diff --git a/advisories/unreviewed/2022/05/GHSA-5c3m-78cg-3wpv/GHSA-5c3m-78cg-3wpv.json b/advisories/unreviewed/2022/05/GHSA-5c3m-78cg-3wpv/GHSA-5c3m-78cg-3wpv.json index ce8881fca60..69edaa49d09 100644 --- a/advisories/unreviewed/2022/05/GHSA-5c3m-78cg-3wpv/GHSA-5c3m-78cg-3wpv.json +++ b/advisories/unreviewed/2022/05/GHSA-5c3m-78cg-3wpv/GHSA-5c3m-78cg-3wpv.json @@ -40,6 +40,10 @@ { "type": "WEB", "url": "https://seclists.org/oss-sec/2019/q4/101" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/06/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-3w6w-r9vq-3r79/GHSA-3w6w-r9vq-3r79.json b/advisories/unreviewed/2024/01/GHSA-3w6w-r9vq-3r79/GHSA-3w6w-r9vq-3r79.json index bbedb7394b3..9e430ce2498 100644 --- a/advisories/unreviewed/2024/01/GHSA-3w6w-r9vq-3r79/GHSA-3w6w-r9vq-3r79.json +++ b/advisories/unreviewed/2024/01/GHSA-3w6w-r9vq-3r79/GHSA-3w6w-r9vq-3r79.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3w6w-r9vq-3r79", - "modified": "2024-01-31T03:30:30Z", + "modified": "2024-02-06T18:30:20Z", "published": "2024-01-31T03:30:30Z", "aliases": [ "CVE-2024-22569" ], "details": "Stored Cross-Site Scripting (XSS) vulnerability in POSCMS v4.6.2, allows attackers to execute arbitrary code via a crafted payload to /index.php?c=install&m=index&step=2&is_install_db=0.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-31T02:15:54Z" diff --git a/advisories/unreviewed/2024/01/GHSA-55jq-jhw2-2vmp/GHSA-55jq-jhw2-2vmp.json b/advisories/unreviewed/2024/01/GHSA-55jq-jhw2-2vmp/GHSA-55jq-jhw2-2vmp.json index 3c64b734986..172863dba99 100644 --- a/advisories/unreviewed/2024/01/GHSA-55jq-jhw2-2vmp/GHSA-55jq-jhw2-2vmp.json +++ b/advisories/unreviewed/2024/01/GHSA-55jq-jhw2-2vmp/GHSA-55jq-jhw2-2vmp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-55jq-jhw2-2vmp", - "modified": "2024-01-31T21:31:03Z", + "modified": "2024-02-06T18:30:20Z", "published": "2024-01-31T21:31:03Z", "aliases": [ "CVE-2024-22159" diff --git a/advisories/unreviewed/2024/01/GHSA-7xm8-wjq7-88r5/GHSA-7xm8-wjq7-88r5.json b/advisories/unreviewed/2024/01/GHSA-7xm8-wjq7-88r5/GHSA-7xm8-wjq7-88r5.json index 365b50722c6..b37ff158e54 100644 --- a/advisories/unreviewed/2024/01/GHSA-7xm8-wjq7-88r5/GHSA-7xm8-wjq7-88r5.json +++ b/advisories/unreviewed/2024/01/GHSA-7xm8-wjq7-88r5/GHSA-7xm8-wjq7-88r5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7xm8-wjq7-88r5", - "modified": "2024-01-29T21:30:27Z", + "modified": "2024-02-06T18:30:19Z", "published": "2024-01-29T21:30:27Z", "aliases": [ "CVE-2023-51839" ], "details": "DeviceFarmer stf v3.6.6 suffers from Use of a Broken or Risky Cryptographic Algorithm.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-327" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-29T20:15:15Z" diff --git a/advisories/unreviewed/2024/01/GHSA-gccg-f527-63v3/GHSA-gccg-f527-63v3.json b/advisories/unreviewed/2024/01/GHSA-gccg-f527-63v3/GHSA-gccg-f527-63v3.json index 30829431aa9..7d73e6e2632 100644 --- a/advisories/unreviewed/2024/01/GHSA-gccg-f527-63v3/GHSA-gccg-f527-63v3.json +++ b/advisories/unreviewed/2024/01/GHSA-gccg-f527-63v3/GHSA-gccg-f527-63v3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gccg-f527-63v3", - "modified": "2024-01-29T21:30:27Z", + "modified": "2024-02-06T18:30:19Z", "published": "2024-01-29T21:30:27Z", "aliases": [ "CVE-2023-49038" ], "details": "Command injection in the ping utility on Buffalo LS210D 1.78-0.03 allows a remote authenticated attacker to inject arbitrary commands onto the NAS as root.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-29T21:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-33cc-g737-2r5g/GHSA-33cc-g737-2r5g.json b/advisories/unreviewed/2024/02/GHSA-33cc-g737-2r5g/GHSA-33cc-g737-2r5g.json new file mode 100644 index 00000000000..8089b85a7bd --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-33cc-g737-2r5g/GHSA-33cc-g737-2r5g.