diff --git a/advisories/unreviewed/2024/01/GHSA-3j4x-9q9q-3277/GHSA-3j4x-9q9q-3277.json b/advisories/unreviewed/2024/01/GHSA-3j4x-9q9q-3277/GHSA-3j4x-9q9q-3277.json index 9c5590bec93..0f9d6331850 100644 --- a/advisories/unreviewed/2024/01/GHSA-3j4x-9q9q-3277/GHSA-3j4x-9q9q-3277.json +++ b/advisories/unreviewed/2024/01/GHSA-3j4x-9q9q-3277/GHSA-3j4x-9q9q-3277.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3j4x-9q9q-3277", - "modified": "2024-01-12T18:30:20Z", + "modified": "2024-01-20T21:30:24Z", "published": "2024-01-12T18:30:20Z", "aliases": [ "CVE-2024-22493" ], "details": "A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save content parameter, which allows remote attackers to inject arbitrary web script or HTML.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-12T16:15:52Z" diff --git a/advisories/unreviewed/2024/01/GHSA-6358-wh5x-64mg/GHSA-6358-wh5x-64mg.json b/advisories/unreviewed/2024/01/GHSA-6358-wh5x-64mg/GHSA-6358-wh5x-64mg.json index 86723f524cd..7717d11896b 100644 --- a/advisories/unreviewed/2024/01/GHSA-6358-wh5x-64mg/GHSA-6358-wh5x-64mg.json +++ b/advisories/unreviewed/2024/01/GHSA-6358-wh5x-64mg/GHSA-6358-wh5x-64mg.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-6m7j-h7qj-2wjm/GHSA-6m7j-h7qj-2wjm.json b/advisories/unreviewed/2024/01/GHSA-6m7j-h7qj-2wjm/GHSA-6m7j-h7qj-2wjm.json index 257dbe8873b..55f85a0ca2a 100644 --- a/advisories/unreviewed/2024/01/GHSA-6m7j-h7qj-2wjm/GHSA-6m7j-h7qj-2wjm.json +++ b/advisories/unreviewed/2024/01/GHSA-6m7j-h7qj-2wjm/GHSA-6m7j-h7qj-2wjm.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-73mh-qcv6-c6ph/GHSA-73mh-qcv6-c6ph.json b/advisories/unreviewed/2024/01/GHSA-73mh-qcv6-c6ph/GHSA-73mh-qcv6-c6ph.json index 4f56991f81a..41bad4a0566 100644 --- a/advisories/unreviewed/2024/01/GHSA-73mh-qcv6-c6ph/GHSA-73mh-qcv6-c6ph.json +++ b/advisories/unreviewed/2024/01/GHSA-73mh-qcv6-c6ph/GHSA-73mh-qcv6-c6ph.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-73mh-qcv6-c6ph", - "modified": "2024-01-18T15:30:41Z", + "modified": "2024-01-20T21:30:25Z", "published": "2024-01-18T15:30:41Z", "aliases": [ "CVE-2024-22592" ], "details": "FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_update", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-18T15:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-859h-4w58-78xw/GHSA-859h-4w58-78xw.json b/advisories/unreviewed/2024/01/GHSA-859h-4w58-78xw/GHSA-859h-4w58-78xw.json index de513e73fe7..2544ce9e85f 100644 --- a/advisories/unreviewed/2024/01/GHSA-859h-4w58-78xw/GHSA-859h-4w58-78xw.json +++ b/advisories/unreviewed/2024/01/GHSA-859h-4w58-78xw/GHSA-859h-4w58-78xw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-859h-4w58-78xw", - "modified": "2024-01-12T18:30:20Z", + "modified": "2024-01-20T21:30:24Z", "published": "2024-01-12T18:30:20Z", "aliases": [ "CVE-2024-22492" ], "details": "A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save contact parameter, which allows remote attackers to inject arbitrary web script or HTML.