From b31a0570744099f14cc13a26e1f1411fa1530cd3 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 27 Sep 2024 21:32:51 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-445x-hw57-f2q2.json | 3 +- .../GHSA-6cv5-8fpc-p4rh.json | 3 +- .../GHSA-6rv3-82jq-3r4c.json | 1 + .../GHSA-h45c-25x4-6qq4.json | 5 +- .../GHSA-hfj7-fpwh-q5vg.json | 5 +- .../GHSA-qv3q-cwv9-r3m3.json | 1 + .../GHSA-vxmm-5m8g-5p2c.json | 3 +- .../GHSA-2wv3-fgjg-gj5w.json | 3 +- .../GHSA-f4wc-3qj8-gq9p.json | 3 +- .../GHSA-4jmv-jvrv-qcv7.json | 5 +- .../GHSA-wc73-qprf-6fv8.json | 3 +- .../GHSA-frh8-6qgg-hm8v.json | 5 +- .../GHSA-897p-22v6-2j5g.json | 3 +- .../GHSA-2xvh-27wv-vhhr.json | 42 ++++++++++++++ .../GHSA-3c7c-8hj4-v9qh.json | 38 ++++++++++++ .../GHSA-3xv2-v2hj-2crv.json | 2 +- .../GHSA-5hm7-x82q-99rh.json | 6 +- .../GHSA-6363-r5pj-4jm8.json | 2 +- .../GHSA-6mcf-rv8f-r9jf.json | 42 ++++++++++++++ .../GHSA-6p38-qv63-r35w.json | 11 ++-- .../GHSA-75mf-739r-c359.json | 11 ++-- .../GHSA-8hgr-rp5m-j4mg.json | 1 + .../GHSA-c4g6-rrx2-j7rm.json | 2 +- .../GHSA-c8ff-57f4-9r7c.json | 35 +++++++++++ .../GHSA-cwpw-7c39-pv7m.json | 11 ++-- .../GHSA-fqgj-hf47-9p78.json | 2 +- .../GHSA-fr4x-3m2g-jm28.json | 2 +- .../GHSA-g2f6-cxmc-24cj.json | 38 ++++++++++++ .../GHSA-g9g7-rmqc-4q4p.json | 11 ++-- .../GHSA-gr4h-g2ph-j8j2.json | 2 +- .../GHSA-gx3x-w926-g8pm.json | 2 +- .../GHSA-hq46-f53r-2cxj.json | 2 +- .../GHSA-jwxr-qpg5-2pj9.json | 11 ++-- .../GHSA-p7pw-3rg9-hpxm.json | 3 +- .../GHSA-qfqv-x56x-5p3g.json | 58 +++++++++++++++++++ .../GHSA-qv98-75v6-5rhf.json | 2 +- .../GHSA-w8pf-f5g8-5xgv.json | 2 +- .../GHSA-wqc2-gwgp-9p7w.json | 11 ++-- .../GHSA-wwq9-rfhf-r6h9.json | 11 ++-- .../GHSA-xv6j-rwrm-mgqv.json | 54 +++++++++++++++++ 40 files changed, 402 insertions(+), 55 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-2xvh-27wv-vhhr/GHSA-2xvh-27wv-vhhr.json create mode 100644 advisories/unreviewed/2024/09/GHSA-3c7c-8hj4-v9qh/GHSA-3c7c-8hj4-v9qh.json create mode 100644 advisories/unreviewed/2024/09/GHSA-6mcf-rv8f-r9jf/GHSA-6mcf-rv8f-r9jf.json create mode 100644 advisories/unreviewed/2024/09/GHSA-c8ff-57f4-9r7c/GHSA-c8ff-57f4-9r7c.json create mode 100644 advisories/unreviewed/2024/09/GHSA-g2f6-cxmc-24cj/GHSA-g2f6-cxmc-24cj.json create mode 100644 advisories/unreviewed/2024/09/GHSA-qfqv-x56x-5p3g/GHSA-qfqv-x56x-5p3g.json create mode 100644 advisories/unreviewed/2024/09/GHSA-xv6j-rwrm-mgqv/GHSA-xv6j-rwrm-mgqv.json diff --git a/advisories/unreviewed/2023/08/GHSA-445x-hw57-f2q2/GHSA-445x-hw57-f2q2.json b/advisories/unreviewed/2023/08/GHSA-445x-hw57-f2q2/GHSA-445x-hw57-f2q2.json index 0b9d8b42922..060ce16cc7b 100644 --- a/advisories/unreviewed/2023/08/GHSA-445x-hw57-f2q2/GHSA-445x-hw57-f2q2.json +++ b/advisories/unreviewed/2023/08/GHSA-445x-hw57-f2q2/GHSA-445x-hw57-f2q2.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-449" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-6cv5-8fpc-p4rh/GHSA-6cv5-8fpc-p4rh.json b/advisories/unreviewed/2023/08/GHSA-6cv5-8fpc-p4rh/GHSA-6cv5-8fpc-p4rh.json index a1da3fe5ede..16aab802a30 100644 --- a/advisories/unreviewed/2023/08/GHSA-6cv5-8fpc-p4rh/GHSA-6cv5-8fpc-p4rh.json +++ b/advisories/unreviewed/2023/08/GHSA-6cv5-8fpc-p4rh/GHSA-6cv5-8fpc-p4rh.