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-33cc-g737-2r5g", + "modified": "2024-02-06T18:30:21Z", + "published": "2024-02-06T18:30:21Z", + "aliases": [ + "CVE-2024-1253" + ], + "details": "A vulnerability, which was classified as critical, has been found in Beijing Baichuo Smart S40 Management Platform up to 20240126. Affected by this issue is some unknown functionality of the file /useratte/web.php of the component Import Handler. The manipulation of the argument file_upload leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252992. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1253" + }, + { + "type": "WEB", + "url": "https://github.com/b51s77/cve/blob/main/upload.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252992" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252992" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-37j2-h4x2-rp3v/GHSA-37j2-h4x2-rp3v.json b/advisories/unreviewed/2024/02/GHSA-37j2-h4x2-rp3v/GHSA-37j2-h4x2-rp3v.json new file mode 100644 index 00000000000..85a3fc44b81 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-37j2-h4x2-rp3v/GHSA-37j2-h4x2-rp3v.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37j2-h4x2-rp3v", + "modified": "2024-02-06T18:30:21Z", + "published": "2024-02-06T18:30:21Z", + "aliases": [ + "CVE-2023-40545" + ], + "details": "Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40545" + }, + { + "type": "WEB", + "url": "https://docs.pingidentity.com/r/en-us/pingfederate-113/hro1701116403236" + }, + { + "type": "WEB", + "url": "https://support.pingidentity.com/s/article/SECADV040-PingFederate-OAuth-Client-Authentication-Bypass" + }, + { + "type": "WEB", + "url": "https://www.pingidentity.com/en/resources/downloads/pingfederate/previous-releases.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T18:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-3c3r-6mf2-xcmp/GHSA-3c3r-6mf2-xcmp.json b/advisories/unreviewed/2024/02/GHSA-3c3r-6mf2-xcmp/GHSA-3c3r-6mf2-xcmp.json new file mode 100644 index 00000000000..bcd3831a5a6 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-3c3r-6mf2-xcmp/GHSA-3c3r-6mf2-xcmp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c3r-6mf2-xcmp", + "modified": "2024-02-06T18:30:21Z", + "published": "2024-02-06T18:30:21Z", + "aliases": [ + "CVE-2024-24013" + ], + "details": "A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/pay/list", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24013" + }, + { + "type": "WEB", + "url": "https://github.com/201206030/novel-plus" + }, + { + "type": "WEB", + "url": "https://github.com/cxcxcxcxcxcxcxc/cxcxcxcxcxcxcxc/blob/main/cxcxcxcxcxc/about-2024/24013.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T16:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-3gjv-wq7v-458m/GHSA-3gjv-wq7v-458m.json b/advisories/unreviewed/2024/02/GHSA-3gjv-wq7v-458m/GHSA-3gjv-wq7v-458m.json new file mode 100644 index 00000000000..f380d5aa55b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-3gjv-wq7v-458m/GHSA-3gjv-wq7v-458m.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gjv-wq7v-458m", + "modified": "2024-02-06T18:30:21Z", + "published": "2024-02-06T18:30:21Z", + "aliases": [ + "CVE-2024-22331" + ], + "details": "IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 through 7.3.2.3, and IBM UrbanCode Deploy (UCD) - IBM DevOps Deploy 8.0.0.0 could disclose sensitive user information when installing the Windows agent. IBM X-Force ID: 279971.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22331" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/279971" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7114131" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-3qrv-r8v8-pmw7/GHSA-3qrv-r8v8-pmw7.json b/advisories/unreviewed/2024/02/GHSA-3qrv-r8v8-pmw7/GHSA-3qrv-r8v8-pmw7.json new file mode 100644 index 00000000000..d245c58888e --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-3qrv-r8v8-pmw7/GHSA-3qrv-r8v8-pmw7.