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-12T16:15:52Z" diff --git a/advisories/unreviewed/2024/01/GHSA-8w7f-m7fg-fhfc/GHSA-8w7f-m7fg-fhfc.json b/advisories/unreviewed/2024/01/GHSA-8w7f-m7fg-fhfc/GHSA-8w7f-m7fg-fhfc.json index 44f62ac9f12..76395128cfb 100644 --- a/advisories/unreviewed/2024/01/GHSA-8w7f-m7fg-fhfc/GHSA-8w7f-m7fg-fhfc.json +++ b/advisories/unreviewed/2024/01/GHSA-8w7f-m7fg-fhfc/GHSA-8w7f-m7fg-fhfc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8w7f-m7fg-fhfc", - "modified": "2024-01-12T09:30:29Z", + "modified": "2024-01-20T21:30:24Z", "published": "2024-01-12T09:30:29Z", "aliases": [ "CVE-2023-30016" ], "details": "SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via sub_event_id parameter in sub_event_details_edit.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-12T09:15:44Z" diff --git a/advisories/unreviewed/2024/01/GHSA-c86f-jcmq-4qx2/GHSA-c86f-jcmq-4qx2.json b/advisories/unreviewed/2024/01/GHSA-c86f-jcmq-4qx2/GHSA-c86f-jcmq-4qx2.json index 7010ef963df..6df6d14e5e7 100644 --- a/advisories/unreviewed/2024/01/GHSA-c86f-jcmq-4qx2/GHSA-c86f-jcmq-4qx2.json +++ b/advisories/unreviewed/2024/01/GHSA-c86f-jcmq-4qx2/GHSA-c86f-jcmq-4qx2.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-c962-g533-823f/GHSA-c962-g533-823f.json b/advisories/unreviewed/2024/01/GHSA-c962-g533-823f/GHSA-c962-g533-823f.json index 42e8a965971..18dd207132b 100644 --- a/advisories/unreviewed/2024/01/GHSA-c962-g533-823f/GHSA-c962-g533-823f.json +++ b/advisories/unreviewed/2024/01/GHSA-c962-g533-823f/GHSA-c962-g533-823f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c962-g533-823f", - "modified": "2024-01-17T00:30:19Z", + "modified": "2024-01-20T21:30:24Z", "published": "2024-01-17T00:30:19Z", "aliases": [ "CVE-2023-36236" ], "details": "Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-16T22:15:37Z" diff --git a/advisories/unreviewed/2024/01/GHSA-chj7-w3f6-cvfj/GHSA-chj7-w3f6-cvfj.json b/advisories/unreviewed/2024/01/GHSA-chj7-w3f6-cvfj/GHSA-chj7-w3f6-cvfj.json new file mode 100644 index 00000000000..7f240a0e0cf --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-chj7-w3f6-cvfj/GHSA-chj7-w3f6-cvfj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chj7-w3f6-cvfj", + "modified": "2024-01-20T21:30:25Z", + "published": "2024-01-20T21:30:25Z", + "aliases": [ + "CVE-2024-0521" + ], + "details": "Code Injection in paddlepaddle/paddle", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0521" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/a569c64b-1e2b-4bed-a19f-47fd5a3da453" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-20T21:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-f9qq-63wv-mx2f/GHSA-f9qq-63wv-mx2f.json b/advisories/unreviewed/2024/01/GHSA-f9qq-63wv-mx2f/GHSA-f9qq-63wv-mx2f.json index 2df9e12640b..c3d28aff99e 100644 --- a/advisories/unreviewed/2024/01/GHSA-f9qq-63wv-mx2f/GHSA-f9qq-63wv-mx2f.json +++ b/advisories/unreviewed/2024/01/GHSA-f9qq-63wv-mx2f/GHSA-f9qq-63wv-mx2f.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-fr6v-xvf6-fpc3/GHSA-fr6v-xvf6-fpc3.json b/advisories/unreviewed/2024/01/GHSA-fr6v-xvf6-fpc3/GHSA-fr6v-xvf6-fpc3.json index a713cad1faa..ede2a0b58b6 100644 --- a/advisories/unreviewed/2024/01/GHSA-fr6v-xvf6-fpc3/GHSA-fr6v-xvf6-fpc3.json +++ b/advisories/unreviewed/2024/01/GHSA-fr6v-xvf6-fpc3/GHSA-fr6v-xvf6-fpc3.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-g8g5-r26f-qmjp/GHSA-g8g5-r26f-qmjp.json b/advisories/unreviewed/2024/01/GHSA-g8g5-r26f-qmjp/GHSA-g8g5-r26f-qmjp.json index bf6659b5870..7b9fee1f1ae 100644 --- a/advisories/unreviewed/2024/01/GHSA-g8g5-r26f-qmjp/GHSA-g8g5-r26f-qmjp.json +++ b/advisories/unreviewed/2024/01/GHSA-g8g5-r26f-qmjp/GHSA-g8g5-r26f-qmjp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g8g5-r26f-qmjp", - "modified": "2024-01-18T15:30:41Z", + "modified": "2024-01-20T21:30:25Z", "published": "2024-01-18T15:30:41Z", "aliases": [ "CVE-2024-22568" ], "details": "FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/del.