From c3eba60ec95e04c08fb186e47f14eb80d9ead860 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 20 Aug 2024 18:32:57 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-hrww-x3fq-xcvh.json | 69 +++++++++++++++++++ .../GHSA-2734-8vv8-c662.json | 11 +-- .../GHSA-6xrw-49j6-7f3m.json | 11 +-- .../GHSA-772r-9j2c-4jvf.json | 11 +-- .../GHSA-9w56-p5q4-69pw.json | 11 +-- .../GHSA-f6rh-8x43-h7fg.json | 11 +-- .../GHSA-g7gr-43mm-gr6q.json | 11 +-- .../GHSA-rj56-c2jf-78qg.json | 11 +-- .../GHSA-42g6-fx4g-4pxv.json | 11 +-- .../GHSA-9qhr-489p-hcrq.json | 11 +-- .../GHSA-gp37-m2c5-j775.json | 11 +-- .../GHSA-h4rc-3vfw-rw96.json | 11 +-- .../GHSA-hp95-552p-6qxj.json | 11 +-- .../GHSA-mgj2-4fwc-v47j.json | 11 +-- .../GHSA-p3rv-p6mh-g8xg.json | 11 +-- .../GHSA-ppwh-5frw-h5v9.json | 11 +-- .../GHSA-r73q-v44r-mw6r.json | 2 +- .../GHSA-rqg9-hrw2-mxcf.json | 11 +-- .../GHSA-v5r5-978f-9w52.json | 11 +-- .../GHSA-v8r8-56x7-prx6.json | 11 +-- .../GHSA-5273-3j45-994v.json | 11 +-- .../GHSA-8mcw-ghrq-qxqc.json | 11 +-- .../GHSA-gc3r-pjrv-f3xv.json | 11 +-- .../GHSA-gv23-j6x4-4x4x.json | 1 + .../GHSA-q373-f6gj-mw99.json | 11 +-- .../GHSA-vmfr-35cq-g5ch.json | 2 +- .../GHSA-prvp-xgc5-f378.json | 9 ++- .../GHSA-226h-2qfh-4hf8.json | 11 +-- .../GHSA-2mh3-x6j9-j554.json | 35 ++++++++++ .../GHSA-2vfq-7gxj-92hg.json | 11 +-- .../GHSA-389v-vqc7-p3xm.json | 35 ++++++++++ .../GHSA-42gg-98x6-j389.json | 35 ++++++++++ .../GHSA-4qxp-c58r-4xg9.json | 38 ++++++++++ .../GHSA-688r-h6x5-8qpm.json | 11 +-- .../GHSA-68j4-c7vg-fcgc.json | 9 ++- .../GHSA-6pqq-98x8-92qf.json | 35 ++++++++++ .../GHSA-7pwv-g7hj-39pr.json | 10 ++- .../GHSA-8c68-8q52-rmjm.json | 11 +-- .../GHSA-96vh-rc6m-vw24.json | 11 +-- .../GHSA-9r73-v3pv-4xj4.json | 12 ++-- .../GHSA-c36j-4grh-9p4v.json | 11 +-- .../GHSA-c7jx-vf9h-c39w.json | 35 ++++++++++ .../GHSA-ch97-hpq7-jfg9.json | 6 +- .../GHSA-cwjq-hcgw-p8cp.json | 11 +-- .../GHSA-f8fv-2xcx-3x86.json | 11 +-- .../GHSA-fp6w-w9xq-jxfv.json | 11 +-- .../GHSA-fq29-72jg-5hrj.json | 9 ++- .../GHSA-g7q2-vcm2-c3q8.json | 11 +-- .../GHSA-gr6c-f4fc-5x96.json | 35 ++++++++++ .../GHSA-h95q-q7mj-92qm.json | 3 +- .../GHSA-hf49-mv84-4q97.json | 11 +-- .../GHSA-hh8p-374f-qgr5.json | 38 ++++++++++ .../GHSA-j78j-h8vv-5m5x.json | 6 +- .../GHSA-j9c3-gww2-4h3v.json | 11 +-- .../GHSA-jhpq-42hq-rch5.json | 11 +-- .../GHSA-mf3h-674w-gp32.json | 11 +-- .../GHSA-mg4j-48vm-fxmg.json | 35 ++++++++++ .../GHSA-ppwh-v8g5-pg9c.json | 11 +-- .../GHSA-q677-7pjp-5hq5.json | 35 ++++++++++ .../GHSA-qp2p-3fr2-8j54.json | 6 +- .../GHSA-wqq8-c887-jc8m.json | 11 +-- .../GHSA-xg93-f9hr-8vjh.json | 11 +-- 62 files changed, 751 insertions(+), 178 deletions(-) create mode 100644 advisories/github-reviewed/2024/08/GHSA-hrww-x3fq-xcvh/GHSA-hrww-x3fq-xcvh.json create mode 100644 advisories/unreviewed/2024/08/GHSA-2mh3-x6j9-j554/GHSA-2mh3-x6j9-j554.json create mode 100644 advisories/unreviewed/2024/08/GHSA-389v-vqc7-p3xm/GHSA-389v-vqc7-p3xm.json create mode 100644 advisories/unreviewed/2024/08/GHSA-42gg-98x6-j389/GHSA-42gg-98x6-j389.json create mode 100644 advisories/unreviewed/2024/08/GHSA-4qxp-c58r-4xg9/GHSA-4qxp-c58r-4xg9.json create mode 100644 advisories/unreviewed/2024/08/GHSA-6pqq-98x8-92qf/GHSA-6pqq-98x8-92qf.json create mode 100644 advisories/unreviewed/2024/08/GHSA-c7jx-vf9h-c39w/GHSA-c7jx-vf9h-c39w.json create mode 100644 advisories/unreviewed/2024/08/GHSA-gr6c-f4fc-5x96/GHSA-gr6c-f4fc-5x96.json create mode 100644 advisories/unreviewed/2024/08/GHSA-hh8p-374f-qgr5/GHSA-hh8p-374f-qgr5.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mg4j-48vm-fxmg/GHSA-mg4j-48vm-fxmg.json create mode 100644 advisories/unreviewed/2024/08/GHSA-q677-7pjp-5hq5/GHSA-q677-7pjp-5hq5.json diff --git a/advisories/github-reviewed/2024/08/GHSA-hrww-x3fq-xcvh/GHSA-hrww-x3fq-xcvh.json b/advisories/github-reviewed/2024/08/GHSA-hrww-x3fq-xcvh/GHSA-hrww-x3fq-xcvh.json new file mode 100644 index 00000000000..de7508fd3bc --- /dev/null +++ b/advisories/github-reviewed/2024/08/GHSA-hrww-x3fq-xcvh/GHSA-hrww-x3fq-xcvh.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrww-x3fq-xcvh", + "modified": "2024-08-20T18:32:26Z", + "published": "2024-08-20T18:32:26Z", + "aliases": [ + "CVE-2024-43377" + ], + "summary": "Umbraco CMS Improper Access Control vulnerability", + "details": "### Impact\nAs an authenticated user one can access a few unintended endpoints\n\n\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "NuGet", + "name": "Umbraco.Cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "14.0.0" + }, + { + "fixed": "14.1.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-hrww-x3fq-xcvh" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43377" + }, + { + "type": "WEB", + "url": "https://github.com/umbraco/Umbraco-CMS/commit/72bef8861d94a39d5cc9530a04c4797b91fcbecf" + }, + { + "type": "PACKAGE", + "url": "https://github.com/umbraco/Umbraco-CMS" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-08-20T18:32:26Z", + "nvd_published_at": "2024-08-20T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-2734-8vv8-c662/GHSA-2734-8vv8-c662.json b/advisories/unreviewed/2024/03/GHSA-2734-8vv8-c662/GHSA-2734-8vv8-c662.json index ded8aec61dc..da4545e6f59 100644 --- a/advisories/unreviewed/2024/03/GHSA-2734-8vv8-c662/GHSA-2734-8vv8-c662.json +++ b/advisories/unreviewed/2024/03/GHSA-2734-8vv8-c662/GHSA-2734-8vv8-c662.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2734-8vv8-c662", - "modified": "2024-03-27T00:30:54Z", + "modified": "2024-08-20T18:31:14Z", "published": "2024-03-27T00:30:54Z", "aliases": [ "CVE-2023-51146" ], "details": "Buffer Overflow vulnerability in TRENDnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_add_user action.