diff --git a/advisories/unreviewed/2023/10/GHSA-2vcg-7j3r-mm58/GHSA-2vcg-7j3r-mm58.json b/advisories/unreviewed/2023/10/GHSA-2vcg-7j3r-mm58/GHSA-2vcg-7j3r-mm58.json new file mode 100644 index 00000000000..74cd2b9a5e9 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-2vcg-7j3r-mm58/GHSA-2vcg-7j3r-mm58.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2vcg-7j3r-mm58", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2023-5666" + ], + "details": "The Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcpaccordion' shortcode in all versions up to, and including, 2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5666" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/accordions-wp/trunk/theme/custom-wp-accordion-themes.php?rev=2406278#L24" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/2982015/accordions-wp#file370" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a8ada876-4a8b-494f-9132-d88a71b42c44?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-35gm-cw3v-mj5j/GHSA-35gm-cw3v-mj5j.json b/advisories/unreviewed/2023/10/GHSA-35gm-cw3v-mj5j/GHSA-35gm-cw3v-mj5j.json new file mode 100644 index 00000000000..7f862f0222a --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-35gm-cw3v-mj5j/GHSA-35gm-cw3v-mj5j.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35gm-cw3v-mj5j", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2023-5565" + ], + "details": "The Shortcode Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shortmenu' shortcode in versions up to, and including, 3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5565" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/shortcode-menu/tags/3.2/shortcode-menu.php#L183" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/438b9c13-4059-4671-ab4a-07a8cf6f6122?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-3jg7-ghg4-5pxr/GHSA-3jg7-ghg4-5pxr.json b/advisories/unreviewed/2023/10/GHSA-3jg7-ghg4-5pxr/GHSA-3jg7-ghg4-5pxr.json index 7f327a976a5..c91f1754bfd 100644 --- a/advisories/unreviewed/2023/10/GHSA-3jg7-ghg4-5pxr/GHSA-3jg7-ghg4-5pxr.json +++ b/advisories/unreviewed/2023/10/GHSA-3jg7-ghg4-5pxr/GHSA-3jg7-ghg4-5pxr.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-4m6r-j49h-94c5/GHSA-4m6r-j49h-94c5.json b/advisories/unreviewed/2023/10/GHSA-4m6r-j49h-94c5/GHSA-4m6r-j49h-94c5.json new file mode 100644 index 00000000000..bf514b08bde --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-4m6r-j49h-94c5/GHSA-4m6r-j49h-94c5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m6r-j49h-94c5", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2022-4575" + ], + "details": "\nA vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4575" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-106014" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json b/advisories/unreviewed/2023/10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json index bfd9942b871..897c827e921 100644 --- a/advisories/unreviewed/2023/10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json +++ b/advisories/unreviewed/2023/10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://blog.leakix.net/2023/10/vinchin-backup-rce-chain/" }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/175397/VinChin-VMWare-Backup-7.0-Hardcoded-Credential-Remote-Code-Execution.html" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2023/Oct/31" diff --git a/advisories/unreviewed/2023/10/GHSA-5g3f-8396-pv8p/GHSA-5g3f-8396-pv8p.json b/advisories/unreviewed/2023/10/GHSA-5g3f-8396-pv8p/GHSA-5g3f-8396-pv8p.json new file mode 100644 index 00000000000..e97ac1c341a --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-5g3f-8396-pv8p/GHSA-5g3f-8396-pv8p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g3f-8396-pv8p", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2023-5250" + ], + "details": "The Grid Plus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.2 via a shortcode attribute. This allows subscriber-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files with arbitrary content can be uploaded and included. This is limited to .php files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5250" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/grid-plus/tags/1.3.2/core/grid.plus.base.class.php#L19" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a6407792-2c76-4149-a9f9-d53002135bec?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-65xh-wxfv-47ch/GHSA-65xh-wxfv-47ch.json b/advisories/unreviewed/2023/10/GHSA-65xh-wxfv-47ch/GHSA-65xh-wxfv-47ch.json new file mode 100644 index 00000000000..7665e4b42a3 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-65xh-wxfv-47ch/GHSA-65xh-wxfv-47ch.