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-80" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-6rv3-82jq-3r4c/GHSA-6rv3-82jq-3r4c.json b/advisories/unreviewed/2023/08/GHSA-6rv3-82jq-3r4c/GHSA-6rv3-82jq-3r4c.json index 1e96081c541..6a8ad591eec 100644 --- a/advisories/unreviewed/2023/08/GHSA-6rv3-82jq-3r4c/GHSA-6rv3-82jq-3r4c.json +++ b/advisories/unreviewed/2023/08/GHSA-6rv3-82jq-3r4c/GHSA-6rv3-82jq-3r4c.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-176", "CWE-74" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/08/GHSA-h45c-25x4-6qq4/GHSA-h45c-25x4-6qq4.json b/advisories/unreviewed/2023/08/GHSA-h45c-25x4-6qq4/GHSA-h45c-25x4-6qq4.json index 5d27f964d3b..c3df989a733 100644 --- a/advisories/unreviewed/2023/08/GHSA-h45c-25x4-6qq4/GHSA-h45c-25x4-6qq4.json +++ b/advisories/unreviewed/2023/08/GHSA-h45c-25x4-6qq4/GHSA-h45c-25x4-6qq4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h45c-25x4-6qq4", - "modified": "2024-04-04T06:42:54Z", + "modified": "2024-09-27T21:31:45Z", "published": "2023-08-08T18:30:37Z", "aliases": [ "CVE-2023-39217" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-80" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-hfj7-fpwh-q5vg/GHSA-hfj7-fpwh-q5vg.json b/advisories/unreviewed/2023/08/GHSA-hfj7-fpwh-q5vg/GHSA-hfj7-fpwh-q5vg.json index 6777ed71a12..41d90b7db77 100644 --- a/advisories/unreviewed/2023/08/GHSA-hfj7-fpwh-q5vg/GHSA-hfj7-fpwh-q5vg.json +++ b/advisories/unreviewed/2023/08/GHSA-hfj7-fpwh-q5vg/GHSA-hfj7-fpwh-q5vg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hfj7-fpwh-q5vg", - "modified": "2023-12-14T18:30:18Z", + "modified": "2024-09-27T21:31:45Z", "published": "2023-08-09T00:31:57Z", "aliases": [ "CVE-2023-39214" @@ -29,7 +29,8 @@ "database_specific": { "cwe_ids": [ "CWE-200", - "CWE-668" + "CWE-668", + "CWE-749" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/08/GHSA-qv3q-cwv9-r3m3/GHSA-qv3q-cwv9-r3m3.json b/advisories/unreviewed/2023/08/GHSA-qv3q-cwv9-r3m3/GHSA-qv3q-cwv9-r3m3.json index 86942f58341..9e0a65aaf6a 100644 --- a/advisories/unreviewed/2023/08/GHSA-qv3q-cwv9-r3m3/GHSA-qv3q-cwv9-r3m3.json +++ b/advisories/unreviewed/2023/08/GHSA-qv3q-cwv9-r3m3/GHSA-qv3q-cwv9-r3m3.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-449", "CWE-602" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/08/GHSA-vxmm-5m8g-5p2c/GHSA-vxmm-5m8g-5p2c.json b/advisories/unreviewed/2023/08/GHSA-vxmm-5m8g-5p2c/GHSA-vxmm-5m8g-5p2c.json index c76197699a9..b27d5701b3c 100644 --- a/advisories/unreviewed/2023/08/GHSA-vxmm-5m8g-5p2c/GHSA-vxmm-5m8g-5p2c.json +++ b/advisories/unreviewed/2023/08/GHSA-vxmm-5m8g-5p2c/GHSA-vxmm-5m8g-5p2c.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-347" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-2wv3-fgjg-gj5w/GHSA-2wv3-fgjg-gj5w.json b/advisories/unreviewed/2023/09/GHSA-2wv3-fgjg-gj5w/GHSA-2wv3-fgjg-gj5w.json index ff276e74111..f007bdde603 100644 --- a/advisories/unreviewed/2023/09/GHSA-2wv3-fgjg-gj5w/GHSA-2wv3-fgjg-gj5w.json +++ b/advisories/unreviewed/2023/09/GHSA-2wv3-fgjg-gj5w/GHSA-2wv3-fgjg-gj5w.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/09/GHSA-f4wc-3qj8-gq9p/GHSA-f4wc-3qj8-gq9p.json b/advisories/unreviewed/2023/09/GHSA-f4wc-3qj8-gq9p/GHSA-f4wc-3qj8-gq9p.json index c27ef88e4e3..4d41826d715 100644 --- a/advisories/unreviewed/2023/09/GHSA-f4wc-3qj8-gq9p/GHSA-f4wc-3qj8-gq9p.json +++ b/advisories/unreviewed/2023/09/GHSA-f4wc-3qj8-gq9p/GHSA-f4wc-3qj8-gq9p.