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-121" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T22:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-6xrw-49j6-7f3m/GHSA-6xrw-49j6-7f3m.json b/advisories/unreviewed/2024/04/GHSA-6xrw-49j6-7f3m/GHSA-6xrw-49j6-7f3m.json index 04deaba31fb..25e099b404a 100644 --- a/advisories/unreviewed/2024/04/GHSA-6xrw-49j6-7f3m/GHSA-6xrw-49j6-7f3m.json +++ b/advisories/unreviewed/2024/04/GHSA-6xrw-49j6-7f3m/GHSA-6xrw-49j6-7f3m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6xrw-49j6-7f3m", - "modified": "2024-04-03T06:30:48Z", + "modified": "2024-08-20T18:31:14Z", "published": "2024-04-03T06:30:48Z", "aliases": [ "CVE-2024-31011" ], "details": "Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path that was not isolated and the suffix was not verified in admin_template.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T05:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-772r-9j2c-4jvf/GHSA-772r-9j2c-4jvf.json b/advisories/unreviewed/2024/04/GHSA-772r-9j2c-4jvf/GHSA-772r-9j2c-4jvf.json index 8772f345202..b4904d125cf 100644 --- a/advisories/unreviewed/2024/04/GHSA-772r-9j2c-4jvf/GHSA-772r-9j2c-4jvf.json +++ b/advisories/unreviewed/2024/04/GHSA-772r-9j2c-4jvf/GHSA-772r-9j2c-4jvf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-772r-9j2c-4jvf", - "modified": "2024-04-05T21:32:44Z", + "modified": "2024-08-20T18:31:14Z", "published": "2024-04-05T21:32:44Z", "aliases": [ "CVE-2024-29749" ], "details": "In tmu_set_tr_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-05T20:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9w56-p5q4-69pw/GHSA-9w56-p5q4-69pw.json b/advisories/unreviewed/2024/04/GHSA-9w56-p5q4-69pw/GHSA-9w56-p5q4-69pw.json index 9bd3e9544c1..84a53220bce 100644 --- a/advisories/unreviewed/2024/04/GHSA-9w56-p5q4-69pw/GHSA-9w56-p5q4-69pw.json +++ b/advisories/unreviewed/2024/04/GHSA-9w56-p5q4-69pw/GHSA-9w56-p5q4-69pw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9w56-p5q4-69pw", - "modified": "2024-04-16T00:30:32Z", + "modified": "2024-08-20T18:31:14Z", "published": "2024-04-16T00:30:32Z", "aliases": [ "CVE-2024-31651" ], "details": "A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the First Name parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T22:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-f6rh-8x43-h7fg/GHSA-f6rh-8x43-h7fg.json b/advisories/unreviewed/2024/04/GHSA-f6rh-8x43-h7fg/GHSA-f6rh-8x43-h7fg.json index 3f5cb688006..8f413caa8f0 100644 --- a/advisories/unreviewed/2024/04/GHSA-f6rh-8x43-h7fg/GHSA-f6rh-8x43-h7fg.json +++ b/advisories/unreviewed/2024/04/GHSA-f6rh-8x43-h7fg/GHSA-f6rh-8x43-h7fg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f6rh-8x43-h7fg", - "modified": "2024-04-09T00:30:41Z", + "modified": "2024-08-20T18:31:14Z", "published": "2024-04-09T00:30:41Z", "aliases": [ "CVE-2024-23084" ], "details": "Apfloat v1.10.1 was discovered to contain an ArrayIndexOutOfBoundsException via the component org.apfloat.internal.DoubleCRTMath::add(double[], double[]).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-129" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T23:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-g7gr-43mm-gr6q/GHSA-g7gr-43mm-gr6q.json b/advisories/unreviewed/2024/04/GHSA-g7gr-43mm-gr6q/GHSA-g7gr-43mm-gr6q.json index 995b8b5d568..bcd0cfc6c7e 100644 --- a/advisories/unreviewed/2024/04/GHSA-g7gr-43mm-gr6q/GHSA-g7gr-43mm-gr6q.json +++ b/advisories/unreviewed/2024/04/GHSA-g7gr-43mm-gr6q/GHSA-g7gr-43mm-gr6q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g7gr-43mm-gr6q", - "modified": "2024-04-29T18:30:46Z", + "modified": "2024-08-20T18:31:14Z", "published": "2024-04-29T18:30:46Z", "aliases": [ "CVE-2024-31705" ], "details": "An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insufficient validation of user-supplied input.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-29T18:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-rj56-c2jf-78qg/GHSA-rj56-c2jf-78qg.json b/advisories/unreviewed/2024/04/GHSA-rj56-c2jf-78qg/GHSA-rj56-c2jf-78qg.json index 55a131769cc..8938b6b8a08 100644 --- a/advisories/unreviewed/2024/04/GHSA-rj56-c2jf-78qg/GHSA-rj56-c2jf-78qg.json +++ b/advisories/unreviewed/2024/04/GHSA-rj56-c2jf-78qg/GHSA-rj56-c2jf-78qg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rj56-c2jf-78qg", - "modified": "2024-04-02T09:30:42Z", + "modified": "2024-08-20T18:31:14Z", "published": "2024-04-02T09:30:42Z", "aliases": [ "CVE-2024-29276" ], "details": "An issue was discovered in seeyonOA version 8, allows remote attackers to execute arbitrary code via the importProcess method in WorkFlowDesignerController.class component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:45Z" diff --git a/advisories/unreviewed/2024/05/GHSA-42g6-fx4g-4pxv/GHSA-42g6-fx4g-4pxv.json b/advisories/unreviewed/2024/05/GHSA-42g6-fx4g-4pxv/GHSA-42g6-fx4g-4pxv.json index 482c2b52ac2..869f78f6096 100644 --- a/advisories/unreviewed/2024/05/GHSA-42g6-fx4g-4pxv/GHSA-42g6-fx4g-4pxv.json +++ b/advisories/unreviewed/2024/05/GHSA-42g6-fx4g-4pxv/GHSA-42g6-fx4g-4pxv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-42g6-fx4g-4pxv", - "modified": "2024-05-22T15:31:01Z", + "modified": "2024-08-20T18:31:15Z", "published": "2024-05-22T15:31:01Z", "aliases": [ "CVE-2024-33219" ], "details": "An issue in the component AsIO64.sys of ASUSTeK Computer Inc ASUS SABERTOOTH X99 Driver v1.0.1.