diff --git a/advisories/unreviewed/2024/03/GHSA-2vf8-hmhp-gw9x/GHSA-2vf8-hmhp-gw9x.json b/advisories/unreviewed/2024/03/GHSA-2vf8-hmhp-gw9x/GHSA-2vf8-hmhp-gw9x.json index 122e9b2717b..f3e7f220610 100644 --- a/advisories/unreviewed/2024/03/GHSA-2vf8-hmhp-gw9x/GHSA-2vf8-hmhp-gw9x.json +++ b/advisories/unreviewed/2024/03/GHSA-2vf8-hmhp-gw9x/GHSA-2vf8-hmhp-gw9x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2vf8-hmhp-gw9x", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-10-27T15:30:43Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23293" ], "details": "This issue was addressed through improved state management. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An attacker with physical access may be able to use Siri to access sensitive user data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:50Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7j2j-w9w6-4cg9/GHSA-7j2j-w9w6-4cg9.json b/advisories/unreviewed/2024/03/GHSA-7j2j-w9w6-4cg9/GHSA-7j2j-w9w6-4cg9.json index 1e70746d9f4..9276e6693ce 100644 --- a/advisories/unreviewed/2024/03/GHSA-7j2j-w9w6-4cg9/GHSA-7j2j-w9w6-4cg9.json +++ b/advisories/unreviewed/2024/03/GHSA-7j2j-w9w6-4cg9/GHSA-7j2j-w9w6-4cg9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7j2j-w9w6-4cg9", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-10-27T15:30:43Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23283" ], "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to access user-sensitive data.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-ggwq-65m4-2gf3/GHSA-ggwq-65m4-2gf3.json b/advisories/unreviewed/2024/03/GHSA-ggwq-65m4-2gf3/GHSA-ggwq-65m4-2gf3.json index a46977b4b07..a4d8f172ee1 100644 --- a/advisories/unreviewed/2024/03/GHSA-ggwq-65m4-2gf3/GHSA-ggwq-65m4-2gf3.json +++ b/advisories/unreviewed/2024/03/GHSA-ggwq-65m4-2gf3/GHSA-ggwq-65m4-2gf3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ggwq-65m4-2gf3", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-10-27T15:30:43Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23297" ], "details": "The issue was addressed with improved checks. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, watchOS 10.4. A malicious application may be able to access private information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:50Z" diff --git a/advisories/unreviewed/2024/03/GHSA-x7v5-rxwv-mpjw/GHSA-x7v5-rxwv-mpjw.json b/advisories/unreviewed/2024/03/GHSA-x7v5-rxwv-mpjw/GHSA-x7v5-rxwv-mpjw.json index 640add654d4..64d4e28df0a 100644 --- a/advisories/unreviewed/2024/03/GHSA-x7v5-rxwv-mpjw/GHSA-x7v5-rxwv-mpjw.json +++ b/advisories/unreviewed/2024/03/GHSA-x7v5-rxwv-mpjw/GHSA-x7v5-rxwv-mpjw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x7v5-rxwv-mpjw", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-10-27T15:30:43Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23295" ], "details": "A permissions issue was addressed to help ensure Personas are always protected This issue is fixed in visionOS 1.1. An unauthenticated user may be able to use an unprotected Persona.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:50Z" diff --git a/advisories/unreviewed/2024/04/GHSA-58mp-9hhc-gwv9/GHSA-58mp-9hhc-gwv9.json b/advisories/unreviewed/2024/04/GHSA-58mp-9hhc-gwv9/GHSA-58mp-9hhc-gwv9.json index 9592ff6f5f8..7d1f108a1d0 100644 --- a/advisories/unreviewed/2024/04/GHSA-58mp-9hhc-gwv9/GHSA-58mp-9hhc-gwv9.json +++ b/advisories/unreviewed/2024/04/GHSA-58mp-9hhc-gwv9/GHSA-58mp-9hhc-gwv9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-58mp-9hhc-gwv9", - "modified": "2024-04-08T03:30:53Z", + "modified": "2024-10-27T15:30:43Z", "published": "2024-04-08T03:30:53Z", "aliases": [ "CVE-2024-23658" ], "details": "In camera driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T03:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-h2wx-vrp7-wvmw/GHSA-h2wx-vrp7-wvmw.json b/advisories/unreviewed/2024/05/GHSA-h2wx-vrp7-wvmw/GHSA-h2wx-vrp7-wvmw.json index 66db080efbd..34100d7776b 100644 --- a/advisories/unreviewed/2024/05/GHSA-h2wx-vrp7-wvmw/GHSA-h2wx-vrp7-wvmw.json +++ b/advisories/unreviewed/2024/05/GHSA-h2wx-vrp7-wvmw/GHSA-h2wx-vrp7-wvmw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h2wx-vrp7-wvmw", - "modified": "2024-05-19T09:34:46Z", + "modified": "2024-10-27T15:30:43Z", "published": "2024-05-19T09:34:46Z", "aliases": [ "CVE-2024-35870" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix UAF in smb2_reconnect_server()\n\nThe UAF bug is due to smb2_reconnect_server() accessing a session that\nis already being teared down by another thread that is executing\n__cifs_put_smb_ses(). This can happen when (a) the client has\nconnection to the server but no session or (b) another thread ends up\nsetting @ses->ses_status again to something different than\nSES_EXITING.\n\nTo fix this, we need to make sure to unconditionally set\n@ses->ses_status to SES_EXITING and prevent any other threads from\nsetting a new status while we're still tearing it down.\n\nThe following can be reproduced by adding some delay to right after\nthe ipc is freed in __cifs_put_smb_ses() - which will give\nsmb2_reconnect_server() worker a chance to run and then accessing\n@ses->ipc:\n\nkinit ...\nmount.cifs //srv/share /mnt/1 -o sec=krb5,nohandlecache,echo_interval=10\n[disconnect srv]\nls /mnt/1 &>/dev/null\nsleep 30\nkdestroy\n[reconnect srv]\nsleep 10\numount /mnt/1\n...\nCIFS: VFS: Verify user has a krb5 ticket and keyutils is installed\nCIFS: VFS: \\\\srv Send error in SessSetup = -126\nCIFS: VFS: Verify user has a krb5 ticket and keyutils is installed\nCIFS: VFS: \\\\srv Send error in SessSetup = -126\ngeneral protection fault, probably for non-canonical address\n0x6b6b6b6b6b6b6b6b: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 3 PID: 50 Comm: kworker/3:1 Not tainted 6.9.0-rc2 #1\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-1.fc39\n04/01/2014\nWorkqueue: cifsiod smb2_reconnect_server [cifs]\nRIP: 0010:__list_del_entry_valid_or_report+0x33/0xf0\nCode: 4f 08 48 85 d2 74 42 48 85 c9 74 59 48 b8 00 01 00 00 00 00 ad\nde 48 39 c2 74 61 48 b8 22 01 00 00 00 00 74 69 <48> 8b 01 48 39 f8 75\n7b 48 8b 72 08 48 39 c6 0f 85 88 00 00 00 b8\nRSP: 0018:ffffc900001bfd70 EFLAGS: 00010a83\nRAX: dead000000000122 RBX: ffff88810da53838 RCX: 6b6b6b6b6b6b6b6b\nRDX: 6b6b6b6b6b6b6b6b RSI: ffffffffc02f6878 RDI: ffff88810da53800\nRBP: ffff88810da53800 R08: 0000000000000001 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000001 R12: ffff88810c064000\nR13: 0000000000000001 R14: ffff88810c064000 R15: ffff8881039cc000\nFS: 0000000000000000(0000) GS:ffff888157c00000(0000)\nknlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007fe3728b1000 CR3: 000000010caa4000 CR4: 0000000000750ef0\nPKRU: 55555554\nCall Trace:\n \n ? die_addr+0x36/0x90\n ? exc_general_protection+0x1c1/0x3f0\n ? asm_exc_general_protection+0x26/0x30\n ? __list_del_entry_valid_or_report+0x33/0xf0\n __cifs_put_smb_ses+0x1ae/0x500 [cifs]\n smb2_reconnect_server+0x4ed/0x710 [cifs]\n process_one_work+0x205/0x6b0\n worker_thread+0x191/0x360\n ? __pfx_worker_thread+0x10/0x10\n kthread+0xe2/0x110\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x34/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n ", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-19T09:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-x6vg-gvf6-hmp9/GHSA-x6vg-gvf6-hmp9.json b/advisories/unreviewed/2024/05/GHSA-x6vg-gvf6-hmp9/GHSA-x6vg-gvf6-hmp9.json index 77c54a1edce..23f28400e29 100644 --- a/advisories/unreviewed/2024/05/GHSA-x6vg-gvf6-hmp9/GHSA-x6vg-gvf6-hmp9.json +++ b/advisories/unreviewed/2024/05/GHSA-x6vg-gvf6-hmp9/GHSA-x6vg-gvf6-hmp9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x6vg-gvf6-hmp9", - "modified": "2024-05-21T15:31:44Z", + "modified": "2024-10-27T15:30:43Z", "published": "2024-05-21T15:31:44Z", "aliases": [ "CVE-2021-47375" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblktrace: Fix uaf in blk_trace access after removing by sysfs\n\nThere is an use-after-free problem triggered by following process:\n\n P1(sda)\t\t\t\tP2(sdb)\n\t\t\techo 0 > /sys/block/sdb/trace/enable\n\t\t\t blk_trace_remove_queue\n\t\t\t synchronize_rcu\n\t\t\t blk_trace_free\n\t\t\t relay_close\nrcu_read_lock\n__blk_add_trace\n trace_note_tsk\n (Iterate running_trace_list)\n\t\t\t relay_close_buf\n\t\t\t\t relay_destroy_buf\n\t\t\t\t kfree(buf)\n trace_note(sdb's bt)\n relay_reserve\n buf->offset <- nullptr deference (use-after-free) !!!\nrcu_read_unlock\n\n[ 502.714379] BUG: kernel NULL pointer dereference, address:\n0000000000000010\n[ 502.715260] #PF: supervisor read access in kernel mode\n[ 502.715903] #PF: error_code(0x0000) - not-present page\n[ 502.716546] PGD 103984067 P4D 103984067 PUD 17592b067 PMD 0\n[ 502.717252] Oops: 0000 [#1] SMP\n[ 502.720308] RIP: 0010:trace_note.isra.0+0x86/0x360\n[ 502.732872] Call Trace:\n[ 502.733193] __blk_add_trace.cold+0x137/0x1a3\n[ 502.733734] blk_add_trace_rq+0x7b/0xd0\n[ 502.734207] blk_add_trace_rq_issue+0x54/0xa0\n[ 502.734755] blk_mq_start_request+0xde/0x1b0\n[ 502.735287] scsi_queue_rq+0x528/0x1140\n...\n[ 502.742704] sg_new_write.isra.0+0x16e/0x3e0\n[ 502.747501] sg_ioctl+0x466/0x1100\n\nReproduce method:\n ioctl(/dev/sda, BLKTRACESETUP, blk_user_trace_setup[buf_size=127])\n ioctl(/dev/sda, BLKTRACESTART)\n ioctl(/dev/sdb, BLKTRACESETUP, blk_user_trace_setup[buf_size=127])\n ioctl(/dev/sdb, BLKTRACESTART)\n\n echo 0 > /sys/block/sdb/trace/enable &\n // Add delay(mdelay/msleep) before kernel enters blk_trace_free()\n\n ioctl$SG_IO(/dev/sda, SG_IO, ...)\n // Enters trace_note_tsk() after blk_trace_free() returned\n // Use mdelay in rcu region rather than msleep(which may schedule out)\n\nRemove blk_trace from running_list before calling blk_trace_free() by\nsysfs if blk_trace is at Blktrace_running state.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:23Z" diff --git a/advisories/unreviewed/2024/07/GHSA-wvw3-cj3j-fc6w/GHSA-wvw3-cj3j-fc6w.json b/advisories/unreviewed/2024/07/GHSA-wvw3-cj3j-fc6w/GHSA-wvw3-cj3j-fc6w.json index e935433ef2a..b1037663fee 100644 --- a/advisories/unreviewed/2024/07/GHSA-wvw3-cj3j-fc6w/GHSA-wvw3-cj3j-fc6w.json +++ b/advisories/unreviewed/2024/07/GHSA-wvw3-cj3j-fc6w/GHSA-wvw3-cj3j-fc6w.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-367" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-9gw4-m84r-cgxj/GHSA-9gw4-m84r-cgxj.json b/advisories/unreviewed/2024/10/GHSA-9gw4-m84r-cgxj/GHSA-9gw4-m84r-cgxj.json new file mode 100644 index 00000000000..03819e1ad67 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9gw4-m84r-cgxj/GHSA-9gw4-m84r-cgxj.