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65xh-wxfv-47ch", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2023-5832" + ], + "details": "Improper Input Validation in GitHub repository mintplex-labs/anything-llm prior to 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5832" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/18798c5b640018aaee924e0afd941705d88df92e" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/afee3726-571f-416e-bba5-0828c815f5df" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-67w3-cv99-6qhq/GHSA-67w3-cv99-6qhq.json b/advisories/unreviewed/2023/10/GHSA-67w3-cv99-6qhq/GHSA-67w3-cv99-6qhq.json new file mode 100644 index 00000000000..6b9e794fb70 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-67w3-cv99-6qhq/GHSA-67w3-cv99-6qhq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67w3-cv99-6qhq", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2023-5252" + ], + "details": "The FareHarbor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.6.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5252" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/fareharbor/tags/3.6.7/fareharbor.php#L287" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/42ad6fef-4280-45db-a3e2-6d7522751fa7?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-6gp7-g3rx-2cq6/GHSA-6gp7-g3rx-2cq6.json b/advisories/unreviewed/2023/10/GHSA-6gp7-g3rx-2cq6/GHSA-6gp7-g3rx-2cq6.json index 015802e1c8e..3f7f7ae58ba 100644 --- a/advisories/unreviewed/2023/10/GHSA-6gp7-g3rx-2cq6/GHSA-6gp7-g3rx-2cq6.json +++ b/advisories/unreviewed/2023/10/GHSA-6gp7-g3rx-2cq6/GHSA-6gp7-g3rx-2cq6.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-97wj-4q63-7pp6/GHSA-97wj-4q63-7pp6.json b/advisories/unreviewed/2023/10/GHSA-97wj-4q63-7pp6/GHSA-97wj-4q63-7pp6.json new file mode 100644 index 00000000000..08651b6d86f --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-97wj-4q63-7pp6/GHSA-97wj-4q63-7pp6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97wj-4q63-7pp6", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2023-5843" + ], + "details": "The Ads by datafeedr.com plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.1.3 via the 'dfads_ajax_load_ads' function. This allows unauthenticated attackers to execute code on the server. The parameters of the callable function are limited, they cannot be specified arbitrarily.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5843" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ads-by-datafeedrcom/tags/1.1.3/inc/dfads.class.php#L34" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5412fd87-49bc-445c-8d16-443e38933d1e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-c449-rxg5-mv8h/GHSA-c449-rxg5-mv8h.json b/advisories/unreviewed/2023/10/GHSA-c449-rxg5-mv8h/GHSA-c449-rxg5-mv8h.json new file mode 100644 index 00000000000..485cd81d746 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-c449-rxg5-mv8h/GHSA-c449-rxg5-mv8h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c449-rxg5-mv8h", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2023-4964" + ], + "details": "Potential open redirect vulnerability\nin opentext Service Management Automation X\n(SMAX) versions 2020.05, 2020.08,\n2020.11, 2021.02, 2021.05, 2021.08, 2021.11, 2022.05, 2022.11 and opentext Asset\nManagement X (AMX) versions 2021.08, 2021.11, 2022.05, 2022.11. The\nvulnerability could allow attackers to redirect a user to\nmalicious websites.\n\n\n\n\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4964" + }, + { + "type": "WEB", + "url": "https://portal.microfocus.com/s/article/KM000022703?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-c6fh-27x8-5p84/GHSA-c6fh-27x8-5p84.json b/advisories/unreviewed/2023/10/GHSA-c6fh-27x8-5p84/GHSA-c6fh-27x8-5p84.json new file mode 100644 index 00000000000..0d1db7f4be6 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-c6fh-27x8-5p84/GHSA-c6fh-27x8-5p84.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6fh-27x8-5p84", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2023-5583" + ], + "details": "The WP Simple Galleries plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.34 via deserialization of untrusted input from the 'wpsimplegallery_gallery' post meta via 'wpsgallery' shortcode. This allows authenticated attackers, with contributor-level permissions and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5583" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-simple-galleries/tags/1.34/wp-simple-gallery.php#L250" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0dc8f7cf-d8be-4229-b823-3bd9bc9f6eda?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-ch74-qvc9-j4fg/GHSA-ch74-qvc9-j4fg.json b/advisories/unreviewed/2023/10/GHSA-ch74-qvc9-j4fg/GHSA-ch74-qvc9-j4fg.json new file mode 100644 index 00000000000..f5228c7a73e --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-ch74-qvc9-j4fg/GHSA-ch74-qvc9-j4fg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch74-qvc9-j4fg", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2023-5335" + ], + "details": "The Buzzsprout Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'buzzsprout' shortcode in versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5335" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/buzzsprout-podcasting/tags/1.8.3/buzzsprout-podcasting.php#L271" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/be7f8b73-801d-46e8-81c1-8bb0bb576700?