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-449" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-4jmv-jvrv-qcv7/GHSA-4jmv-jvrv-qcv7.json b/advisories/unreviewed/2023/11/GHSA-4jmv-jvrv-qcv7/GHSA-4jmv-jvrv-qcv7.json index 309789072b1..6b7cefa1405 100644 --- a/advisories/unreviewed/2023/11/GHSA-4jmv-jvrv-qcv7/GHSA-4jmv-jvrv-qcv7.json +++ b/advisories/unreviewed/2023/11/GHSA-4jmv-jvrv-qcv7/GHSA-4jmv-jvrv-qcv7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4jmv-jvrv-qcv7", - "modified": "2023-11-15T00:31:07Z", + "modified": "2024-09-27T21:31:45Z", "published": "2023-11-15T00:31:07Z", "aliases": [ "CVE-2023-39203" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-789" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-wc73-qprf-6fv8/GHSA-wc73-qprf-6fv8.json b/advisories/unreviewed/2023/11/GHSA-wc73-qprf-6fv8/GHSA-wc73-qprf-6fv8.json index 81f7e2ed974..08d51bb9949 100644 --- a/advisories/unreviewed/2023/11/GHSA-wc73-qprf-6fv8/GHSA-wc73-qprf-6fv8.json +++ b/advisories/unreviewed/2023/11/GHSA-wc73-qprf-6fv8/GHSA-wc73-qprf-6fv8.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-280" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-frh8-6qgg-hm8v/GHSA-frh8-6qgg-hm8v.json b/advisories/unreviewed/2023/12/GHSA-frh8-6qgg-hm8v/GHSA-frh8-6qgg-hm8v.json index 254534706f4..0c0d6af5deb 100644 --- a/advisories/unreviewed/2023/12/GHSA-frh8-6qgg-hm8v/GHSA-frh8-6qgg-hm8v.json +++ b/advisories/unreviewed/2023/12/GHSA-frh8-6qgg-hm8v/GHSA-frh8-6qgg-hm8v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-frh8-6qgg-hm8v", - "modified": "2023-12-14T00:30:26Z", + "modified": "2024-09-27T21:31:45Z", "published": "2023-12-14T00:30:26Z", "aliases": [ "CVE-2023-43585" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-449" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-897p-22v6-2j5g/GHSA-897p-22v6-2j5g.json b/advisories/unreviewed/2024/02/GHSA-897p-22v6-2j5g/GHSA-897p-22v6-2j5g.json index 06d4c63d338..d2695ba6253 100644 --- a/advisories/unreviewed/2024/02/GHSA-897p-22v6-2j5g/GHSA-897p-22v6-2j5g.json +++ b/advisories/unreviewed/2024/02/GHSA-897p-22v6-2j5g/GHSA-897p-22v6-2j5g.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-449" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-2xvh-27wv-vhhr/GHSA-2xvh-27wv-vhhr.json b/advisories/unreviewed/2024/09/GHSA-2xvh-27wv-vhhr/GHSA-2xvh-27wv-vhhr.json new file mode 100644 index 00000000000..beb133fc970 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-2xvh-27wv-vhhr/GHSA-2xvh-27wv-vhhr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xvh-27wv-vhhr", + "modified": "2024-09-27T21:31:50Z", + "published": "2024-09-27T21:31:50Z", + "aliases": [ + "CVE-2024-33368" + ], + "details": "An issue in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the build method in DonwloadPromptScreen", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33368" + }, + { + "type": "WEB", + "url": "https://gist.github.com/apple502j/54e0f80bfe082fd934e33970394adbb8" + }, + { + "type": "WEB", + "url": "https://github.com/plasmoapp/RPShare" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3c7c-8hj4-v9qh/GHSA-3c7c-8hj4-v9qh.json b/advisories/unreviewed/2024/09/GHSA-3c7c-8hj4-v9qh/GHSA-3c7c-8hj4-v9qh.json new file mode 100644 index 00000000000..e2e1859b4fd --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3c7c-8hj4-v9qh/GHSA-3c7c-8hj4-v9qh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c7c-8hj4-v9qh", + "modified": "2024-09-27T21:31:50Z", + "published": "2024-09-27T21:31:50Z", + "aliases": [ + "CVE-2024-9160" + ], + "details": "In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9160" + }, + { + "type": "WEB", + "url": "https://portal.perforce.com/s/detail/a91PA000001SXN3YAO" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3xv2-v2hj-2crv/GHSA-3xv2-v2hj-2crv.json b/advisories/unreviewed/2024/09/GHSA-3xv2-v2hj-2crv/GHSA-3xv2-v2hj-2crv.json index b092ce34108..329c6011cad 100644 --- a/advisories/unreviewed/2024/09/GHSA-3xv2-v2hj-2crv/GHSA-3xv2-v2hj-2crv.json +++ b/advisories/unreviewed/2024/09/GHSA-3xv2-v2hj-2crv/GHSA-3xv2-v2hj-2crv.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-5hm7-x82q-99rh/GHSA-5hm7-x82q-99rh.json b/advisories/unreviewed/2024/09/GHSA-5hm7-x82q-99rh/GHSA-5hm7-x82q-99rh.json index 3ed21aae894..a19e405f8d6 100644 --- a/advisories/unreviewed/2024/09/GHSA-5hm7-x82q-99rh/GHSA-5hm7-x82q-99rh.json +++ b/advisories/unreviewed/2024/09/GHSA-5hm7-x82q-99rh/GHSA-5hm7-x82q-99rh.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5hm7-x82q-99rh", - "modified": "2024-09-10T09:31:12Z", + "modified": "2024-09-27T21:31:49Z", "published": "2024-09-10T09:31:12Z", "aliases": [ "CVE-2024-8258" ], "details": "Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code via insecure Electron Fuses configuration.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-6363-r5pj-4jm8/GHSA-6363-r5pj-4jm8.json b/advisories/unreviewed/2024/09/GHSA-6363-r5pj-4jm8/GHSA-6363-r5pj-4jm8.json index f1c757f035d..e1862d96cf5 100644 --- a/advisories/unreviewed/2024/09/GHSA-6363-r5pj-4jm8/GHSA-6363-r5pj-4jm8.json +++ b/advisories/unreviewed/2024/09/GHSA-6363-r5pj-4jm8/GHSA-6363-r5pj-4jm8.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-6mcf-rv8f-r9jf/GHSA-6mcf-rv8f-r9jf.json b/advisories/unreviewed/2024/09/GHSA-6mcf-rv8f-r9jf/GHSA-6mcf-rv8f-r9jf.json new file mode 100644 index 00000000000..100cdb0ad2e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6mcf-rv8f-r9jf/GHSA-6mcf-rv8f-r9jf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mcf-rv8f-r9jf", + "modified": "2024-09-27T21:31:50Z", + "published": "2024-09-27T21:31:50Z", + "aliases": [ + "CVE-2024-33369" + ], + "details": "Directory Traversal vulnerability in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the getFileNameFromConnection method in DownloadTask", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33369" + }, + { + "type": "WEB", + "url": "https://gist.github.com/apple502j/54e0f80bfe082fd934e33970394adbb8" + }, + { + "type": "WEB", + "url": "https://github.com/plasmoapp/RPShare" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6p38-qv63-r35w/GHSA-6p38-qv63-r35w.json b/advisories/unreviewed/2024/09/GHSA-6p38-qv63-r35w/GHSA-6p38-qv63-r35w.json index 088871ead30..3a10eb59d26 100644 --- a/advisories/unreviewed/2024/09/GHSA-6p38-qv63-r35w/GHSA-6p38-qv63-r35w.json +++ b/advisories/unreviewed/2024/09/GHSA-6p38-qv63-r35w/GHSA-6p38-qv63-r35w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6p38-qv63-r35w", - "modified": "2024-09-27T00:31:04Z", + "modified": "2024-09-27T21:31:49Z", "published": "2024-09-27T00:31:04Z", "aliases": [ "CVE-2024-40507" ], "details": "Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMPersonnel.asmx function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-26T22:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-75mf-739r-c359/GHSA-75mf-739r-c359.json b/advisories/unreviewed/2024/09/GHSA-75mf-739r-c359/GHSA-75mf-739r-c359.json index 78d4f95e5e6..b02c390986d 100644 --- a/advisories/unreviewed/2024/09/GHSA-75mf-739r-c359/GHSA-75mf-739r-c359.json +++ b/advisories/unreviewed/2024/09/GHSA-75mf-739r-c359/GHSA-75mf-739r-c359.