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qrv-r8v8-pmw7", + "modified": "2024-02-06T18:30:21Z", + "published": "2024-02-06T18:30:21Z", + "aliases": [ + "CVE-2024-1048" + ], + "details": "A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1048" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-1048" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2256827" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/02/06/3" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/06/3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T18:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-44xm-468v-w3hq/GHSA-44xm-468v-w3hq.json b/advisories/unreviewed/2024/02/GHSA-44xm-468v-w3hq/GHSA-44xm-468v-w3hq.json new file mode 100644 index 00000000000..069065b5b7e --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-44xm-468v-w3hq/GHSA-44xm-468v-w3hq.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44xm-468v-w3hq", + "modified": "2024-02-06T18:30:21Z", + "published": "2024-02-06T18:30:21Z", + "aliases": [ + "CVE-2024-1252" + ], + "details": "A vulnerability classified as critical was found in Tongda OA 2017 up to 11.9. Affected by this vulnerability is an unknown functionality of the file /general/attendance/manage/ask_duty/delete.php. The manipulation of the argument ASK_DUTY_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-252991.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1252" + }, + { + "type": "WEB", + "url": "https://github.com/b51s77/cve/blob/main/sql.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252991" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252991" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-62qv-qwj7-9q6x/GHSA-62qv-qwj7-9q6x.json b/advisories/unreviewed/2024/02/GHSA-62qv-qwj7-9q6x/GHSA-62qv-qwj7-9q6x.json new file mode 100644 index 00000000000..99ad87e94c8 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-62qv-qwj7-9q6x/GHSA-62qv-qwj7-9q6x.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62qv-qwj7-9q6x", + "modified": "2024-02-06T18:30:21Z", + "published": "2024-02-06T18:30:21Z", + "aliases": [ + "CVE-2023-46683" + ], + "details": "A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection . An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46683" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1857" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-6xj8-7c6f-w9rq/GHSA-6xj8-7c6f-w9rq.json b/advisories/unreviewed/2024/02/GHSA-6xj8-7c6f-w9rq/GHSA-6xj8-7c6f-w9rq.json new file mode 100644 index 00000000000..cb089665b84 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-6xj8-7c6f-w9rq/GHSA-6xj8-7c6f-w9rq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xj8-7c6f-w9rq", + "modified": "2024-02-06T18:30:21Z", + "published": "2024-02-06T18:30:21Z", + "aliases": [ + "CVE-2024-24000" + ], + "details": "jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into the upload path, resulting in arbitrary file uploads with controllable paths.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24000" + }, + { + "type": "WEB", + "url": "https://github.com/cxcxcxcxcxcxcxc/cxcxcxcxcxcxcxc/blob/main/cxcxcxcxcxc/about-2024/24000.txt" + }, + { + "type": "WEB", + "url": "https://github.com/jishenghua/jshERP" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T16:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-99rx-9376-xmfc/GHSA-99rx-9376-xmfc.json b/advisories/unreviewed/2024/02/GHSA-99rx-9376-xmfc/GHSA-99rx-9376-xmfc.json new file mode 100644 index 00000000000..410738e6e91 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-99rx-9376-xmfc/GHSA-99rx-9376-xmfc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99rx-9376-xmfc", + "modified": "2024-02-06T18:30:21Z", + "published": "2024-02-06T18:30:21Z", + "aliases": [ + "CVE-2023-43482" + ], + "details": "A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43482" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1850" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-cpxr-hfmm-j69h/GHSA-cpxr-hfmm-j69h.json b/advisories/unreviewed/2024/02/GHSA-cpxr-hfmm-j69h/GHSA-cpxr-hfmm-j69h.json new file mode 100644 index 00000000000..b45957e8f9e --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-cpxr-hfmm-j69h/GHSA-cpxr-hfmm-j69h.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpxr-hfmm-j69h", + "modified": "2024-02-06T18:30:20Z", + "published": "2024-02-06T18:30:20Z", + "aliases": [ + "CVE-2024-1251" + ], + "details": "A vulnerability classified as critical has been found in Tongda OA 2017 up to 11.10. Affected is an unknown function of the file /general/email/outbox/delete.php. The manipulation of the argument DELETE_STR leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-252990 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1251" + }, + { + "type": "WEB", + "url": "https://github.com/rockersiyuan/CVE/blob/main/TongDa%20Sql%20inject.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252990" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252990" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T16:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-gqfw-9432-p6cq/GHSA-gqfw-9432-p6cq.json b/advisories/unreviewed/2024/02/GHSA-gqfw-9432-p6cq/GHSA-gqfw-9432-p6cq.json new file mode 100644 index 00000000000..9cb83c292e8 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-gqfw-9432-p6cq/GHSA-gqfw-9432-p6cq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqfw-9432-p6cq", + "modified": "2024-02-06T18:30:20Z", + "published": "2024-02-06T18:30:20Z", + "aliases": [ + "CVE-2023-50395" + ], + "details": "\nSQL Injection Remote Code Execution Vulnerability was found using an update statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50395" + }, + { + "type": "WEB", + "url": "https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2024-1_release_notes.htm" + }, + { + "type": "WEB", + "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2023-50395" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T16:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-hgwr-gpf8-663p/GHSA-hgwr-gpf8-663p.json b/advisories/unreviewed/2024/02/GHSA-hgwr-gpf8-663p/GHSA-hgwr-gpf8-663p.json new file mode 100644 index 00000000000..b65e85921e6 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-hgwr-gpf8-663p/GHSA-hgwr-gpf8-663p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgwr-gpf8-663p", + "modified": "2024-02-06T18:30:21Z", + "published": "2024-02-06T18:30:21Z", + "aliases": [ + "CVE-2023-47617" + ], + "details": "A post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47617" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1858" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-j9rf-q3p6-99gv/GHSA-j9rf-q3p6-99gv.json b/advisories/unreviewed/2024/02/GHSA-j9rf-q3p6-99gv/GHSA-j9rf-q3p6-99gv.json new file mode 100644 index 00000000000..5c67944748b --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-j9rf-q3p6-99gv/GHSA-j9rf-q3p6-99gv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9rf-q3p6-99gv", + "modified": "2024-02-06T18:30:21Z", + "published": "2024-02-06T18:30:21Z", + "aliases": [ + "CVE-2024-24291" + ], + "details": "An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24291" + }, + { + "type": "WEB", + "url": "https://gitee.com/wgd0ay/wgd0ay/issues/I8WSD1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T16:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-jv9f-872m-gv5x/GHSA-jv9f-872m-gv5x.json b/advisories/unreviewed/2024/02/GHSA-jv9f-872m-gv5x/GHSA-jv9f-872m-gv5x.json