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-18T15:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-gg96-3hrr-8jf4/GHSA-gg96-3hrr-8jf4.json b/advisories/unreviewed/2024/01/GHSA-gg96-3hrr-8jf4/GHSA-gg96-3hrr-8jf4.json index 9bc2a7dfb2d..ce00dd62373 100644 --- a/advisories/unreviewed/2024/01/GHSA-gg96-3hrr-8jf4/GHSA-gg96-3hrr-8jf4.json +++ b/advisories/unreviewed/2024/01/GHSA-gg96-3hrr-8jf4/GHSA-gg96-3hrr-8jf4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gg96-3hrr-8jf4", - "modified": "2024-01-12T18:30:20Z", + "modified": "2024-01-20T21:30:24Z", "published": "2024-01-12T18:30:20Z", "aliases": [ "CVE-2023-51978" ], "details": "In PHPGurukul Art Gallery Management System v1.1, \"Update Artist Image\" functionality of \"imageid\" parameter is vulnerable to SQL Injection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-12T16:15:52Z" diff --git a/advisories/unreviewed/2024/01/GHSA-gpc4-hgmf-4jfc/GHSA-gpc4-hgmf-4jfc.json b/advisories/unreviewed/2024/01/GHSA-gpc4-hgmf-4jfc/GHSA-gpc4-hgmf-4jfc.json index 757e568f87e..9471ef5b3fc 100644 --- a/advisories/unreviewed/2024/01/GHSA-gpc4-hgmf-4jfc/GHSA-gpc4-hgmf-4jfc.json +++ b/advisories/unreviewed/2024/01/GHSA-gpc4-hgmf-4jfc/GHSA-gpc4-hgmf-4jfc.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-hjg8-pr7m-gj33/GHSA-hjg8-pr7m-gj33.json b/advisories/unreviewed/2024/01/GHSA-hjg8-pr7m-gj33/GHSA-hjg8-pr7m-gj33.json index f879a48a6c0..e4b87698736 100644 --- a/advisories/unreviewed/2024/01/GHSA-hjg8-pr7m-gj33/GHSA-hjg8-pr7m-gj33.json +++ b/advisories/unreviewed/2024/01/GHSA-hjg8-pr7m-gj33/GHSA-hjg8-pr7m-gj33.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hjg8-pr7m-gj33", - "modified": "2024-01-12T06:30:16Z", + "modified": "2024-01-20T21:30:24Z", "published": "2024-01-12T06:30:16Z", "aliases": [ "CVE-2022-48620" ], "details": "uev (aka libuev) before 2.4.1 has a buffer overflow in epoll_wait if maxevents is a large number.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-12T04:15:08Z" diff --git a/advisories/unreviewed/2024/01/GHSA-j6v3-rqm7-vfhh/GHSA-j6v3-rqm7-vfhh.json b/advisories/unreviewed/2024/01/GHSA-j6v3-rqm7-vfhh/GHSA-j6v3-rqm7-vfhh.json index f51314639b1..ac2dae41dcb 100644 --- a/advisories/unreviewed/2024/01/GHSA-j6v3-rqm7-vfhh/GHSA-j6v3-rqm7-vfhh.json +++ b/advisories/unreviewed/2024/01/GHSA-j6v3-rqm7-vfhh/GHSA-j6v3-rqm7-vfhh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j6v3-rqm7-vfhh", - "modified": "2024-01-18T15:30:41Z", + "modified": "2024-01-20T21:30:24Z", "published": "2024-01-18T15:30:41Z", "aliases": [ "CVE-2024-22548" ], "details": "FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the system website settings website name section.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-18T15:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-jwjx-77h7-83hp/GHSA-jwjx-77h7-83hp.json b/advisories/unreviewed/2024/01/GHSA-jwjx-77h7-83hp/GHSA-jwjx-77h7-83hp.json index 9e44cca1586..78eeceb7d30 100644 --- a/advisories/unreviewed/2024/01/GHSA-jwjx-77h7-83hp/GHSA-jwjx-77h7-83hp.json +++ b/advisories/unreviewed/2024/01/GHSA-jwjx-77h7-83hp/GHSA-jwjx-77h7-83hp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jwjx-77h7-83hp", - "modified": "2024-01-18T15:30:41Z", + "modified": "2024-01-20T21:30:25Z", "published": "2024-01-18T15:30:41Z", "aliases": [ "CVE-2024-22591" ], "details": "FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_save.