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-75mf-739r-c359", - "modified": "2024-09-27T00:31:04Z", + "modified": "2024-09-27T21:31:49Z", "published": "2024-09-27T00:31:04Z", "aliases": [ "CVE-2024-40508" ], "details": "Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMConference.asmx function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-26T22:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-8hgr-rp5m-j4mg/GHSA-8hgr-rp5m-j4mg.json b/advisories/unreviewed/2024/09/GHSA-8hgr-rp5m-j4mg/GHSA-8hgr-rp5m-j4mg.json index 35255bcf07b..20950be88f2 100644 --- a/advisories/unreviewed/2024/09/GHSA-8hgr-rp5m-j4mg/GHSA-8hgr-rp5m-j4mg.json +++ b/advisories/unreviewed/2024/09/GHSA-8hgr-rp5m-j4mg/GHSA-8hgr-rp5m-j4mg.json @@ -36,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-312", "CWE-313" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-c4g6-rrx2-j7rm/GHSA-c4g6-rrx2-j7rm.json b/advisories/unreviewed/2024/09/GHSA-c4g6-rrx2-j7rm/GHSA-c4g6-rrx2-j7rm.json index c7fecf40c28..0e6e35eafa2 100644 --- a/advisories/unreviewed/2024/09/GHSA-c4g6-rrx2-j7rm/GHSA-c4g6-rrx2-j7rm.json +++ b/advisories/unreviewed/2024/09/GHSA-c4g6-rrx2-j7rm/GHSA-c4g6-rrx2-j7rm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c4g6-rrx2-j7rm", - "modified": "2024-09-10T09:31:12Z", + "modified": "2024-09-27T21:31:48Z", "published": "2024-09-10T09:31:12Z", "aliases": [ "CVE-2024-43392" diff --git a/advisories/unreviewed/2024/09/GHSA-c8ff-57f4-9r7c/GHSA-c8ff-57f4-9r7c.json b/advisories/unreviewed/2024/09/GHSA-c8ff-57f4-9r7c/GHSA-c8ff-57f4-9r7c.json new file mode 100644 index 00000000000..aa180b4690f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c8ff-57f4-9r7c/GHSA-c8ff-57f4-9r7c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8ff-57f4-9r7c", + "modified": "2024-09-27T21:31:50Z", + "published": "2024-09-27T21:31:50Z", + "aliases": [ + "CVE-2024-46453" + ], + "details": "A cross-site scripting (XSS) vulnerability in the component /test/ of iq3xcite v2.31 to v3.05 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46453" + }, + { + "type": "WEB", + "url": "https://github.com/nosmo-gla/iq3xcite-XSS-2.31-3.05/tree/main" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T21:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cwpw-7c39-pv7m/GHSA-cwpw-7c39-pv7m.json b/advisories/unreviewed/2024/09/GHSA-cwpw-7c39-pv7m/GHSA-cwpw-7c39-pv7m.json index 1db5e3a8856..a3987c7bd56 100644 --- a/advisories/unreviewed/2024/09/GHSA-cwpw-7c39-pv7m/GHSA-cwpw-7c39-pv7m.json +++ b/advisories/unreviewed/2024/09/GHSA-cwpw-7c39-pv7m/GHSA-cwpw-7c39-pv7m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cwpw-7c39-pv7m", - "modified": "2024-09-27T00:31:04Z", + "modified": "2024-09-27T21:31:49Z", "published": "2024-09-27T00:31:04Z", "aliases": [ "CVE-2024-40506" ], "details": "Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMHospitality.asmx function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-26T22:15:03Z" diff --git a/advisories/unreviewed/2024/09/GHSA-fqgj-hf47-9p78/GHSA-fqgj-hf47-9p78.json b/advisories/unreviewed/2024/09/GHSA-fqgj-hf47-9p78/GHSA-fqgj-hf47-9p78.json index 1d21b23a4ee..60a3ceeb39e 100644 --- a/advisories/unreviewed/2024/09/GHSA-fqgj-hf47-9p78/GHSA-fqgj-hf47-9p78.json +++ b/advisories/unreviewed/2024/09/GHSA-fqgj-hf47-9p78/GHSA-fqgj-hf47-9p78.