Publish Advisories

GHSA-4pfv-vgmw-jgcr
GHSA-6h8p-4hx9-w66c
GHSA-8h5w-f6q9-wg35
GHSA-jrq4-jwcw-x9x4
GHSA-mcm3-pfm7-4jqc
GHSA-pfwv-624m-h3m9
GHSA-w74v-6wvv-qx6w
GHSA-wj86-wmr8-wpx4
GHSA-xxvm-h2mx-9mwj
This commit is contained in:
advisory-database[bot]
2023-10-21 00:31:56 +00:00
parent a6f8de3a0b
commit ba95f3b93f
9 changed files with 327 additions and 0 deletions
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4pfv-vgmw-jgcr",
"modified": "2023-10-21T00:30:47Z",
"published": "2023-10-21T00:30:47Z",
"aliases": [
"CVE-2023-43356"
],
"details": "Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Global Meatadata parameter in the Global Settings Menu component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43356"
},
{
"type": "WEB",
"url": "https://github.com/sromanhu/CVE-2023-43356-CMSmadesimple-Stored-XSS---Global-Settings"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6h8p-4hx9-w66c",
"modified": "2023-10-21T00:30:47Z",
"published": "2023-10-21T00:30:47Z",
"aliases": [
"CVE-2023-32786"
],
"details": "In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32786"
},
{
"type": "WEB",
"url": "https://gist.github.com/rharang/d265f46fc3161b31ac2e81db44d662e1"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8h5w-f6q9-wg35",
"modified": "2023-10-21T00:30:47Z",
"published": "2023-10-21T00:30:47Z",
"aliases": [
"CVE-2023-32785"
],
"details": "In Langchain through 0.0.155, prompt injection allows execution of arbitrary code against the SQL service provided by the chain.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32785"
},
{
"type": "WEB",
"url": "https://gist.github.com/rharang/9c58d39db8c01db5b7c888e467c0533f"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jrq4-jwcw-x9x4",
"modified": "2023-10-21T00:30:47Z",
"published": "2023-10-21T00:30:47Z",
"aliases": [
"CVE-2023-43353"
],
"details": "Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the extra parameter in the news menu component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43353"
},
{
"type": "WEB",
"url": "https://github.com/sromanhu/CVE-2023-43353-CMSmadesimple-Stored-XSS---News---Extra"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mcm3-pfm7-4jqc",
"modified": "2023-10-21T00:30:47Z",
"published": "2023-10-21T00:30:47Z",
"aliases": [
"CVE-2023-43355"
],
"details": "Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the password and password again parameters in the My Preferences - Add user component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43355"
},
{
"type": "WEB",
"url": "https://github.com/sromanhu/CMSmadesimple-Reflected-XSS---Add-user"
},
{
"type": "WEB",
"url": "https://github.com/sromanhu/CVE-2023-43355-CMSmadesimple-Reflected-XSS---Add-user"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pfwv-624m-h3m9",
"modified": "2023-10-21T00:30:47Z",
"published": "2023-10-21T00:30:47Z",
"aliases": [
"CVE-2023-38191"
],
"details": "An issue was discovered in SuperWebMailer 9.00.0.01710. It allows spamtest_external.php XSS via a crafted filename.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38191"
},
{
"type": "WEB",
"url": "https://herolab.usd.de/security-advisories/"
},
{
"type": "WEB",
"url": "https://herolab.usd.de/security-advisories/usd-2023-0012/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w74v-6wvv-qx6w",
"modified": "2023-10-21T00:30:47Z",
"published": "2023-10-21T00:30:47Z",
"aliases": [
"CVE-2023-43354"
],
"details": "Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Profiles parameter in the Extensions -MicroTiny WYSIWYG editor component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43354"
},
{
"type": "WEB",
"url": "https://github.com/sromanhu/CVE-2023-43354-CMSmadesimple-Stored-XSS---MicroTIny-extension"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wj86-wmr8-wpx4",
"modified": "2023-10-21T00:30:47Z",
"published": "2023-10-21T00:30:47Z",
"aliases": [
"CVE-2023-43346"
],
"details": "Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Backend - Dashboard parameter in the Languages Menu component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43346"
},
{
"type": "WEB",
"url": "https://github.com/sromanhu/CVE-2023-43346-Quick-CMS-Stored-XSS---Languages-Backend"
},
{
"type": "WEB",
"url": "https://github.com/sromanhu/Quick-CMS-Stored-XSS---Languages-Backend"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xxvm-h2mx-9mwj",
"modified": "2023-10-21T00:30:47Z",
"published": "2023-10-21T00:30:47Z",
"aliases": [
"CVE-2023-43357"
],
"details": "Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the Manage Shortcuts component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43357"
},
{
"type": "WEB",
"url": "https://github.com/sromanhu/CVE-2023-43357-CMSmadesimple-Stored-XSS---Shortcut"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}