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-cqv4-m6cq-x9jx/GHSA-cqv4-m6cq-x9jx.json b/advisories/unreviewed/2023/10/GHSA-cqv4-m6cq-x9jx/GHSA-cqv4-m6cq-x9jx.json index 2f1402a4baf..4619b1e547c 100644 --- a/advisories/unreviewed/2023/10/GHSA-cqv4-m6cq-x9jx/GHSA-cqv4-m6cq-x9jx.json +++ b/advisories/unreviewed/2023/10/GHSA-cqv4-m6cq-x9jx/GHSA-cqv4-m6cq-x9jx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cqv4-m6cq-x9jx", - "modified": "2023-10-20T06:30:19Z", + "modified": "2023-10-30T15:30:44Z", "published": "2023-10-20T06:30:19Z", "aliases": [ "CVE-2023-45471" ], "details": "The QAD Search Server is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to, and including, 1.0.0.315 due to insufficient checks on indexes. This makes it possible for unauthenticated attackers to create a new index and inject a malicious web script into its name, that will execute whenever a user accesses the search page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-cxcr-4mx7-3jpm/GHSA-cxcr-4mx7-3jpm.json b/advisories/unreviewed/2023/10/GHSA-cxcr-4mx7-3jpm/GHSA-cxcr-4mx7-3jpm.json new file mode 100644 index 00000000000..eff014946ac --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-cxcr-4mx7-3jpm/GHSA-cxcr-4mx7-3jpm.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxcr-4mx7-3jpm", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2023-5251" + ], + "details": "The Grid Plus plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'grid_plus_save_layout_callback' and 'grid_plus_delete_callback' functions in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with subscriber privileges or above, to add, update or delete grid layout.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5251" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/grid-plus/tags/1.3.2/core/ajax_be.php#L10" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/grid-plus/tags/1.3.2/core/ajax_be.php#L69" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d2d34c84-473c-49f8-b55c-c869b5479974?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-f865-7gxm-95r4/GHSA-f865-7gxm-95r4.json b/advisories/unreviewed/2023/10/GHSA-f865-7gxm-95r4/GHSA-f865-7gxm-95r4.json index 9649e222bed..ab070b22f2b 100644 --- a/advisories/unreviewed/2023/10/GHSA-f865-7gxm-95r4/GHSA-f865-7gxm-95r4.json +++ b/advisories/unreviewed/2023/10/GHSA-f865-7gxm-95r4/GHSA-f865-7gxm-95r4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f865-7gxm-95r4", - "modified": "2023-10-20T06:30:19Z", + "modified": "2023-10-30T15:30:44Z", "published": "2023-10-20T06:30:19Z", "aliases": [ "CVE-2023-45394" ], "details": "Stored Cross-Site Scripting (XSS) vulnerability in the Company field in the \"Request a Quote\" Section of Small CRM v3.0 allows an attacker to store and execute malicious javascript code in the Admin panel which leads to Admin account takeover.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-fm9f-7rqx-chvx/GHSA-fm9f-7rqx-chvx.json b/advisories/unreviewed/2023/10/GHSA-fm9f-7rqx-chvx/GHSA-fm9f-7rqx-chvx.json new file mode 100644 index 00000000000..abc5b5b9e73 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-fm9f-7rqx-chvx/GHSA-fm9f-7rqx-chvx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm9f-7rqx-chvx", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2022-4574" + ], + "details": "\nAn SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.  \n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4574" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-106014" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-ghgc-qf42-c3jp/GHSA-ghgc-qf42-c3jp.json b/advisories/unreviewed/2023/10/GHSA-ghgc-qf42-c3jp/GHSA-ghgc-qf42-c3jp.json new file mode 100644 index 00000000000..939ae2ca29e --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-ghgc-qf42-c3jp/GHSA-ghgc-qf42-c3jp.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghgc-qf42-c3jp", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2023-5566" + ], + "details": "The Simple Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.0.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5566" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/smpl-shortcodes/tags/1.0.20/includes/shortcodes.php#L257" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/smpl-shortcodes/tags/1.0.20/includes/shortcodes.php#L292" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/smpl-shortcodes/tags/1.0.20/includes/shortcodes.php#L386" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a153d6b2-e3fd-42db-90ba-d899a07d60c1?