diff --git a/advisories/unreviewed/2023/10/GHSA-4pfv-vgmw-jgcr/GHSA-4pfv-vgmw-jgcr.json b/advisories/unreviewed/2023/10/GHSA-4pfv-vgmw-jgcr/GHSA-4pfv-vgmw-jgcr.json new file mode 100644 index 00000000000..04a71c36920 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-4pfv-vgmw-jgcr/GHSA-4pfv-vgmw-jgcr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pfv-vgmw-jgcr", + "modified": "2023-10-21T00:30:47Z", + "published": "2023-10-21T00:30:47Z", + "aliases": [ + "CVE-2023-43356" + ], + "details": "Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Global Meatadata parameter in the Global Settings Menu component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43356" + }, + { + "type": "WEB", + "url": "https://github.com/sromanhu/CVE-2023-43356-CMSmadesimple-Stored-XSS---Global-Settings" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-6h8p-4hx9-w66c/GHSA-6h8p-4hx9-w66c.json b/advisories/unreviewed/2023/10/GHSA-6h8p-4hx9-w66c/GHSA-6h8p-4hx9-w66c.json new file mode 100644 index 00000000000..43ae1b00245 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-6h8p-4hx9-w66c/GHSA-6h8p-4hx9-w66c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6h8p-4hx9-w66c", + "modified": "2023-10-21T00:30:47Z", + "published": "2023-10-21T00:30:47Z", + "aliases": [ + "CVE-2023-32786" + ], + "details": "In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32786" + }, + { + "type": "WEB", + "url": "https://gist.github.com/rharang/d265f46fc3161b31ac2e81db44d662e1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-8h5w-f6q9-wg35/GHSA-8h5w-f6q9-wg35.json b/advisories/unreviewed/2023/10/GHSA-8h5w-f6q9-wg35/GHSA-8h5w-f6q9-wg35.json new file mode 100644 index 00000000000..7458f7dc2d0 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-8h5w-f6q9-wg35/GHSA-8h5w-f6q9-wg35.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h5w-f6q9-wg35", + "modified": "2023-10-21T00:30:47Z", + "published": "2023-10-21T00:30:47Z", + "aliases": [ + "CVE-2023-32785" + ], + "details": "In Langchain through 0.0.155, prompt injection allows execution of arbitrary code against the SQL service provided by the chain.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32785" + }, + { + "type": "WEB", + "url": "https://gist.github.com/rharang/9c58d39db8c01db5b7c888e467c0533f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-jrq4-jwcw-x9x4/GHSA-jrq4-jwcw-x9x4.json b/advisories/unreviewed/2023/10/GHSA-jrq4-jwcw-x9x4/GHSA-jrq4-jwcw-x9x4.json new file mode 100644 index 00000000000..cf3f785ad52 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-jrq4-jwcw-x9x4/GHSA-jrq4-jwcw-x9x4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrq4-jwcw-x9x4", + "modified": "2023-10-21T00:30:47Z", + "published": "2023-10-21T00:30:47Z", + "aliases": [ + "CVE-2023-43353" + ], + "details": "Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the extra parameter in the news menu component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43353" + }, + { + "type": "WEB", + "url": "https://github.com/sromanhu/CVE-2023-43353-CMSmadesimple-Stored-XSS---News---Extra" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-mcm3-pfm7-4jqc/GHSA-mcm3-pfm7-4jqc.json b/advisories/unreviewed/2023/10/GHSA-mcm3-pfm7-4jqc/GHSA-mcm3-pfm7-4jqc.json new file mode 100644 index 00000000000..62938a86c12 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-mcm3-pfm7-4jqc/GHSA-mcm3-pfm7-4jqc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcm3-pfm7-4jqc", + "modified": "2023-10-21T00:30:47Z", + "published": "2023-10-21T00:30:47Z", + "aliases": [ + "CVE-2023-43355" + ], + "details": "Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the password and password again parameters in the My Preferences - Add user