From afdb8eafa4d9c176ad7c390812b46556e767834e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 19 Jul 2024 21:33:08 +0000 Subject: [PATCH] Publish Advisories GHSA-cvfx-wfgc-g5xw GHSA-hq4f-mv3q-8wcv GHSA-47mc-qmh2-mqj4 GHSA-8hrw-qmjc-qr28 GHSA-9f75-gjv3-f63r GHSA-h8w3-xwp6-m9v8 GHSA-j22r-3rf3-cv25 GHSA-j53r-x8pp-944v GHSA-p9gv-wf2w-7v75 GHSA-qw47-q6g9-7mxw GHSA-r9vw-cjf9-xh4x GHSA-rm36-22xp-2grj GHSA-wgpq-79rc-3fgg --- .../GHSA-cvfx-wfgc-g5xw.json | 3 +- .../GHSA-hq4f-mv3q-8wcv.json | 11 +++--- .../GHSA-47mc-qmh2-mqj4.json | 35 +++++++++++++++++++ .../GHSA-8hrw-qmjc-qr28.json | 11 +++--- .../GHSA-9f75-gjv3-f63r.json | 35 +++++++++++++++++++ .../GHSA-h8w3-xwp6-m9v8.json | 11 +++--- .../GHSA-j22r-3rf3-cv25.json | 35 +++++++++++++++++++ .../GHSA-j53r-x8pp-944v.json | 9 +++-- .../GHSA-p9gv-wf2w-7v75.json | 9 +++-- .../GHSA-qw47-q6g9-7mxw.json | 11 +++--- .../GHSA-r9vw-cjf9-xh4x.json | 35 +++++++++++++++++++ .../GHSA-rm36-22xp-2grj.json | 11 +++--- .../GHSA-wgpq-79rc-3fgg.json | 2 +- 13 files changed, 190 insertions(+), 28 deletions(-) create mode 100644 advisories/unreviewed/2024/07/GHSA-47mc-qmh2-mqj4/GHSA-47mc-qmh2-mqj4.json create mode 100644 advisories/unreviewed/2024/07/GHSA-9f75-gjv3-f63r/GHSA-9f75-gjv3-f63r.json create mode 100644 advisories/unreviewed/2024/07/GHSA-j22r-3rf3-cv25/GHSA-j22r-3rf3-cv25.json create mode 100644 advisories/unreviewed/2024/07/GHSA-r9vw-cjf9-xh4x/GHSA-r9vw-cjf9-xh4x.json diff --git a/advisories/unreviewed/2024/06/GHSA-cvfx-wfgc-g5xw/GHSA-cvfx-wfgc-g5xw.json b/advisories/unreviewed/2024/06/GHSA-cvfx-wfgc-g5xw/GHSA-cvfx-wfgc-g5xw.json index 5f73ea86f0d..925f169e40b 100644 --- a/advisories/unreviewed/2024/06/GHSA-cvfx-wfgc-g5xw/GHSA-cvfx-wfgc-g5xw.json +++ b/advisories/unreviewed/2024/06/GHSA-cvfx-wfgc-g5xw/GHSA-cvfx-wfgc-g5xw.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-261" + "CWE-261", + "CWE-326" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-hq4f-mv3q-8wcv/GHSA-hq4f-mv3q-8wcv.json b/advisories/unreviewed/2024/06/GHSA-hq4f-mv3q-8wcv/GHSA-hq4f-mv3q-8wcv.json index da6312b9f3f..e48d47cd7cc 100644 --- a/advisories/unreviewed/2024/06/GHSA-hq4f-mv3q-8wcv/GHSA-hq4f-mv3q-8wcv.json +++ b/advisories/unreviewed/2024/06/GHSA-hq4f-mv3q-8wcv/GHSA-hq4f-mv3q-8wcv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hq4f-mv3q-8wcv", - "modified": "2024-06-25T21:31:17Z", + "modified": "2024-07-19T21:31:10Z", "published": "2024-06-25T21:31:17Z", "aliases": [ "CVE-2024-37843" ], "details": "Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T21:15:59Z" diff --git a/advisories/unreviewed/2024/07/GHSA-47mc-qmh2-mqj4/GHSA-47mc-qmh2-mqj4.json b/advisories/unreviewed/2024/07/GHSA-47mc-qmh2-mqj4/GHSA-47mc-qmh2-mqj4.json new file mode 100644 index 00000000000..11f0a290057 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-47mc-qmh2-mqj4/GHSA-47mc-qmh2-mqj4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47mc-qmh2-mqj4", + "modified": "2024-07-19T21:31:11Z", + "published": "2024-07-19T21:31:11Z", + "aliases": [ + "CVE-2024-40400" + ], + "details": "An arbitrary file upload vulnerability in the image upload function of Automad v2.0.0 allows attackers to execute arbitrary code via a crafted file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40400" + }, + { + "type": "WEB", + "url": "https://github.com/marcantondahmen/automad/issues/106" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-19T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8hrw-qmjc-qr28/GHSA-8hrw-qmjc-qr28.json b/advisories/unreviewed/2024/07/GHSA-8hrw-qmjc-qr28/GHSA-8hrw-qmjc-qr28.json index fa40a7c9eff..76629f4d132 100644 --- a/advisories/unreviewed/2024/07/GHSA-8hrw-qmjc-qr28/GHSA-8hrw-qmjc-qr28.json +++ b/advisories/unreviewed/2024/07/GHSA-8hrw-qmjc-qr28/GHSA-8hrw-qmjc-qr28.