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fqgj-hf47-9p78", - "modified": "2024-09-10T09:31:12Z", + "modified": "2024-09-27T21:31:48Z", "published": "2024-09-10T09:31:12Z", "aliases": [ "CVE-2024-43391" diff --git a/advisories/unreviewed/2024/09/GHSA-fr4x-3m2g-jm28/GHSA-fr4x-3m2g-jm28.json b/advisories/unreviewed/2024/09/GHSA-fr4x-3m2g-jm28/GHSA-fr4x-3m2g-jm28.json index d9b309e1b3e..43bae241605 100644 --- a/advisories/unreviewed/2024/09/GHSA-fr4x-3m2g-jm28/GHSA-fr4x-3m2g-jm28.json +++ b/advisories/unreviewed/2024/09/GHSA-fr4x-3m2g-jm28/GHSA-fr4x-3m2g-jm28.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-g2f6-cxmc-24cj/GHSA-g2f6-cxmc-24cj.json b/advisories/unreviewed/2024/09/GHSA-g2f6-cxmc-24cj/GHSA-g2f6-cxmc-24cj.json new file mode 100644 index 00000000000..0b8ad127efa --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g2f6-cxmc-24cj/GHSA-g2f6-cxmc-24cj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2f6-cxmc-24cj", + "modified": "2024-09-27T21:31:50Z", + "published": "2024-09-27T21:31:50Z", + "aliases": [ + "CVE-2024-6436" + ], + "details": "An input validation vulnerability exists in the Rockwell Automation Sequence Managerâ„¢ which could allow a malicious user to send malformed packets to the server and cause a denial-of-service condition. If exploited, the device would become unresponsive, and a manual restart will be required for recovery. Additionally, if exploited, there could be a loss of view for the downstream equipment sequences in the controller. Users would not be able to view the status or command the equipment sequences, however the equipment sequence would continue to execute uninterrupted.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6436" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1679.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T20:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g9g7-rmqc-4q4p/GHSA-g9g7-rmqc-4q4p.json b/advisories/unreviewed/2024/09/GHSA-g9g7-rmqc-4q4p/GHSA-g9g7-rmqc-4q4p.json index 4a32de7db66..6d73bf563f8 100644 --- a/advisories/unreviewed/2024/09/GHSA-g9g7-rmqc-4q4p/GHSA-g9g7-rmqc-4q4p.json +++ b/advisories/unreviewed/2024/09/GHSA-g9g7-rmqc-4q4p/GHSA-g9g7-rmqc-4q4p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g9g7-rmqc-4q4p", - "modified": "2024-09-27T18:32:26Z", + "modified": "2024-09-27T21:31:50Z", "published": "2024-09-27T18:32:26Z", "aliases": [ "CVE-2024-25411" ], "details": "A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter in setup.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T18:15:04Z" diff --git a/advisories/unreviewed/2024/09/GHSA-gr4h-g2ph-j8j2/GHSA-gr4h-g2ph-j8j2.json b/advisories/unreviewed/2024/09/GHSA-gr4h-g2ph-j8j2/GHSA-gr4h-g2ph-j8j2.json index cd358ae8a2a..5d20db6b82e 100644 --- a/advisories/unreviewed/2024/09/GHSA-gr4h-g2ph-j8j2/GHSA-gr4h-g2ph-j8j2.json +++ b/advisories/unreviewed/2024/09/GHSA-gr4h-g2ph-j8j2/GHSA-gr4h-g2ph-j8j2.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-gx3x-w926-g8pm/GHSA-gx3x-w926-g8pm.json b/advisories/unreviewed/2024/09/GHSA-gx3x-w926-g8pm/GHSA-gx3x-w926-g8pm.json index aeb9ceca80c..b2321f2999d 100644 --- a/advisories/unreviewed/2024/09/GHSA-gx3x-w926-g8pm/GHSA-gx3x-w926-g8pm.json +++ b/advisories/unreviewed/2024/09/GHSA-gx3x-w926-g8pm/GHSA-gx3x-w926-g8pm.