component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43355" + }, + { + "type": "WEB", + "url": "https://github.com/sromanhu/CMSmadesimple-Reflected-XSS---Add-user" + }, + { + "type": "WEB", + "url": "https://github.com/sromanhu/CVE-2023-43355-CMSmadesimple-Reflected-XSS---Add-user" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-pfwv-624m-h3m9/GHSA-pfwv-624m-h3m9.json b/advisories/unreviewed/2023/10/GHSA-pfwv-624m-h3m9/GHSA-pfwv-624m-h3m9.json new file mode 100644 index 00000000000..1880eb528f1 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-pfwv-624m-h3m9/GHSA-pfwv-624m-h3m9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfwv-624m-h3m9", + "modified": "2023-10-21T00:30:47Z", + "published": "2023-10-21T00:30:47Z", + "aliases": [ + "CVE-2023-38191" + ], + "details": "An issue was discovered in SuperWebMailer 9.00.0.01710. It allows spamtest_external.php XSS via a crafted filename.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38191" + }, + { + "type": "WEB", + "url": "https://herolab.usd.de/security-advisories/" + }, + { + "type": "WEB", + "url": "https://herolab.usd.de/security-advisories/usd-2023-0012/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-w74v-6wvv-qx6w/GHSA-w74v-6wvv-qx6w.json b/advisories/unreviewed/2023/10/GHSA-w74v-6wvv-qx6w/GHSA-w74v-6wvv-qx6w.json new file mode 100644 index 00000000000..83b84ab7102 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-w74v-6wvv-qx6w/GHSA-w74v-6wvv-qx6w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w74v-6wvv-qx6w", + "modified": "2023-10-21T00:30:47Z", + "published": "2023-10-21T00:30:47Z", + "aliases": [ + "CVE-2023-43354" + ], + "details": "Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Profiles parameter in the Extensions -MicroTiny WYSIWYG editor component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43354" + }, + { + "type": "WEB", + "url": "https://github.com/sromanhu/CVE-2023-43354-CMSmadesimple-Stored-XSS---MicroTIny-extension" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-wj86-wmr8-wpx4/GHSA-wj86-wmr8-wpx4.json b/advisories/unreviewed/2023/10/GHSA-wj86-wmr8-wpx4/GHSA-wj86-wmr8-wpx4.json new file mode 100644 index 00000000000..b27f511af19 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-wj86-wmr8-wpx4/GHSA-wj86-wmr8-wpx4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj86-wmr8-wpx4", + "modified": "2023-10-21T00:30:47Z", + "published": "2023-10-21T00:30:47Z", + "aliases": [ + "CVE-2023-43346" + ], + "details": "Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Backend - Dashboard parameter in the Languages Menu component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43346" + }, + { + "type": "WEB", + "url": "https://github.com/sromanhu/CVE-2023-43346-Quick-CMS-Stored-XSS---Languages-Backend" + }, + { + "type": "WEB", + "url": "https://github.com/sromanhu/Quick-CMS-Stored-XSS---Languages-Backend" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-xxvm-h2mx-9mwj/GHSA-xxvm-h2mx-9mwj.json b/advisories/unreviewed/2023/10/GHSA-xxvm-h2mx-9mwj/GHSA-xxvm-h2mx-9mwj.json new file mode 100644 index 00000000000..c11358affe7 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-xxvm-h2mx-9mwj/GHSA-xxvm-h2mx-9mwj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxvm-h2mx-9mwj", + "modified": "2023-10-21T00:30:47Z", + "published": "2023-10-21T00:30:47Z", + "aliases": [ + "CVE-2023-43357" + ], + "details": "Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the Manage Shortcuts component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43357" + }, + { + "type": "WEB", + "url": "https://github.com/sromanhu/CVE-2023-43357-CMSmadesimple-Stored-XSS---Shortcut" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file