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8hrw-qmjc-qr28", - "modified": "2024-07-16T18:31:42Z", + "modified": "2024-07-19T21:31:10Z", "published": "2024-07-16T18:31:42Z", "aliases": [ "CVE-2024-33182" ], "details": "Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/addWifiMacFilter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T16:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-9f75-gjv3-f63r/GHSA-9f75-gjv3-f63r.json b/advisories/unreviewed/2024/07/GHSA-9f75-gjv3-f63r/GHSA-9f75-gjv3-f63r.json new file mode 100644 index 00000000000..223961bcd60 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-9f75-gjv3-f63r/GHSA-9f75-gjv3-f63r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f75-gjv3-f63r", + "modified": "2024-07-19T21:31:11Z", + "published": "2024-07-19T21:31:11Z", + "aliases": [ + "CVE-2024-41599" + ], + "details": "Cross Site Scripting vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the file upload method", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41599" + }, + { + "type": "WEB", + "url": "https://github.com/topsky979/Security-Collections/tree/main/CVE-2024-41599" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-19T20:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-h8w3-xwp6-m9v8/GHSA-h8w3-xwp6-m9v8.json b/advisories/unreviewed/2024/07/GHSA-h8w3-xwp6-m9v8/GHSA-h8w3-xwp6-m9v8.json index 733988aa1fb..5706ff335f4 100644 --- a/advisories/unreviewed/2024/07/GHSA-h8w3-xwp6-m9v8/GHSA-h8w3-xwp6-m9v8.json +++ b/advisories/unreviewed/2024/07/GHSA-h8w3-xwp6-m9v8/GHSA-h8w3-xwp6-m9v8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h8w3-xwp6-m9v8", - "modified": "2024-07-19T06:31:13Z", + "modified": "2024-07-19T21:31:10Z", "published": "2024-07-19T06:31:13Z", "aliases": [ "CVE-2024-6205" ], "details": "The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement via a WooCommerce API route available to unauthenticated users, leading to an SQL injection vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-19T06:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-j22r-3rf3-cv25/GHSA-j22r-3rf3-cv25.json b/advisories/unreviewed/2024/07/GHSA-j22r-3rf3-cv25/GHSA-j22r-3rf3-cv25.json new file mode 100644 index 00000000000..06b6e67e9ad --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-j22r-3rf3-cv25/GHSA-j22r-3rf3-cv25.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j22r-3rf3-cv25", + "modified": "2024-07-19T21:31:11Z", + "published": "2024-07-19T21:31:11Z", + "aliases": [ + "CVE-2024-39123" + ], + "details": "In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39123" + }, + { + "type": "WEB", + "url": "https://github.com/pentesttoolscom/vulnerability-research/tree/master/CVE-2024-39123" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-19T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-j53r-x8pp-944v/GHSA-j53r-x8pp-944v.json b/advisories/unreviewed/2024/07/GHSA-j53r-x8pp-944v/GHSA-j53r-x8pp-944v.json index 53966bc6150..5d87aaff086 100644 --- a/advisories/unreviewed/2024/07/GHSA-j53r-x8pp-944v/GHSA-j53r-x8pp-944v.json +++ b/advisories/unreviewed/2024/07/GHSA-j53r-x8pp-944v/GHSA-j53r-x8pp-944v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j53r-x8pp-944v", - "modified": "2024-07-10T09:30:38Z", + "modified": "2024-07-19T21:31:10Z", "published": "2024-07-09T18:30:49Z", "aliases": [ "CVE-2024-26279" ], "details": "Inadequate content filtering leads to XSS vulnerabilities in various components.