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-18T15:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-m3r3-chhw-2wjp/GHSA-m3r3-chhw-2wjp.json b/advisories/unreviewed/2024/01/GHSA-m3r3-chhw-2wjp/GHSA-m3r3-chhw-2wjp.json index 2a0738e8f3a..478d5f94525 100644 --- a/advisories/unreviewed/2024/01/GHSA-m3r3-chhw-2wjp/GHSA-m3r3-chhw-2wjp.json +++ b/advisories/unreviewed/2024/01/GHSA-m3r3-chhw-2wjp/GHSA-m3r3-chhw-2wjp.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-p94c-49x7-2v8m/GHSA-p94c-49x7-2v8m.json b/advisories/unreviewed/2024/01/GHSA-p94c-49x7-2v8m/GHSA-p94c-49x7-2v8m.json index 80e14c61e85..198c6000ded 100644 --- a/advisories/unreviewed/2024/01/GHSA-p94c-49x7-2v8m/GHSA-p94c-49x7-2v8m.json +++ b/advisories/unreviewed/2024/01/GHSA-p94c-49x7-2v8m/GHSA-p94c-49x7-2v8m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p94c-49x7-2v8m", - "modified": "2024-01-18T15:30:41Z", + "modified": "2024-01-20T21:30:25Z", "published": "2024-01-18T15:30:41Z", "aliases": [ "CVE-2024-22593" ], "details": "FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/add_group_save", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-18T15:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-rpm8-5pp6-j5jr/GHSA-rpm8-5pp6-j5jr.json b/advisories/unreviewed/2024/01/GHSA-rpm8-5pp6-j5jr/GHSA-rpm8-5pp6-j5jr.json index 9873f2abab4..df2d948eba4 100644 --- a/advisories/unreviewed/2024/01/GHSA-rpm8-5pp6-j5jr/GHSA-rpm8-5pp6-j5jr.json +++ b/advisories/unreviewed/2024/01/GHSA-rpm8-5pp6-j5jr/GHSA-rpm8-5pp6-j5jr.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-vh2f-9g4r-xhjf/GHSA-vh2f-9g4r-xhjf.json b/advisories/unreviewed/2024/01/GHSA-vh2f-9g4r-xhjf/GHSA-vh2f-9g4r-xhjf.json index f03dc358479..7ee9e5dbab1 100644 --- a/advisories/unreviewed/2024/01/GHSA-vh2f-9g4r-xhjf/GHSA-vh2f-9g4r-xhjf.json +++ b/advisories/unreviewed/2024/01/GHSA-vh2f-9g4r-xhjf/GHSA-vh2f-9g4r-xhjf.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/01/GHSA-w4p6-8j24-xpq3/GHSA-w4p6-8j24-xpq3.json b/advisories/unreviewed/2024/01/GHSA-w4p6-8j24-xpq3/GHSA-w4p6-8j24-xpq3.json index 600465429d4..6ee6b1bd325 100644 --- a/advisories/unreviewed/2024/01/GHSA-w4p6-8j24-xpq3/GHSA-w4p6-8j24-xpq3.json +++ b/advisories/unreviewed/2024/01/GHSA-w4p6-8j24-xpq3/GHSA-w4p6-8j24-xpq3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w4p6-8j24-xpq3", - "modified": "2024-01-18T15:30:41Z", + "modified": "2024-01-20T21:30:25Z", "published": "2024-01-18T15:30:41Z", "aliases": [ "CVE-2024-22549" ], "details": "FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the email settings of the website settings section.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-18T15:15:09Z" diff --git a/advisories/unreviewed/2024/01/GHSA-w87r-m7g7-f5v8/GHSA-w87r-m7g7-f5v8.json b/advisories/unreviewed/2024/01/GHSA-w87r-m7g7-f5v8/GHSA-w87r-m7g7-f5v8.json index 4eeb36829c5..33f3ab2302c 100644 --- a/advisories/unreviewed/2024/01/GHSA-w87r-m7g7-f5v8/GHSA-w87r-m7g7-f5v8.json +++ b/advisories/unreviewed/2024/01/GHSA-w87r-m7g7-f5v8/GHSA-w87r-m7g7-f5v8.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false,