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gw4-m84r-cgxj", + "modified": "2024-10-27T15:30:43Z", + "published": "2024-10-27T15:30:43Z", + "aliases": [ + "CVE-2024-10418" + ], + "details": "A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /file/infoAdd.php. The manipulation of the argument bg leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10418" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://gist.github.com/higordiego/25a103a1fe84c4db4530e68d2f998d11" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.281959" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.281959" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.431782" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-27T14:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9xjq-9p64-px3q/GHSA-9xjq-9p64-px3q.json b/advisories/unreviewed/2024/10/GHSA-9xjq-9p64-px3q/GHSA-9xjq-9p64-px3q.json new file mode 100644 index 00000000000..9c2c8a6f572 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9xjq-9p64-px3q/GHSA-9xjq-9p64-px3q.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xjq-9p64-px3q", + "modified": "2024-10-27T15:30:43Z", + "published": "2024-10-27T15:30:43Z", + "aliases": [ + "CVE-2024-10417" + ], + "details": "A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /file/delete.php. The manipulation of the argument bid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10417" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://gist.github.com/higordiego/bf0cf963ec56cfe0dcaba2956352bafd" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.281958" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.281958" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.431781" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-27T13:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fr6r-4pjc-5pwj/GHSA-fr6r-4pjc-5pwj.json b/advisories/unreviewed/2024/10/GHSA-fr6r-4pjc-5pwj/GHSA-fr6r-4pjc-5pwj.json new file mode 100644 index 00000000000..3f9abc15387 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fr6r-4pjc-5pwj/GHSA-fr6r-4pjc-5pwj.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr6r-4pjc-5pwj", + "modified": "2024-10-27T15:30:43Z", + "published": "2024-10-27T15:30:43Z", + "aliases": [ + "CVE-2024-10416" + ], + "details": "A vulnerability was found in code-projects Blood Bank Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /file/cancel.php. The manipulation of the argument reqid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10416" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://gist.github.com/higordiego/18cf04067697c8ceb2cba68980139dcc" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.281957" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.281957" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.431686" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-27T13:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qmc7-2p7g-4x4p/GHSA-qmc7-2p7g-4x4p.json b/advisories/unreviewed/2024/10/GHSA-qmc7-2p7g-4x4p/GHSA-qmc7-2p7g-4x4p.json new file mode 100644 index 00000000000..ef4afde98e2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qmc7-2p7g-4x4p/GHSA-qmc7-2p7g-4x4p.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmc7-2p7g-4x4p", + "modified": "2024-10-27T15:30:43Z", + "published": "2024-10-27T15:30:43Z", + "aliases": [ + "CVE-2024-10419" + ], + "details": "A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /bloodrequest.php. The manipulation of the argument msg leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10419" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://gist.github.com/higordiego/62ad5208270c67834d02818d6ba44126" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.281960" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.281960" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.431784" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-27T15:15:02Z" + } +} \ No newline at end of file