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-09T17:15:15Z" diff --git a/advisories/unreviewed/2024/07/GHSA-p9gv-wf2w-7v75/GHSA-p9gv-wf2w-7v75.json b/advisories/unreviewed/2024/07/GHSA-p9gv-wf2w-7v75/GHSA-p9gv-wf2w-7v75.json index c6e3cc41975..4f1bc007a94 100644 --- a/advisories/unreviewed/2024/07/GHSA-p9gv-wf2w-7v75/GHSA-p9gv-wf2w-7v75.json +++ b/advisories/unreviewed/2024/07/GHSA-p9gv-wf2w-7v75/GHSA-p9gv-wf2w-7v75.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p9gv-wf2w-7v75", - "modified": "2024-07-09T18:30:49Z", + "modified": "2024-07-19T21:31:10Z", "published": "2024-07-09T18:30:49Z", "aliases": [ "CVE-2024-26278" ], "details": "The Custom Fields component not correctly filter inputs, leading to a XSS vector.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-09T17:15:14Z" diff --git a/advisories/unreviewed/2024/07/GHSA-qw47-q6g9-7mxw/GHSA-qw47-q6g9-7mxw.json b/advisories/unreviewed/2024/07/GHSA-qw47-q6g9-7mxw/GHSA-qw47-q6g9-7mxw.json index 07bc9f1d307..bd9d4f85947 100644 --- a/advisories/unreviewed/2024/07/GHSA-qw47-q6g9-7mxw/GHSA-qw47-q6g9-7mxw.json +++ b/advisories/unreviewed/2024/07/GHSA-qw47-q6g9-7mxw/GHSA-qw47-q6g9-7mxw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qw47-q6g9-7mxw", - "modified": "2024-07-16T18:31:42Z", + "modified": "2024-07-19T21:31:10Z", "published": "2024-07-16T18:31:42Z", "aliases": [ "CVE-2024-35338" ], "details": "Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T16:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-r9vw-cjf9-xh4x/GHSA-r9vw-cjf9-xh4x.json b/advisories/unreviewed/2024/07/GHSA-r9vw-cjf9-xh4x/GHSA-r9vw-cjf9-xh4x.json new file mode 100644 index 00000000000..d41f8fbcaed --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-r9vw-cjf9-xh4x/GHSA-r9vw-cjf9-xh4x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9vw-cjf9-xh4x", + "modified": "2024-07-19T21:31:11Z", + "published": "2024-07-19T21:31:11Z", + "aliases": [ + "CVE-2024-41597" + ], + "details": "Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to execute arbitrary code via a crafted HTML file to the comments functionality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41597" + }, + { + "type": "WEB", + "url": "https://gist.github.com/DefensiumDevelopers/608be4d10b016dce0566925368a8b08c#file-cve-2024-41597-md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-19T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-rm36-22xp-2grj/GHSA-rm36-22xp-2grj.json b/advisories/unreviewed/2024/07/GHSA-rm36-22xp-2grj/GHSA-rm36-22xp-2grj.json index b541c34ebf9..fb8dd28b1a7 100644 --- a/advisories/unreviewed/2024/07/GHSA-rm36-22xp-2grj/GHSA-rm36-22xp-2grj.json +++ b/advisories/unreviewed/2024/07/GHSA-rm36-22xp-2grj/GHSA-rm36-22xp-2grj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rm36-22xp-2grj", - "modified": "2024-07-16T18:31:42Z", + "modified": "2024-07-19T21:31:10Z", "published": "2024-07-16T18:31:42Z", "aliases": [ "CVE-2024-33180" ], "details": "Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/saveParentControlInfo.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T16:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-wgpq-79rc-3fgg/GHSA-wgpq-79rc-3fgg.json b/advisories/unreviewed/2024/07/GHSA-wgpq-79rc-3fgg/GHSA-wgpq-79rc-3fgg.json index e38c09466a4..47b58e6355a 100644 --- a/advisories/unreviewed/2024/07/GHSA-wgpq-79rc-3fgg/GHSA-wgpq-79rc-3fgg.json +++ b/advisories/unreviewed/2024/07/GHSA-wgpq-79rc-3fgg/GHSA-wgpq-79rc-3fgg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wgpq-79rc-3fgg", - "modified": "2024-07-19T09:32:06Z", + "modified": "2024-07-19T21:31:10Z", "published": "2024-07-19T09:32:06Z", "aliases": [ "CVE-2024-6338"