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-782" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T15:15:28Z" diff --git a/advisories/unreviewed/2024/05/GHSA-9qhr-489p-hcrq/GHSA-9qhr-489p-hcrq.json b/advisories/unreviewed/2024/05/GHSA-9qhr-489p-hcrq/GHSA-9qhr-489p-hcrq.json index db96bf766bc..20b3268fbab 100644 --- a/advisories/unreviewed/2024/05/GHSA-9qhr-489p-hcrq/GHSA-9qhr-489p-hcrq.json +++ b/advisories/unreviewed/2024/05/GHSA-9qhr-489p-hcrq/GHSA-9qhr-489p-hcrq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9qhr-489p-hcrq", - "modified": "2024-05-23T18:30:55Z", + "modified": "2024-08-20T18:31:15Z", "published": "2024-05-23T18:30:55Z", "aliases": [ "CVE-2024-34934" ], "details": "A SQL injection vulnerability in /view/emarks_range_grade_update_form.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-23T17:15:30Z" diff --git a/advisories/unreviewed/2024/05/GHSA-gp37-m2c5-j775/GHSA-gp37-m2c5-j775.json b/advisories/unreviewed/2024/05/GHSA-gp37-m2c5-j775/GHSA-gp37-m2c5-j775.json index 5d5cb712aaa..b8307d14130 100644 --- a/advisories/unreviewed/2024/05/GHSA-gp37-m2c5-j775/GHSA-gp37-m2c5-j775.json +++ b/advisories/unreviewed/2024/05/GHSA-gp37-m2c5-j775/GHSA-gp37-m2c5-j775.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gp37-m2c5-j775", - "modified": "2024-05-21T18:31:24Z", + "modified": "2024-08-20T18:31:14Z", "published": "2024-05-21T18:31:23Z", "aliases": [ "CVE-2024-36052" ], "details": "RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-2024-33899.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-150" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T17:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-h4rc-3vfw-rw96/GHSA-h4rc-3vfw-rw96.json b/advisories/unreviewed/2024/05/GHSA-h4rc-3vfw-rw96/GHSA-h4rc-3vfw-rw96.json index 3d484b3588c..eb1945df381 100644 --- a/advisories/unreviewed/2024/05/GHSA-h4rc-3vfw-rw96/GHSA-h4rc-3vfw-rw96.json +++ b/advisories/unreviewed/2024/05/GHSA-h4rc-3vfw-rw96/GHSA-h4rc-3vfw-rw96.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h4rc-3vfw-rw96", - "modified": "2024-05-21T18:31:24Z", + "modified": "2024-08-20T18:31:14Z", "published": "2024-05-21T18:31:24Z", "aliases": [ "CVE-2024-34240" ], "details": "QDOCS Smart School 7.0.0 is vulnerable to Cross Site Scripting (XSS) resulting in arbitrary code execution in admin functions related to adding or updating records.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T18:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-hp95-552p-6qxj/GHSA-hp95-552p-6qxj.json b/advisories/unreviewed/2024/05/GHSA-hp95-552p-6qxj/GHSA-hp95-552p-6qxj.json index fe6fc2eb16a..efae238089b 100644 --- a/advisories/unreviewed/2024/05/GHSA-hp95-552p-6qxj/GHSA-hp95-552p-6qxj.json +++ b/advisories/unreviewed/2024/05/GHSA-hp95-552p-6qxj/GHSA-hp95-552p-6qxj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hp95-552p-6qxj", - "modified": "2024-05-16T18:30:31Z", + "modified": "2024-08-20T18:31:14Z", "published": "2024-05-16T18:30:31Z", "aliases": [ "CVE-2023-48643" ], "details": "Shrubbery tac_plus 2.x, 3.x. and 4.x through F4.0.4.28 allows unauthenticated Remote Command Execution. The product allows users to configure authorization checks as shell commands through the tac_plus.cfg configuration file. These are executed when a client sends an authorization request with a username that has pre-authorization directives configured. However, it is possible to inject additional commands into these checks because strings from TACACS+ packets are used as command-line arguments. If the installation lacks a a pre-shared secret (there is no pre-shared secret by default), then the injection can be triggered without authentication. (The attacker needs to know a username configured to use a pre-authorization command.) NOTE: this is related to CVE-2023-45239 but the issue is in the original Shrubbery product, not Meta's fork.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-16T16:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-mgj2-4fwc-v47j/GHSA-mgj2-4fwc-v47j.json b/advisories/unreviewed/2024/05/GHSA-mgj2-4fwc-v47j/GHSA-mgj2-4fwc-v47j.json index 06137159b86..036cab2ec7a 100644 --- a/advisories/unreviewed/2024/05/GHSA-mgj2-4fwc-v47j/GHSA-mgj2-4fwc-v47j.json +++ b/advisories/unreviewed/2024/05/GHSA-mgj2-4fwc-v47j/GHSA-mgj2-4fwc-v47j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mgj2-4fwc-v47j", - "modified": "2024-05-22T15:30:59Z", + "modified": "2024-08-20T18:31:15Z", "published": "2024-05-22T15:30:59Z", "aliases": [ "CVE-2024-35409" ], "details": "WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T14:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-p3rv-p6mh-g8xg/GHSA-p3rv-p6mh-g8xg.json b/advisories/unreviewed/2024/05/GHSA-p3rv-p6mh-g8xg/GHSA-p3rv-p6mh-g8xg.json index e7a5d64c35c..3dd9671e1f2 100644 --- a/advisories/unreviewed/2024/05/GHSA-p3rv-p6mh-g8xg/GHSA-p3rv-p6mh-g8xg.json +++ b/advisories/unreviewed/2024/05/GHSA-p3rv-p6mh-g8xg/GHSA-p3rv-p6mh-g8xg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p3rv-p6mh-g8xg", - "modified": "2024-05-14T18:30:51Z", + "modified": "2024-08-20T18:31:14Z", "published": "2024-05-14T18:30:51Z", "aliases": [ "CVE-2024-35099" ], "details": "TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password parameter in the function loginAuth.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:39:39Z" diff --git a/advisories/unreviewed/2024/05/GHSA-ppwh-5frw-h5v9/GHSA-ppwh-5frw-h5v9.json b/advisories/unreviewed/2024/05/GHSA-ppwh-5frw-h5v9/GHSA-ppwh-5frw-h5v9.json index 8141ef285d4..717a2aedc15 100644 --- a/advisories/unreviewed/2024/05/GHSA-ppwh-5frw-h5v9/GHSA-ppwh-5frw-h5v9.json +++ b/advisories/unreviewed/2024/05/GHSA-ppwh-5frw-h5v9/GHSA-ppwh-5frw-h5v9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ppwh-5frw-h5v9", - "modified": "2024-05-14T18:31:00Z", + "modified": "2024-08-20T18:31:14Z", "published": "2024-05-14T18:31:00Z", "aliases": [ "CVE-2024-32350" ], "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the \"ipsecPsk\" parameter in the \"cstecgi.cgi\" binary.