g5q2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j567-3wwc-g5q2", + "modified": "2023-07-11T09:30:40Z", + "published": "2023-07-11T09:30:40Z", + "aliases": [ + "CVE-2023-35781" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in LWS Cleaner plugin <= 2.3.0 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35781" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/lws-cleaner/wordpress-lws-cleaner-plugin-2-3-0-multiple-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-m55q-7qj6-v5m6/GHSA-m55q-7qj6-v5m6.json b/advisories/unreviewed/2023/07/GHSA-m55q-7qj6-v5m6/GHSA-m55q-7qj6-v5m6.json new file mode 100644 index 00000000000..b4791ed1347 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-m55q-7qj6-v5m6/GHSA-m55q-7qj6-v5m6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m55q-7qj6-v5m6", + "modified": "2023-07-11T09:30:39Z", + "published": "2023-07-11T09:30:39Z", + "aliases": [ + "CVE-2022-45823" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in GalleryPlugins Video Contest WordPress plugin <= 3.2 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45823" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/video-contest/wordpress-video-contest-wordpress-plugin-plugin-3-2-cross-site-request-forgery-csrf?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-m562-w2v4-chp8/GHSA-m562-w2v4-chp8.json b/advisories/unreviewed/2023/07/GHSA-m562-w2v4-chp8/GHSA-m562-w2v4-chp8.json new file mode 100644 index 00000000000..60cd687e76b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-m562-w2v4-chp8/GHSA-m562-w2v4-chp8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m562-w2v4-chp8", + "modified": "2023-07-11T09:30:40Z", + "published": "2023-07-11T09:30:40Z", + "aliases": [ + "CVE-2023-31190" + ], + "details": "DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an Improper Authentication vulnerability during the firmware update procedure.\n\nSpecifically, the firmware update procedure ignores and does not check the validity of the TLS certificate of the HTTPS endpoint from which the firmware update package (.tar.bz2 file) is downloaded.\nAn attacker with the ability to put himself in a Man-in-the-Middle situation (e.g., DNS poisoning, ARP poisoning, control of a node on the route to the endpoint, etc.) can trick the DroneScout ds230 to install a crafted malicious firmware update containing arbitrary files (e.g., executable and configuration) and gain administrative (root) privileges on the underlying Linux operating system.\nThis issue affects DroneScout ds230 firmware from version 20211210-1627 through 20230329-1042.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31190" + }, + { + "type": "WEB", + "url": "https://download.bluemark.io/dronescout/firmware/history.txt" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-31190/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-pggp-wpfc-2w3c/GHSA-pggp-wpfc-2w3c.json b/advisories/unreviewed/2023/07/GHSA-pggp-wpfc-2w3c/GHSA-pggp-wpfc-2w3c.json new file mode 100644 index 00000000000..e325de7c4fc --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-pggp-wpfc-2w3c/GHSA-pggp-wpfc-2w3c.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pggp-wpfc-2w3c", + "modified": "2023-07-11T09:30:40Z", + "published": "2023-07-11T09:30:40Z", + "aliases": [ + "CVE-2023-29156" + ], + "details": "DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an information loss vulnerability through traffic injection.\nAn attacker can exploit this vulnerability by injecting, at the right times, spoofed Open Drone ID (ODID) messages which force the DroneScout ds230 Remote ID receiver to drop real Remote ID (RID) information and, instead, generate and transmit JSON encoded MQTT messages containing crafted RID information. Consequently, the MQTT broker, typically operated by a system integrator, will have no access to the drones’ real RID information.\n\nThis issue affects DroneScout ds230 in default configuration from firmware version 20211210-1627 through 20230329-1042.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29156" + }, + { + "type": "WEB", + "url": "https://download.bluemark.io/dronescout/firmware/history.txt" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-29156/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-221" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-qmwh-f68f-3hfj/GHSA-qmwh-f68f-3hfj.json b/advisories/unreviewed/2023/07/GHSA-qmwh-f68f-3hfj/GHSA-qmwh-f68f-3hfj.json new file mode 100644 index 00000000000..55ab219511e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-qmwh-f68f-3hfj/GHSA-qmwh-f68f-3hfj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmwh-f68f-3hfj", + "modified": "2023-07-11T09:30:40Z", + "published": "2023-07-11T09:30:40Z", + "aliases": [ + "CVE-2023-24421" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WP Engine PHP Compatibility Checker plugin <= 1.5.2 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24421" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/php-compatibility-checker/wordpress-php-compatibility-checker-plugin-1-5-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-r35g-jc2r-7x2p/GHSA-r35g-jc2r-7x2p.json b/advisories/unreviewed/2023/07/GHSA-r35g-jc2r-7x2p/GHSA-r35g-jc2r-7x2p.json new file mode 100644 index 00000000000..ae938e5c5da --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-r35g-jc2r-7x2p/GHSA-r35g-jc2r-7x2p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r35g-jc2r-7x2p", + "modified": "2023-07-11T09:30:39Z", + "published": "2023-07-11T09:30:39Z", + "aliases": [ + "CVE-2023-23803" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in HasThemes JustTables plugin <= 1.4.9 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23803" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/just-tables/wordpress-justtables-woocommerce-product-table-plugin-1-4-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-vcgf-cp2m-h8gw/GHSA-vcgf-cp2m-h8gw.json b/advisories/unreviewed/2023/07/GHSA-vcgf-cp2m-h8gw/GHSA-vcgf-cp2m-h8gw.json new file mode 100644 index 00000000000..1d5e925d237 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-vcgf-cp2m-h8gw/GHSA-vcgf-cp2m-h8gw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcgf-cp2m-h8gw", + "modified": "2023-07-11T09:30:40Z", + "published": "2023-07-11T09:30:40Z", + "aliases": [ + "CVE-2022-22302" + ], + "details": "A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 and 6.0.0 through 6.0.13 and FortiAuthenticator version 5.5.0 and all versions of 6.1 and 6.0 may allow a local unauthorized party to retrieve the Fortinet private keys used to establish secure communication with both Apple Push Notification and Google Cloud Messaging services, via accessing the files on the filesystem.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-22302" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-20-014" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-x8x7-j36c-mp3c/GHSA-x8x7-j36c-mp3c.json b/advisories/unreviewed/2023/07/GHSA-x8x7-j36c-mp3c/GHSA-x8x7-j36c-mp3c.json new file mode 100644 index 00000000000..71c1f6f5d6e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-x8x7-j36c-mp3c/GHSA-x8x7-j36c-mp3c.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x8x7-j36c-mp3c", + "modified": "2023-07-11T09:30:39Z", + "published": "2023-07-11T09:30:39Z", + "aliases": [ + "CVE-2023-1936" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to leak the email address of a user who created a service desk issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1936" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/1933829" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/405150" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xgh2-wjm9-43xj/GHSA-xgh2-wjm9-43xj.json b/advisories/unreviewed/2023/07/GHSA-xgh2-wjm9-43xj/GHSA-xgh2-wjm9-43xj.json new file mode 100644 index 00000000000..5609aed203d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xgh2-wjm9-43xj/GHSA-xgh2-wjm9-43xj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgh2-wjm9-43xj", + "modified": "2023-07-11T09:30:40Z", + "published": "2023-07-11T09:30:40Z", + "aliases": [ + "CVE-2023-23997" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Dave Jesch Database Collation Fix plugin <= 1.2.7 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23997" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/database-collation-fix/wordpress-database-collation-fix-plugin-1-2-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file