index 4e0d05efa0a..bc426b736d1 100644 --- a/advisories/unreviewed/2024/02/GHSA-jv9f-872m-gv5x/GHSA-jv9f-872m-gv5x.json +++ b/advisories/unreviewed/2024/02/GHSA-jv9f-872m-gv5x/GHSA-jv9f-872m-gv5x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jv9f-872m-gv5x", - "modified": "2024-02-01T12:30:22Z", + "modified": "2024-02-06T18:30:20Z", "published": "2024-02-01T12:30:22Z", "aliases": [ "CVE-2023-51532" diff --git a/advisories/unreviewed/2024/02/GHSA-jxjp-cv56-m425/GHSA-jxjp-cv56-m425.json b/advisories/unreviewed/2024/02/GHSA-jxjp-cv56-m425/GHSA-jxjp-cv56-m425.json new file mode 100644 index 00000000000..6c42c7b0843 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-jxjp-cv56-m425/GHSA-jxjp-cv56-m425.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxjp-cv56-m425", + "modified": "2024-02-06T18:30:21Z", + "published": "2024-02-06T18:30:21Z", + "aliases": [ + "CVE-2024-24015" + ], + "details": "A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL via /sys/user/exit", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24015" + }, + { + "type": "WEB", + "url": "https://github.com/201206030/novel-plus" + }, + { + "type": "WEB", + "url": "https://github.com/cxcxcxcxcxcxcxc/cxcxcxcxcxcxcxc/blob/main/cxcxcxcxcxc/about-2024/24015.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T16:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mj59-82hp-pgf4/GHSA-mj59-82hp-pgf4.json b/advisories/unreviewed/2024/02/GHSA-mj59-82hp-pgf4/GHSA-mj59-82hp-pgf4.json new file mode 100644 index 00000000000..d420e62824f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mj59-82hp-pgf4/GHSA-mj59-82hp-pgf4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mj59-82hp-pgf4", + "modified": "2024-02-06T18:30:21Z", + "published": "2024-02-06T18:30:21Z", + "aliases": [ + "CVE-2023-36498" + ], + "details": "A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability and gain access to an unrestricted shell.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36498" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1853" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-mqq6-542f-w38g/GHSA-mqq6-542f-w38g.json b/advisories/unreviewed/2024/02/GHSA-mqq6-542f-w38g/GHSA-mqq6-542f-w38g.json new file mode 100644 index 00000000000..264b5f1aa95 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-mqq6-542f-w38g/GHSA-mqq6-542f-w38g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqq6-542f-w38g", + "modified": "2024-02-06T18:30:21Z", + "published": "2024-02-06T18:30:21Z", + "aliases": [ + "CVE-2023-47618" + ], + "details": "A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47618" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1859" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-p72g-62xm-rq24/GHSA-p72g-62xm-rq24.json b/advisories/unreviewed/2024/02/GHSA-p72g-62xm-rq24/GHSA-p72g-62xm-rq24.json new file mode 100644 index 00000000000..b075cb6a4d8 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-p72g-62xm-rq24/GHSA-p72g-62xm-rq24.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p72g-62xm-rq24", + "modified": "2024-02-06T18:30:21Z", + "published": "2024-02-06T18:30:21Z", + "aliases": [ + "CVE-2023-47167" + ], + "details": "A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47167" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1855" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-q7wc-c2ff-q9xq/GHSA-q7wc-c2ff-q9xq.json b/advisories/unreviewed/2024/02/GHSA-q7wc-c2ff-q9xq/GHSA-q7wc-c2ff-q9xq.json new file mode 100644 index 00000000000..60c21a5c60c --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-q7wc-c2ff-q9xq/GHSA-q7wc-c2ff-q9xq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7wc-c2ff-q9xq", + "modified": "2024-02-06T18:30:20Z", + "published": "2024-02-06T18:30:20Z", + "aliases": [ + "CVE-2023-46183" + ], + "details": "IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could allow a system administrator to obtain sensitive partition information. IBM X-Force ID: 269695.