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T16:17:02Z" diff --git a/advisories/unreviewed/2024/05/GHSA-r73q-v44r-mw6r/GHSA-r73q-v44r-mw6r.json b/advisories/unreviewed/2024/05/GHSA-r73q-v44r-mw6r/GHSA-r73q-v44r-mw6r.json index 5f15db9be55..973d04bcc2b 100644 --- a/advisories/unreviewed/2024/05/GHSA-r73q-v44r-mw6r/GHSA-r73q-v44r-mw6r.json +++ b/advisories/unreviewed/2024/05/GHSA-r73q-v44r-mw6r/GHSA-r73q-v44r-mw6r.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-rqg9-hrw2-mxcf/GHSA-rqg9-hrw2-mxcf.json b/advisories/unreviewed/2024/05/GHSA-rqg9-hrw2-mxcf/GHSA-rqg9-hrw2-mxcf.json index e18ba369399..0d20ad0776a 100644 --- a/advisories/unreviewed/2024/05/GHSA-rqg9-hrw2-mxcf/GHSA-rqg9-hrw2-mxcf.json +++ b/advisories/unreviewed/2024/05/GHSA-rqg9-hrw2-mxcf/GHSA-rqg9-hrw2-mxcf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rqg9-hrw2-mxcf", - "modified": "2024-05-14T18:31:00Z", + "modified": "2024-08-20T18:31:14Z", "published": "2024-05-14T18:31:00Z", "aliases": [ "CVE-2024-32351" ], "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the \"mru\" parameter in the \"cstecgi.cgi\" binary.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T16:17:02Z" diff --git a/advisories/unreviewed/2024/05/GHSA-v5r5-978f-9w52/GHSA-v5r5-978f-9w52.json b/advisories/unreviewed/2024/05/GHSA-v5r5-978f-9w52/GHSA-v5r5-978f-9w52.json index c21f0c54fa1..4395286f373 100644 --- a/advisories/unreviewed/2024/05/GHSA-v5r5-978f-9w52/GHSA-v5r5-978f-9w52.json +++ b/advisories/unreviewed/2024/05/GHSA-v5r5-978f-9w52/GHSA-v5r5-978f-9w52.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v5r5-978f-9w52", - "modified": "2024-05-22T15:31:00Z", + "modified": "2024-08-20T18:31:14Z", "published": "2024-05-22T15:31:00Z", "aliases": [ "CVE-2024-35556" ], "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsSys_deal.php?mudi=infoSet.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T14:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-v8r8-56x7-prx6/GHSA-v8r8-56x7-prx6.json b/advisories/unreviewed/2024/05/GHSA-v8r8-56x7-prx6/GHSA-v8r8-56x7-prx6.json index 4bd6ea4ac19..5cf90542fa6 100644 --- a/advisories/unreviewed/2024/05/GHSA-v8r8-56x7-prx6/GHSA-v8r8-56x7-prx6.json +++ b/advisories/unreviewed/2024/05/GHSA-v8r8-56x7-prx6/GHSA-v8r8-56x7-prx6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v8r8-56x7-prx6", - "modified": "2024-05-20T18:31:23Z", + "modified": "2024-08-20T18:31:14Z", "published": "2024-05-20T18:31:23Z", "aliases": [ "CVE-2024-34193" ], "details": "smanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vulnerability that can cause arbitrary file reading.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-20T18:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-5273-3j45-994v/GHSA-5273-3j45-994v.json b/advisories/unreviewed/2024/06/GHSA-5273-3j45-994v/GHSA-5273-3j45-994v.json index 3cc5416a2e8..78969d96008 100644 --- a/advisories/unreviewed/2024/06/GHSA-5273-3j45-994v/GHSA-5273-3j45-994v.json +++ b/advisories/unreviewed/2024/06/GHSA-5273-3j45-994v/GHSA-5273-3j45-994v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5273-3j45-994v", - "modified": "2024-06-06T18:30:57Z", + "modified": "2024-08-20T18:31:15Z", "published": "2024-06-06T18:30:57Z", "aliases": [ "CVE-2024-36737" ], "details": "Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the oneflow.full parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-20" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-06T18:15:16Z" diff --git a/advisories/unreviewed/2024/06/GHSA-8mcw-ghrq-qxqc/GHSA-8mcw-ghrq-qxqc.json b/advisories/unreviewed/2024/06/GHSA-8mcw-ghrq-qxqc/GHSA-8mcw-ghrq-qxqc.json index 2bd74dafbee..977617059ae 100644 --- a/advisories/unreviewed/2024/06/GHSA-8mcw-ghrq-qxqc/GHSA-8mcw-ghrq-qxqc.json +++ b/advisories/unreviewed/2024/06/GHSA-8mcw-ghrq-qxqc/GHSA-8mcw-ghrq-qxqc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8mcw-ghrq-qxqc", - "modified": "2024-06-07T21:31:54Z", + "modified": "2024-08-20T18:31:15Z", "published": "2024-06-07T21:31:54Z", "aliases": [ "CVE-2023-49221" ], "details": "Precor touchscreen console P62, P80, and P82 could allow a remote attacker (within the local network) to bypass security restrictions, and access the service menu, because there is a hard-coded service code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-798" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-07T20:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-gc3r-pjrv-f3xv/GHSA-gc3r-pjrv-f3xv.json b/advisories/unreviewed/2024/06/GHSA-gc3r-pjrv-f3xv/GHSA-gc3r-pjrv-f3xv.json index a1fd0fcdaed..87f99198bef 100644 --- a/advisories/unreviewed/2024/06/GHSA-gc3r-pjrv-f3xv/GHSA-gc3r-pjrv-f3xv.json +++ b/advisories/unreviewed/2024/06/GHSA-gc3r-pjrv-f3xv/GHSA-gc3r-pjrv-f3xv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gc3r-pjrv-f3xv", - "modified": "2024-06-13T21:30:55Z", + "modified": "2024-08-20T18:31:15Z", "published": "2024-06-13T21:30:55Z", "aliases": [ "CVE-2024-32921" ], "details": "In lwis_initialize_transaction_fences of lwis_fence.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T21:15:55Z" diff --git a/advisories/unreviewed/2024/06/GHSA-gv23-j6x4-4x4x/GHSA-gv23-j6x4-4x4x.json b/advisories/unreviewed/2024/06/GHSA-gv23-j6x4-4x4x/GHSA-gv23-j6x4-4x4x.json index 3c7ba8f6249..cabe10046d5 100644 --- a/advisories/unreviewed/2024/06/GHSA-gv23-j6x4-4x4x/GHSA-gv23-j6x4-4x4x.json +++ b/advisories/unreviewed/2024/06/GHSA-gv23-j6x4-4x4x/GHSA-gv23-j6x4-4x4x.