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-hq46-f53r-2cxj/GHSA-hq46-f53r-2cxj.json b/advisories/unreviewed/2024/09/GHSA-hq46-f53r-2cxj/GHSA-hq46-f53r-2cxj.json index 32d8692e5fc..2f510b06282 100644 --- a/advisories/unreviewed/2024/09/GHSA-hq46-f53r-2cxj/GHSA-hq46-f53r-2cxj.json +++ b/advisories/unreviewed/2024/09/GHSA-hq46-f53r-2cxj/GHSA-hq46-f53r-2cxj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hq46-f53r-2cxj", - "modified": "2024-09-10T09:31:12Z", + "modified": "2024-09-27T21:31:46Z", "published": "2024-09-10T09:31:12Z", "aliases": [ "CVE-2024-43386" diff --git a/advisories/unreviewed/2024/09/GHSA-jwxr-qpg5-2pj9/GHSA-jwxr-qpg5-2pj9.json b/advisories/unreviewed/2024/09/GHSA-jwxr-qpg5-2pj9/GHSA-jwxr-qpg5-2pj9.json index f607a8f09ba..a38b6f54fa6 100644 --- a/advisories/unreviewed/2024/09/GHSA-jwxr-qpg5-2pj9/GHSA-jwxr-qpg5-2pj9.json +++ b/advisories/unreviewed/2024/09/GHSA-jwxr-qpg5-2pj9/GHSA-jwxr-qpg5-2pj9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jwxr-qpg5-2pj9", - "modified": "2024-09-27T18:32:26Z", + "modified": "2024-09-27T21:31:50Z", "published": "2024-09-27T18:32:26Z", "aliases": [ "CVE-2024-46367" ], "details": "A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T17:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-p7pw-3rg9-hpxm/GHSA-p7pw-3rg9-hpxm.json b/advisories/unreviewed/2024/09/GHSA-p7pw-3rg9-hpxm/GHSA-p7pw-3rg9-hpxm.json index b9bcd50dae8..1fcfaa13464 100644 --- a/advisories/unreviewed/2024/09/GHSA-p7pw-3rg9-hpxm/GHSA-p7pw-3rg9-hpxm.json +++ b/advisories/unreviewed/2024/09/GHSA-p7pw-3rg9-hpxm/GHSA-p7pw-3rg9-hpxm.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-qfqv-x56x-5p3g/GHSA-qfqv-x56x-5p3g.json b/advisories/unreviewed/2024/09/GHSA-qfqv-x56x-5p3g/GHSA-qfqv-x56x-5p3g.json new file mode 100644 index 00000000000..7d2f4e8d204 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qfqv-x56x-5p3g/GHSA-qfqv-x56x-5p3g.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfqv-x56x-5p3g", + "modified": "2024-09-27T21:31:50Z", + "published": "2024-09-27T21:31:50Z", + "aliases": [ + "CVE-2024-9291" + ], + "details": "A vulnerability classified as problematic has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff. Affected is an unknown function of the file /ueditor/upload?configPath=ueditor/config.json&action=uploadfile of the component XML File Handler. The manipulation of the argument upfile leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The GitHub repository of the project did not receive an update for more than two years.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9291" + }, + { + "type": "WEB", + "url": "https://github.com/daxiangya/kvf-admin/issues/1" + }, + { + "type": "WEB", + "url": "https://github.com/user-attachments/files/17058501/kvf-admin_xss.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.278784" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.278784" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.411202" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T21:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qv98-75v6-5rhf/GHSA-qv98-75v6-5rhf.json b/advisories/unreviewed/2024/09/GHSA-qv98-75v6-5rhf/GHSA-qv98-75v6-5rhf.json index 2a4c373b41f..c46fd9edb5b 100644 --- a/advisories/unreviewed/2024/09/GHSA-qv98-75v6-5rhf/GHSA-qv98-75v6-5rhf.json +++ b/advisories/unreviewed/2024/09/GHSA-qv98-75v6-5rhf/GHSA-qv98-75v6-5rhf.