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-ghvx-5v39-7hv5/GHSA-ghvx-5v39-7hv5.json b/advisories/unreviewed/2023/10/GHSA-ghvx-5v39-7hv5/GHSA-ghvx-5v39-7hv5.json index d744482edac..def7b296ad1 100644 --- a/advisories/unreviewed/2023/10/GHSA-ghvx-5v39-7hv5/GHSA-ghvx-5v39-7hv5.json +++ b/advisories/unreviewed/2023/10/GHSA-ghvx-5v39-7hv5/GHSA-ghvx-5v39-7hv5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ghvx-5v39-7hv5", - "modified": "2023-10-20T06:30:19Z", + "modified": "2023-10-30T15:30:44Z", "published": "2023-10-20T06:30:19Z", "aliases": [ "CVE-2023-34051" ], "details": "VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json b/advisories/unreviewed/2023/10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json index dfb9316ab6e..60855c18d6e 100644 --- a/advisories/unreviewed/2023/10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json +++ b/advisories/unreviewed/2023/10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://blog.leakix.net/2023/10/vinchin-backup-rce-chain/" }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/175397/VinChin-VMWare-Backup-7.0-Hardcoded-Credential-Remote-Code-Execution.html" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2023/Oct/31" diff --git a/advisories/unreviewed/2023/10/GHSA-grhf-9x38-2pm7/GHSA-grhf-9x38-2pm7.json b/advisories/unreviewed/2023/10/GHSA-grhf-9x38-2pm7/GHSA-grhf-9x38-2pm7.json new file mode 100644 index 00000000000..b079c66a159 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-grhf-9x38-2pm7/GHSA-grhf-9x38-2pm7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grhf-9x38-2pm7", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2022-48189" + ], + "details": "An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code. ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48189" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-106014" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-hwmg-864w-89m6/GHSA-hwmg-864w-89m6.json b/advisories/unreviewed/2023/10/GHSA-hwmg-864w-89m6/GHSA-hwmg-864w-89m6.json new file mode 100644 index 00000000000..fe082322903 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-hwmg-864w-89m6/GHSA-hwmg-864w-89m6.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwmg-864w-89m6", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2023-5362" + ], + "details": "The Carousel, Recent Post Slider and Banner Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'spice_post_slider' shortcode in versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5362" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/spice-post-slider/tags/1.9/include/view/shortcode.php#L102" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/spice-post-slider/tags/2.0.1/include/view/shortcode.php?rev=2981648#L102" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/2981654/spice-post-slider" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c0dd70b9-6f8a-41fc-ab4f-f6cdfee8dfb8?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-m4h3-mqpx-7mc5/GHSA-m4h3-mqpx-7mc5.json b/advisories/unreviewed/2023/10/GHSA-m4h3-mqpx-7mc5/GHSA-m4h3-mqpx-7mc5.json new file mode 100644 index 00000000000..34eda7a825f --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-m4h3-mqpx-7mc5/GHSA-m4h3-mqpx-7mc5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4h3-mqpx-7mc5", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2023-44323" + ], + "details": "Adobe Acrobat for Edge version 118.0.2088.46 (and earlier) is affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44323" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44323" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-mr7q-pq37-qv94/GHSA-mr7q-pq37-qv94.json b/advisories/unreviewed/2023/10/GHSA-mr7q-pq37-qv94/GHSA-mr7q-pq37-qv94.json new file mode 100644 index 00000000000..e359d860532 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-mr7q-pq37-qv94/GHSA-mr7q-pq37-qv94.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr7q-pq37-qv94", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2023-5164" + ], + "details": "The Bellows Accordion Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5164" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/bellows-accordion-menu/tags/1.4.2/includes/bellows.api.php#L5" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/bellows-accordion-menu/tags/1.4.2/includes/functions.php#L12" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/50283a4f-ea59-488a-bab0-dd6bc5718556?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-pm69-5gmj-rpc4/GHSA-pm69-5gmj-rpc4.json b/advisories/unreviewed/2023/10/GHSA-pm69-5gmj-rpc4/GHSA-pm69-5gmj-rpc4.json new file mode 100644 index 00000000000..645827e4057 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-pm69-5gmj-rpc4/GHSA-pm69-5gmj-rpc4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pm69-5gmj-rpc4", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2022-4573" + ], + "details": "\nAn SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access and elevated privileges to execute arbitrary code.