Publish Advisories

GHSA-3j4x-9q9q-3277
GHSA-6358-wh5x-64mg
GHSA-6m7j-h7qj-2wjm
GHSA-73mh-qcv6-c6ph
GHSA-859h-4w58-78xw
GHSA-8w7f-m7fg-fhfc
GHSA-c86f-jcmq-4qx2
GHSA-c962-g533-823f
GHSA-chj7-w3f6-cvfj
GHSA-f9qq-63wv-mx2f
GHSA-fr6v-xvf6-fpc3
GHSA-g8g5-r26f-qmjp
GHSA-gg96-3hrr-8jf4
GHSA-gpc4-hgmf-4jfc
GHSA-hjg8-pr7m-gj33
GHSA-j6v3-rqm7-vfhh
GHSA-jwjx-77h7-83hp
GHSA-m3r3-chhw-2wjp
GHSA-p94c-49x7-2v8m
GHSA-rpm8-5pp6-j5jr
GHSA-vh2f-9g4r-xhjf
GHSA-w4p6-8j24-xpq3
GHSA-w87r-m7g7-f5v8
This commit is contained in:
advisory-database[bot]
2024-01-20 21:31:43 +00:00
parent 325f625e33
commit b8c6edb7eb
23 changed files with 142 additions and 58 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3j4x-9q9q-3277",
"modified": "2024-01-12T18:30:20Z",
"modified": "2024-01-20T21:30:24Z",
"published": "2024-01-12T18:30:20Z",
"aliases": [
"CVE-2024-22493"
],
"details": "A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save content parameter, which allows remote attackers to inject arbitrary web script or HTML.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-12T16:15:52Z"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-73mh-qcv6-c6ph",
"modified": "2024-01-18T15:30:41Z",
"modified": "2024-01-20T21:30:25Z",
"published": "2024-01-18T15:30:41Z",
"aliases": [
"CVE-2024-22592"
],
"details": "FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_update",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-18T15:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-859h-4w58-78xw",
"modified": "2024-01-12T18:30:20Z",
"modified": "2024-01-20T21:30:24Z",
"published": "2024-01-12T18:30:20Z",
"aliases": [
"CVE-2024-22492"
],
"details": "A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save contact parameter, which allows remote attackers to inject arbitrary web script or HTML.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-12T16:15:52Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8w7f-m7fg-fhfc",
"modified": "2024-01-12T09:30:29Z",
"modified": "2024-01-20T21:30:24Z",
"published": "2024-01-12T09:30:29Z",
"aliases": [
"CVE-2023-30016"
],
"details": "SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via sub_event_id parameter in sub_event_details_edit.php.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-12T09:15:44Z"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c962-g533-823f",
"modified": "2024-01-17T00:30:19Z",
"modified": "2024-01-20T21:30:24Z",
"published": "2024-01-17T00:30:19Z",
"aliases": [
"CVE-2023-36236"
],
"details": "Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T22:15:37Z"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-chj7-w3f6-cvfj",
"modified": "2024-01-20T21:30:25Z",
"published": "2024-01-20T21:30:25Z",
"aliases": [
"CVE-2024-0521"
],
"details": "Code Injection in paddlepaddle/paddle",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0521"
},
{
"type": "WEB",
"url": "https://huntr.com/bounties/a569c64b-1e2b-4bed-a19f-47fd5a3da453"
}
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-20T21:15:43Z"
}
}
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-120"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g8g5-r26f-qmjp",
"modified": "2024-01-18T15:30:41Z",
"modified": "2024-01-20T21:30:25Z",
"published": "2024-01-18T15:30:41Z",
"aliases": [
"CVE-2024-22568"
],
"details": "FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/del.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-18T15:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gg96-3hrr-8jf4",
"modified": "2024-01-12T18:30:20Z",
"modified": "2024-01-20T21:30:24Z",
"published": "2024-01-12T18:30:20Z",
"aliases": [
"CVE-2023-51978"
],
"details": "In PHPGurukul Art Gallery Management System v1.1, \"Update Artist Image\" functionality of \"imageid\" parameter is vulnerable to SQL Injection.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-12T16:15:52Z"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hjg8-pr7m-gj33",
"modified": "2024-01-12T06:30:16Z",
"modified": "2024-01-20T21:30:24Z",
"published": "2024-01-12T06:30:16Z",
"aliases": [
"CVE-2022-48620"
],
"details": "uev (aka libuev) before 2.4.1 has a buffer overflow in epoll_wait if maxevents is a large number.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-12T04:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j6v3-rqm7-vfhh",
"modified": "2024-01-18T15:30:41Z",
"modified": "2024-01-20T21:30:24Z",
"published": "2024-01-18T15:30:41Z",
"aliases": [
"CVE-2024-22548"
],
"details": "FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the system website settings website name section.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-18T15:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jwjx-77h7-83hp",
"modified": "2024-01-18T15:30:41Z",
"modified": "2024-01-20T21:30:25Z",
"published": "2024-01-18T15:30:41Z",
"aliases": [
"CVE-2024-22591"
],
"details": "FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_save.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-18T15:15:09Z"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p94c-49x7-2v8m",
"modified": "2024-01-18T15:30:41Z",
"modified": "2024-01-20T21:30:25Z",
"published": "2024-01-18T15:30:41Z",
"aliases": [
"CVE-2024-22593"
],
"details": "FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/add_group_save",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-18T15:15:09Z"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-120"
],
"severity": "HIGH",
"github_reviewed": false,

Some files were not shown because too many files have changed in this diff Show More