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-204" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/06/GHSA-q373-f6gj-mw99/GHSA-q373-f6gj-mw99.json b/advisories/unreviewed/2024/06/GHSA-q373-f6gj-mw99/GHSA-q373-f6gj-mw99.json index 8f750e1f4a5..b9d003786ac 100644 --- a/advisories/unreviewed/2024/06/GHSA-q373-f6gj-mw99/GHSA-q373-f6gj-mw99.json +++ b/advisories/unreviewed/2024/06/GHSA-q373-f6gj-mw99/GHSA-q373-f6gj-mw99.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q373-f6gj-mw99", - "modified": "2024-06-17T00:31:06Z", + "modified": "2024-08-20T18:31:15Z", "published": "2024-06-17T00:31:06Z", "aliases": [ "CVE-2024-34451" ], "details": "Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is that Ghost should be installed with a reverse proxy that allows only trusted X-Forwarded-For headers.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1390" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-16T22:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-vmfr-35cq-g5ch/GHSA-vmfr-35cq-g5ch.json b/advisories/unreviewed/2024/06/GHSA-vmfr-35cq-g5ch/GHSA-vmfr-35cq-g5ch.json index 0e87054f1a9..0b8c768e42c 100644 --- a/advisories/unreviewed/2024/06/GHSA-vmfr-35cq-g5ch/GHSA-vmfr-35cq-g5ch.json +++ b/advisories/unreviewed/2024/06/GHSA-vmfr-35cq-g5ch/GHSA-vmfr-35cq-g5ch.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-250" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-prvp-xgc5-f378/GHSA-prvp-xgc5-f378.json b/advisories/unreviewed/2024/07/GHSA-prvp-xgc5-f378/GHSA-prvp-xgc5-f378.json index 31666064794..82303bb7c2e 100644 --- a/advisories/unreviewed/2024/07/GHSA-prvp-xgc5-f378/GHSA-prvp-xgc5-f378.json +++ b/advisories/unreviewed/2024/07/GHSA-prvp-xgc5-f378/GHSA-prvp-xgc5-f378.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-prvp-xgc5-f378", - "modified": "2024-07-30T03:30:52Z", + "modified": "2024-08-20T18:31:20Z", "published": "2024-07-30T00:34:26Z", "aliases": [ "CVE-2024-40778" ], "details": "An authentication issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.6, iOS 17.6 and iPadOS 17.6, iOS 16.7.9 and iPadOS 16.7.9. Photos in the Hidden Photos Album may be viewed without authentication.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T23:15:11Z" diff --git a/advisories/unreviewed/2024/08/GHSA-226h-2qfh-4hf8/GHSA-226h-2qfh-4hf8.json b/advisories/unreviewed/2024/08/GHSA-226h-2qfh-4hf8/GHSA-226h-2qfh-4hf8.json index 647f1fff61c..bcbd1279f99 100644 --- a/advisories/unreviewed/2024/08/GHSA-226h-2qfh-4hf8/GHSA-226h-2qfh-4hf8.json +++ b/advisories/unreviewed/2024/08/GHSA-226h-2qfh-4hf8/GHSA-226h-2qfh-4hf8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-226h-2qfh-4hf8", - "modified": "2024-08-20T15:32:12Z", + "modified": "2024-08-20T18:31:25Z", "published": "2024-08-20T15:32:12Z", "aliases": [ "CVE-2024-42562" ], "details": "Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T13:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2mh3-x6j9-j554/GHSA-2mh3-x6j9-j554.json b/advisories/unreviewed/2024/08/GHSA-2mh3-x6j9-j554/GHSA-2mh3-x6j9-j554.json new file mode 100644 index 00000000000..4839535e6f6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-2mh3-x6j9-j554/GHSA-2mh3-x6j9-j554.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mh3-x6j9-j554", + "modified": "2024-08-20T18:31:26Z", + "published": "2024-08-20T18:31:26Z", + "aliases": [ + "CVE-2024-27186" + ], + "details": "The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27186" + }, + { + "type": "WEB", + "url": "https://developer.joomla.org/security-centre/944-20240803-core-xss-in-html-mail-templates.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-2vfq-7gxj-92hg/GHSA-2vfq-7gxj-92hg.json b/advisories/unreviewed/2024/08/GHSA-2vfq-7gxj-92hg/GHSA-2vfq-7gxj-92hg.json index 1b51f20fde5..7566eab9faa 100644 --- a/advisories/unreviewed/2024/08/GHSA-2vfq-7gxj-92hg/GHSA-2vfq-7gxj-92hg.json +++ b/advisories/unreviewed/2024/08/GHSA-2vfq-7gxj-92hg/GHSA-2vfq-7gxj-92hg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2vfq-7gxj-92hg", - "modified": "2024-08-20T15:32:12Z", + "modified": "2024-08-20T18:31:24Z", "published": "2024-08-20T15:32:12Z", "aliases": [ "CVE-2024-42553" ], "details": "A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T13:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-389v-vqc7-p3xm/GHSA-389v-vqc7-p3xm.json b/advisories/unreviewed/2024/08/GHSA-389v-vqc7-p3xm/GHSA-389v-vqc7-p3xm.json new file mode 100644 index 00000000000..eabb0f2eb87 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-389v-vqc7-p3xm/GHSA-389v-vqc7-p3xm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-389v-vqc7-p3xm", + "modified": "2024-08-20T18:31:26Z", + "published": "2024-08-20T18:31:26Z", + "aliases": [ + "CVE-2024-42612" + ], + "details": "Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?whitelist_add", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42612" + }, + { + "type": "WEB", + "url": "https://github.com/jinwu1234567890/cms2/tree/main/5/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-42gg-98x6-j389/GHSA-42gg-98x6-j389.json b/advisories/unreviewed/2024/08/GHSA-42gg-98x6-j389/GHSA-42gg-98x6-j389.json new file mode 100644 index 00000000000..a51954ccb7f --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-42gg-98x6-j389/GHSA-42gg-98x6-j389.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42gg-98x6-j389", + "modified": "2024-08-20T18:31:26Z", + "published": "2024-08-20T18:31:26Z", + "aliases": [ + "CVE-2024-42598" + ], + "details": "SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42598" + }, + { + "type": "WEB", + "url": "https://gitee.com/fushuling/cve/blob/master/SeaCMS%20V13%20admin_editplayer.php%20code%20injection.