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4573" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-106014" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-pwfp-gqpx-2mgg/GHSA-pwfp-gqpx-2mgg.json b/advisories/unreviewed/2023/10/GHSA-pwfp-gqpx-2mgg/GHSA-pwfp-gqpx-2mgg.json new file mode 100644 index 00000000000..0b484790b58 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-pwfp-gqpx-2mgg/GHSA-pwfp-gqpx-2mgg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwfp-gqpx-2mgg", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2023-5199" + ], + "details": "The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-to-page' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to include local file and potentially execute code on the server. While subscribers may need to poison log files or otherwise get a file installed in order to achieve remote code execution, author and above users can upload files by default and achieve remote code execution easily.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5199" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/php-to-page/trunk/php-to-page.php?rev=441028#L22" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/83e5a0dc-fc51-4565-945f-190cf9175874?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-98" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-qrhv-m52g-wcw8/GHSA-qrhv-m52g-wcw8.json b/advisories/unreviewed/2023/10/GHSA-qrhv-m52g-wcw8/GHSA-qrhv-m52g-wcw8.json index 26888ad495f..ee495e2de0f 100644 --- a/advisories/unreviewed/2023/10/GHSA-qrhv-m52g-wcw8/GHSA-qrhv-m52g-wcw8.json +++ b/advisories/unreviewed/2023/10/GHSA-qrhv-m52g-wcw8/GHSA-qrhv-m52g-wcw8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qrhv-m52g-wcw8", - "modified": "2023-10-20T06:30:19Z", + "modified": "2023-10-30T15:30:44Z", "published": "2023-10-20T06:30:19Z", "aliases": [ "CVE-2023-34052" ], "details": "VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can trigger the deserialization of data which could result in authentication bypass.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-502" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-rff8-x3x5-vvqc/GHSA-rff8-x3x5-vvqc.json b/advisories/unreviewed/2023/10/GHSA-rff8-x3x5-vvqc/GHSA-rff8-x3x5-vvqc.json new file mode 100644 index 00000000000..8df188510ff --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-rff8-x3x5-vvqc/GHSA-rff8-x3x5-vvqc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rff8-x3x5-vvqc", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2023-5833" + ], + "details": "Improper Access Control in GitHub repository mintplex-labs/anything-llm prior to 0.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5833" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/d5b1f84a4c7991987eac3454d4f1b4067841d783" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/00ec6847-125b-43e9-9658-d3cace1751d6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-rxvw-rgx9-7hq4/GHSA-rxvw-rgx9-7hq4.json b/advisories/unreviewed/2023/10/GHSA-rxvw-rgx9-7hq4/GHSA-rxvw-rgx9-7hq4.json new file mode 100644 index 00000000000..d4d4c2ab939 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-rxvw-rgx9-7hq4/GHSA-rxvw-rgx9-7hq4.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxvw-rgx9-7hq4", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2023-5049" + ], + "details": "The Giveaways and Contests by RafflePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rafflepress' and 'rafflepress_gutenberg' shortcode in versions up to, and including, 1.12.0 due to insufficient input sanitization and output escaping on 'giframe' user supplied attribute. This makes it possible for authenticated attackers with contributor level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5049" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/rafflepress/tags/1.11.4/app/rafflepress.php#L796" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/rafflepress/tags/1.11.4/app/rafflepress.php#L955" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/2976620/rafflepress#file0" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a6d663a9-3185-4c36-b9d1-878297965379?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-w59p-5rf2-g7gc/GHSA-w59p-5rf2-g7gc.json b/advisories/unreviewed/2023/10/GHSA-w59p-5rf2-g7gc/GHSA-w59p-5rf2-g7gc.json new file mode 100644 index 00000000000..5679a25f3f2 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-w59p-5rf2-g7gc/GHSA-w59p-5rf2-g7gc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w59p-5rf2-g7gc", + "modified": "2023-10-30T15:30:45Z", + "published": "2023-10-30T15:30:45Z", + "aliases": [ + "CVE-2023-5315" + ], + "details": "The Google Maps made Simple plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 0.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5315" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-gmappity-easy-google-maps/tags/0.6/wpgmappity-metadata.php#L127" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/262db9aa-0db5-48cd-a85b-3e6302e88a42?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file