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-w8pf-f5g8-5xgv/GHSA-w8pf-f5g8-5xgv.json b/advisories/unreviewed/2024/09/GHSA-w8pf-f5g8-5xgv/GHSA-w8pf-f5g8-5xgv.json index d811fb4bb97..3cca2b7315d 100644 --- a/advisories/unreviewed/2024/09/GHSA-w8pf-f5g8-5xgv/GHSA-w8pf-f5g8-5xgv.json +++ b/advisories/unreviewed/2024/09/GHSA-w8pf-f5g8-5xgv/GHSA-w8pf-f5g8-5xgv.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-wqc2-gwgp-9p7w/GHSA-wqc2-gwgp-9p7w.json b/advisories/unreviewed/2024/09/GHSA-wqc2-gwgp-9p7w/GHSA-wqc2-gwgp-9p7w.json index 1287f26a9d4..8aa4e0329ad 100644 --- a/advisories/unreviewed/2024/09/GHSA-wqc2-gwgp-9p7w/GHSA-wqc2-gwgp-9p7w.json +++ b/advisories/unreviewed/2024/09/GHSA-wqc2-gwgp-9p7w/GHSA-wqc2-gwgp-9p7w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wqc2-gwgp-9p7w", - "modified": "2024-09-27T18:32:26Z", + "modified": "2024-09-27T21:31:50Z", "published": "2024-09-27T18:32:26Z", "aliases": [ "CVE-2024-46366" ], "details": "A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1336" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T17:15:13Z" diff --git a/advisories/unreviewed/2024/09/GHSA-wwq9-rfhf-r6h9/GHSA-wwq9-rfhf-r6h9.json b/advisories/unreviewed/2024/09/GHSA-wwq9-rfhf-r6h9/GHSA-wwq9-rfhf-r6h9.json index 35ed3aaa13f..c446124f7eb 100644 --- a/advisories/unreviewed/2024/09/GHSA-wwq9-rfhf-r6h9/GHSA-wwq9-rfhf-r6h9.json +++ b/advisories/unreviewed/2024/09/GHSA-wwq9-rfhf-r6h9/GHSA-wwq9-rfhf-r6h9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wwq9-rfhf-r6h9", - "modified": "2024-09-27T18:32:26Z", + "modified": "2024-09-27T21:31:50Z", "published": "2024-09-27T18:32:26Z", "aliases": [ "CVE-2024-46097" ], "details": "TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is created, an ID with an incremental value is automatically generated. Using the edit function you can change the tplan_id parameter to another ID. The application does not carry out a check on the user's permissions maing it possible to recover the IDs of all the TestPlans (even the administrative ones) and modify them even with minimal privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-27T18:15:05Z" diff --git a/advisories/unreviewed/2024/09/GHSA-xv6j-rwrm-mgqv/GHSA-xv6j-rwrm-mgqv.json b/advisories/unreviewed/2024/09/GHSA-xv6j-rwrm-mgqv/GHSA-xv6j-rwrm-mgqv.json new file mode 100644 index 00000000000..85857cfe03f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-xv6j-rwrm-mgqv/GHSA-xv6j-rwrm-mgqv.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv6j-rwrm-mgqv", + "modified": "2024-09-27T21:31:50Z", + "published": "2024-09-27T21:31:50Z", + "aliases": [ + "CVE-2024-9293" + ], + "details": "A vulnerability classified as critical was found in skyselang yylAdmin up to 3.0. Affected by this vulnerability is the function list of the file /app/admin/controller/file/File.php of the component Backend. The manipulation of the argument is_disable leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9293" + }, + { + "type": "WEB", + "url": "https://gitee.com/A0kooo/cve_article/blob/master/yyladmin/yyladmin%20file%20list%20have%20SQL%20injection.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.278785" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.278785" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.411499" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-27T21:15:03Z" + } +} \ No newline at end of file