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4qxp-c58r-4xg9/GHSA-4qxp-c58r-4xg9.json b/advisories/unreviewed/2024/08/GHSA-4qxp-c58r-4xg9/GHSA-4qxp-c58r-4xg9.json new file mode 100644 index 00000000000..fd7d22de9a0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4qxp-c58r-4xg9/GHSA-4qxp-c58r-4xg9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qxp-c58r-4xg9", + "modified": "2024-08-20T18:31:26Z", + "published": "2024-08-20T18:31:26Z", + "aliases": [ + "CVE-2024-35214" + ], + "details": "A tampering vulnerability in the CylanceOPTICS Windows Installer Package of CylanceOPTICS for Windows version 3.2 and 3.3 could allow an attacker to potentially uninstall CylanceOPTICS from a system thereby leaving it with only the protection of CylancePROTECT.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35214" + }, + { + "type": "WEB", + "url": "https://support.blackberry.com/pkb/s/article/140080" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-688r-h6x5-8qpm/GHSA-688r-h6x5-8qpm.json b/advisories/unreviewed/2024/08/GHSA-688r-h6x5-8qpm/GHSA-688r-h6x5-8qpm.json index d8c8313f691..d8ac804a78a 100644 --- a/advisories/unreviewed/2024/08/GHSA-688r-h6x5-8qpm/GHSA-688r-h6x5-8qpm.json +++ b/advisories/unreviewed/2024/08/GHSA-688r-h6x5-8qpm/GHSA-688r-h6x5-8qpm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-688r-h6x5-8qpm", - "modified": "2024-08-20T15:32:13Z", + "modified": "2024-08-20T18:31:26Z", "published": "2024-08-20T15:32:13Z", "aliases": [ "CVE-2024-42576" ], "details": "A Cross-Site Request Forgery (CSRF) in the component edit_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T13:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-68j4-c7vg-fcgc/GHSA-68j4-c7vg-fcgc.json b/advisories/unreviewed/2024/08/GHSA-68j4-c7vg-fcgc/GHSA-68j4-c7vg-fcgc.json index a24d4ac51ad..3c0067791a7 100644 --- a/advisories/unreviewed/2024/08/GHSA-68j4-c7vg-fcgc/GHSA-68j4-c7vg-fcgc.json +++ b/advisories/unreviewed/2024/08/GHSA-68j4-c7vg-fcgc/GHSA-68j4-c7vg-fcgc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-68j4-c7vg-fcgc", - "modified": "2024-08-08T09:30:37Z", + "modified": "2024-08-20T18:31:20Z", "published": "2024-08-08T09:30:37Z", "aliases": [ "CVE-2024-42031" ], "details": "Access permission verification vulnerability in the Settings module.\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-08T09:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-6pqq-98x8-92qf/GHSA-6pqq-98x8-92qf.json b/advisories/unreviewed/2024/08/GHSA-6pqq-98x8-92qf/GHSA-6pqq-98x8-92qf.json new file mode 100644 index 00000000000..97e640553c0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-6pqq-98x8-92qf/GHSA-6pqq-98x8-92qf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pqq-98x8-92qf", + "modified": "2024-08-20T18:31:26Z", + "published": "2024-08-20T18:31:26Z", + "aliases": [ + "CVE-2024-27187" + ], + "details": "Improper Access Controls allows backend users to overwrite their username when disallowed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27187" + }, + { + "type": "WEB", + "url": "https://developer.joomla.org/security-centre/945-20240804-core-improper-acl-for-backend-profile-view.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7pwv-g7hj-39pr/GHSA-7pwv-g7hj-39pr.json b/advisories/unreviewed/2024/08/GHSA-7pwv-g7hj-39pr/GHSA-7pwv-g7hj-39pr.json index 50695368280..72874cf9cdb 100644 --- a/advisories/unreviewed/2024/08/GHSA-7pwv-g7hj-39pr/GHSA-7pwv-g7hj-39pr.json +++ b/advisories/unreviewed/2024/08/GHSA-7pwv-g7hj-39pr/GHSA-7pwv-g7hj-39pr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7pwv-g7hj-39pr", - "modified": "2024-08-19T21:35:10Z", + "modified": "2024-08-20T18:31:21Z", "published": "2024-08-19T21:35:10Z", "aliases": [ "CVE-2024-7592" ], "details": "There is a LOW severity vulnerability affecting CPython, specifically the\n'http.cookies' standard library module.\n\n\nWhen parsing cookies that contained backslashes for quoted characters in\nthe cookie value, the parser would use an algorithm with quadratic\ncomplexity, resulting in excess CPU resources being used while parsing the\nvalue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,10 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1333", "CWE-400" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-19T19:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-8c68-8q52-rmjm/GHSA-8c68-8q52-rmjm.json b/advisories/unreviewed/2024/08/GHSA-8c68-8q52-rmjm/GHSA-8c68-8q52-rmjm.json index 3b72887b2a7..dbd1741d153 100644 --- a/advisories/unreviewed/2024/08/GHSA-8c68-8q52-rmjm/GHSA-8c68-8q52-rmjm.json +++ b/advisories/unreviewed/2024/08/GHSA-8c68-8q52-rmjm/GHSA-8c68-8q52-rmjm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8c68-8q52-rmjm", - "modified": "2024-08-19T21:35:10Z", + "modified": "2024-08-20T18:31:21Z", "published": "2024-08-19T21:35:10Z", "aliases": [ "CVE-2024-23729" ], "details": "The ColorOS Internet Browser com.heytap.browser application 45.10.3.4.1 for Android allows a remote attacker to execute arbitrary JavaScript code via the com.android.browser.RealBrowserActivity component.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-19T19:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-96vh-rc6m-vw24/GHSA-96vh-rc6m-vw24.json b/advisories/unreviewed/2024/08/GHSA-96vh-rc6m-vw24/GHSA-96vh-rc6m-vw24.json index 5c2eaaae54e..5eb6db17a2b 100644 --- a/advisories/unreviewed/2024/08/GHSA-96vh-rc6m-vw24/GHSA-96vh-rc6m-vw24.json +++ b/advisories/unreviewed/2024/08/GHSA-96vh-rc6m-vw24/GHSA-96vh-rc6m-vw24.