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46183" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/269695" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7114982" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T16:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-qphc-8455-gj55/GHSA-qphc-8455-gj55.json b/advisories/unreviewed/2024/02/GHSA-qphc-8455-gj55/GHSA-qphc-8455-gj55.json new file mode 100644 index 00000000000..9f0b4a842f7 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-qphc-8455-gj55/GHSA-qphc-8455-gj55.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qphc-8455-gj55", + "modified": "2024-02-06T18:30:21Z", + "published": "2024-02-06T18:30:21Z", + "aliases": [ + "CVE-2023-47209" + ], + "details": "A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47209" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1854" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-v62h-prj4-9v6m/GHSA-v62h-prj4-9v6m.json b/advisories/unreviewed/2024/02/GHSA-v62h-prj4-9v6m/GHSA-v62h-prj4-9v6m.json index ea0ffe036f9..845589e0da5 100644 --- a/advisories/unreviewed/2024/02/GHSA-v62h-prj4-9v6m/GHSA-v62h-prj4-9v6m.json +++ b/advisories/unreviewed/2024/02/GHSA-v62h-prj4-9v6m/GHSA-v62h-prj4-9v6m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v62h-prj4-9v6m", - "modified": "2024-02-01T12:30:21Z", + "modified": "2024-02-06T18:30:20Z", "published": "2024-02-01T12:30:21Z", "aliases": [ "CVE-2023-52191" diff --git a/advisories/unreviewed/2024/02/GHSA-v63h-fjp2-v8q9/GHSA-v63h-fjp2-v8q9.json b/advisories/unreviewed/2024/02/GHSA-v63h-fjp2-v8q9/GHSA-v63h-fjp2-v8q9.json new file mode 100644 index 00000000000..3c0b17a44c6 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-v63h-fjp2-v8q9/GHSA-v63h-fjp2-v8q9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v63h-fjp2-v8q9", + "modified": "2024-02-06T18:30:20Z", + "published": "2024-02-06T18:30:20Z", + "aliases": [ + "CVE-2023-35188" + ], + "details": "\nSQL Injection Remote Code Execution Vulnerability was found using a create statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35188" + }, + { + "type": "WEB", + "url": "https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2024-1_release_notes.htm" + }, + { + "type": "WEB", + "url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2023-35188" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T16:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-vmmp-h76c-g65f/GHSA-vmmp-h76c-g65f.json b/advisories/unreviewed/2024/02/GHSA-vmmp-h76c-g65f/GHSA-vmmp-h76c-g65f.json new file mode 100644 index 00000000000..0e99da60baa --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-vmmp-h76c-g65f/GHSA-vmmp-h76c-g65f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmmp-h76c-g65f", + "modified": "2024-02-06T18:30:21Z", + "published": "2024-02-06T18:30:21Z", + "aliases": [ + "CVE-2023-42664" + ], + "details": "A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42664" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1856" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-06T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-wj7p-x86m-qmwx/GHSA-wj7p-x86m-qmwx.json b/advisories/unreviewed/2024/02/GHSA-wj7p-x86m-qmwx/GHSA-wj7p-x86m-qmwx.json index bb54946f086..ee0d5946f61 100644 --- a/advisories/unreviewed/2024/02/GHSA-wj7p-x86m-qmwx/GHSA-wj7p-x86m-qmwx.json +++ b/advisories/unreviewed/2024/02/GHSA-wj7p-x86m-qmwx/GHSA-wj7p-x86m-qmwx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wj7p-x86m-qmwx", - "modified": "2024-02-01T12:30:22Z", + "modified": "2024-02-06T18:30:20Z", "published": "2024-02-01T12:30:22Z", "aliases": [ "CVE-2023-51534"