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-96vh-rc6m-vw24", - "modified": "2024-08-15T21:31:20Z", + "modified": "2024-08-20T18:31:21Z", "published": "2024-08-15T21:31:19Z", "aliases": [ "CVE-2024-42757" ], "details": "Command injection vulnerability in Asus RT-N15U 3.0.0.4.376_3754 allows a remote attacker to execute arbitrary code via the netstat function page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-15T19:15:19Z" diff --git a/advisories/unreviewed/2024/08/GHSA-9r73-v3pv-4xj4/GHSA-9r73-v3pv-4xj4.json b/advisories/unreviewed/2024/08/GHSA-9r73-v3pv-4xj4/GHSA-9r73-v3pv-4xj4.json index 0491dc10137..224da54bbc5 100644 --- a/advisories/unreviewed/2024/08/GHSA-9r73-v3pv-4xj4/GHSA-9r73-v3pv-4xj4.json +++ b/advisories/unreviewed/2024/08/GHSA-9r73-v3pv-4xj4/GHSA-9r73-v3pv-4xj4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9r73-v3pv-4xj4", - "modified": "2024-08-19T18:32:08Z", + "modified": "2024-08-20T18:31:21Z", "published": "2024-08-19T18:32:08Z", "aliases": [ "CVE-2024-42657" ], "details": "An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption during login process", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -33,9 +36,10 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200", + "CWE-311" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-19T17:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-c36j-4grh-9p4v/GHSA-c36j-4grh-9p4v.json b/advisories/unreviewed/2024/08/GHSA-c36j-4grh-9p4v/GHSA-c36j-4grh-9p4v.json index 8ce55a7a661..b8dbce08bc9 100644 --- a/advisories/unreviewed/2024/08/GHSA-c36j-4grh-9p4v/GHSA-c36j-4grh-9p4v.json +++ b/advisories/unreviewed/2024/08/GHSA-c36j-4grh-9p4v/GHSA-c36j-4grh-9p4v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c36j-4grh-9p4v", - "modified": "2024-08-20T15:32:13Z", + "modified": "2024-08-20T18:31:26Z", "published": "2024-08-20T15:32:13Z", "aliases": [ "CVE-2024-42611" ], "details": "Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/admin_page.php?link_id=1&mode=delete", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T15:15:22Z" diff --git a/advisories/unreviewed/2024/08/GHSA-c7jx-vf9h-c39w/GHSA-c7jx-vf9h-c39w.json b/advisories/unreviewed/2024/08/GHSA-c7jx-vf9h-c39w/GHSA-c7jx-vf9h-c39w.json new file mode 100644 index 00000000000..813962bb7d0 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c7jx-vf9h-c39w/GHSA-c7jx-vf9h-c39w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7jx-vf9h-c39w", + "modified": "2024-08-20T18:31:26Z", + "published": "2024-08-20T18:31:26Z", + "aliases": [ + "CVE-2024-27184" + ], + "details": "Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27184" + }, + { + "type": "WEB", + "url": "https://developer.joomla.org/security-centre/941-20240801-core-inadequate-validation-of-internal-urls.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ch97-hpq7-jfg9/GHSA-ch97-hpq7-jfg9.json b/advisories/unreviewed/2024/08/GHSA-ch97-hpq7-jfg9/GHSA-ch97-hpq7-jfg9.json index 3b0cdf57efd..8af925a22ee 100644 --- a/advisories/unreviewed/2024/08/GHSA-ch97-hpq7-jfg9/GHSA-ch97-hpq7-jfg9.json +++ b/advisories/unreviewed/2024/08/GHSA-ch97-hpq7-jfg9/GHSA-ch97-hpq7-jfg9.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ch97-hpq7-jfg9", - "modified": "2024-08-14T18:32:43Z", + "modified": "2024-08-20T18:31:20Z", "published": "2024-08-14T18:32:43Z", "aliases": [ "CVE-2024-5915" ], "details": "A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Amber" diff --git a/advisories/unreviewed/2024/08/GHSA-cwjq-hcgw-p8cp/GHSA-cwjq-hcgw-p8cp.json b/advisories/unreviewed/2024/08/GHSA-cwjq-hcgw-p8cp/GHSA-cwjq-hcgw-p8cp.json index 01c5fdd8f36..a69aa780b85 100644 --- a/advisories/unreviewed/2024/08/GHSA-cwjq-hcgw-p8cp/GHSA-cwjq-hcgw-p8cp.json +++ b/advisories/unreviewed/2024/08/GHSA-cwjq-hcgw-p8cp/GHSA-cwjq-hcgw-p8cp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cwjq-hcgw-p8cp", - "modified": "2024-08-20T15:32:12Z", + "modified": "2024-08-20T18:31:26Z", "published": "2024-08-20T15:32:12Z", "aliases": [ "CVE-2024-42571" ], "details": "School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at insertattendance.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T13:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-f8fv-2xcx-3x86/GHSA-f8fv-2xcx-3x86.json b/advisories/unreviewed/2024/08/GHSA-f8fv-2xcx-3x86/GHSA-f8fv-2xcx-3x86.json index 492b350ec1f..f26124dfcf3 100644 --- a/advisories/unreviewed/2024/08/GHSA-f8fv-2xcx-3x86/GHSA-f8fv-2xcx-3x86.json +++ b/advisories/unreviewed/2024/08/GHSA-f8fv-2xcx-3x86/GHSA-f8fv-2xcx-3x86.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f8fv-2xcx-3x86", - "modified": "2024-08-20T15:32:12Z", + "modified": "2024-08-20T18:31:24Z", "published": "2024-08-20T15:32:12Z", "aliases": [ "CVE-2024-42555" ], "details": "A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T13:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-fp6w-w9xq-jxfv/GHSA-fp6w-w9xq-jxfv.json b/advisories/unreviewed/2024/08/GHSA-fp6w-w9xq-jxfv/GHSA-fp6w-w9xq-jxfv.json index c8b5b46ed23..8fa48e27461 100644 --- a/advisories/unreviewed/2024/08/GHSA-fp6w-w9xq-jxfv/GHSA-fp6w-w9xq-jxfv.json +++ b/advisories/unreviewed/2024/08/GHSA-fp6w-w9xq-jxfv/GHSA-fp6w-w9xq-jxfv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fp6w-w9xq-jxfv", - "modified": "2024-08-20T15:32:12Z", + "modified": "2024-08-20T18:31:25Z", "published": "2024-08-20T15:32:12Z", "aliases": [ "CVE-2024-42560" ], "details": "A cross-site scripting (XSS) vulnerability in the component update_page_details.php of Blood Bank And Donation Management System commit dc9e039 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Details parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T13:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-fq29-72jg-5hrj/GHSA-fq29-72jg-5hrj.json b/advisories/unreviewed/2024/08/GHSA-fq29-72jg-5hrj/GHSA-fq29-72jg-5hrj.json index 1c68abf748b..12573196afd 100644 --- a/advisories/unreviewed/2024/08/GHSA-fq29-72jg-5hrj/GHSA-fq29-72jg-5hrj.json +++ b/advisories/unreviewed/2024/08/GHSA-fq29-72jg-5hrj/GHSA-fq29-72jg-5hrj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fq29-72jg-5hrj", - "modified": "2024-08-19T18:32:07Z", + "modified": "2024-08-20T18:31:21Z", "published": "2024-08-19T18:32:07Z", "aliases": [ "CVE-2024-32928" ], "details": "The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-19T17:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-g7q2-vcm2-c3q8/GHSA-g7q2-vcm2-c3q8.json b/advisories/unreviewed/2024/08/GHSA-g7q2-vcm2-c3q8/GHSA-g7q2-vcm2-c3q8.json index ceae83cadba..5a71790e915 100644 --- a/advisories/unreviewed/2024/08/GHSA-g7q2-vcm2-c3q8/GHSA-g7q2-vcm2-c3q8.json +++ b/advisories/unreviewed/2024/08/GHSA-g7q2-vcm2-c3q8/GHSA-g7q2-vcm2-c3q8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g7q2-vcm2-c3q8", - "modified": "2024-08-20T15:32:12Z", + "modified": "2024-08-20T18:31:25Z", "published": "2024-08-20T15:32:12Z", "aliases": [ "CVE-2024-42561" ], "details": "Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at sales_report.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T13:15:06Z" diff --git a/advisories/unreviewed/2024/08/GHSA-gr6c-f4fc-5x96/GHSA-gr6c-f4fc-5x96.json b/advisories/unreviewed/2024/08/GHSA-gr6c-f4fc-5x96/GHSA-gr6c-f4fc-5x96.json new file mode 100644 index 00000000000..34147baa8a4 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-gr6c-f4fc-5x96/GHSA-gr6c-f4fc-5x96.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr6c-f4fc-5x96", + "modified": "2024-08-20T18:31:26Z", + "published": "2024-08-20T18:31:26Z", + "aliases": [ + "CVE-2024-42919" + ], + "details": "eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42919" + }, + { + "type": "WEB", + "url": "https://github.com/jeyabalaji711/CVE-2024-42919" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T17:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-h95q-q7mj-92qm/GHSA-h95q-q7mj-92qm.json b/advisories/unreviewed/2024/08/GHSA-h95q-q7mj-92qm/GHSA-h95q-q7mj-92qm.json index 4e98fef9a11..e806c9ee851 100644 --- a/advisories/unreviewed/2024/08/GHSA-h95q-q7mj-92qm/GHSA-h95q-q7mj-92qm.json +++ b/advisories/unreviewed/2024/08/GHSA-h95q-q7mj-92qm/GHSA-h95q-q7mj-92qm.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-hf49-mv84-4q97/GHSA-hf49-mv84-4q97.json b/advisories/unreviewed/2024/08/GHSA-hf49-mv84-4q97/GHSA-hf49-mv84-4q97.json index ae2e018907e..45259318c58 100644 --- a/advisories/unreviewed/2024/08/GHSA-hf49-mv84-4q97/GHSA-hf49-mv84-4q97.json +++ b/advisories/unreviewed/2024/08/GHSA-hf49-mv84-4q97/GHSA-hf49-mv84-4q97.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hf49-mv84-4q97", - "modified": "2024-08-20T15:32:13Z", + "modified": "2024-08-20T18:31:26Z", "published": "2024-08-20T15:32:13Z", "aliases": [ "CVE-2024-35540" ], "details": "A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T15:15:21Z" diff --git a/advisories/unreviewed/2024/08/GHSA-hh8p-374f-qgr5/GHSA-hh8p-374f-qgr5.json b/advisories/unreviewed/2024/08/GHSA-hh8p-374f-qgr5/GHSA-hh8p-374f-qgr5.json new file mode 100644 index 00000000000..0c2a3592d9d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hh8p-374f-qgr5/GHSA-hh8p-374f-qgr5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh8p-374f-qgr5", + "modified": "2024-08-20T18:31:26Z", + "published": "2024-08-20T18:31:26Z", + "aliases": [ + "CVE-2024-6322" + ], + "details": "Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must have prior query access to the impacted datasource.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6322" + }, + { + "type": "WEB", + "url": "https://grafana.com/security/security-advisories/cve-2024-6322" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j78j-h8vv-5m5x/GHSA-j78j-h8vv-5m5x.json b/advisories/unreviewed/2024/08/GHSA-j78j-h8vv-5m5x/GHSA-j78j-h8vv-5m5x.json index 579e9dcce61..3e7422bd5e4 100644 --- a/advisories/unreviewed/2024/08/GHSA-j78j-h8vv-5m5x/GHSA-j78j-h8vv-5m5x.json +++ b/advisories/unreviewed/2024/08/GHSA-j78j-h8vv-5m5x/GHSA-j78j-h8vv-5m5x.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j78j-h8vv-5m5x", - "modified": "2024-08-14T18:32:43Z", + "modified": "2024-08-20T18:31:20Z", "published": "2024-08-14T18:32:43Z", "aliases": [ "CVE-2024-5914" ], "details": "A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber" diff --git a/advisories/unreviewed/2024/08/GHSA-j9c3-gww2-4h3v/GHSA-j9c3-gww2-4h3v.json b/advisories/unreviewed/2024/08/GHSA-j9c3-gww2-4h3v/GHSA-j9c3-gww2-4h3v.json index 048f11ffbb2..4141f7df200 100644 --- a/advisories/unreviewed/2024/08/GHSA-j9c3-gww2-4h3v/GHSA-j9c3-gww2-4h3v.json +++ b/advisories/unreviewed/2024/08/GHSA-j9c3-gww2-4h3v/GHSA-j9c3-gww2-4h3v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j9c3-gww2-4h3v", - "modified": "2024-08-20T15:32:13Z", + "modified": "2024-08-20T18:31:26Z", "published": "2024-08-20T15:32:13Z", "aliases": [ "CVE-2024-42585" ], "details": "A Cross-Site Request Forgery (CSRF) in the component delete_media.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T13:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-jhpq-42hq-rch5/GHSA-jhpq-42hq-rch5.json b/advisories/unreviewed/2024/08/GHSA-jhpq-42hq-rch5/GHSA-jhpq-42hq-rch5.json index 6f358f393e8..e331cd072a8 100644 --- a/advisories/unreviewed/2024/08/GHSA-jhpq-42hq-rch5/GHSA-jhpq-42hq-rch5.json +++ b/advisories/unreviewed/2024/08/GHSA-jhpq-42hq-rch5/GHSA-jhpq-42hq-rch5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jhpq-42hq-rch5", - "modified": "2024-08-20T15:32:13Z", + "modified": "2024-08-20T18:31:26Z", "published": "2024-08-20T15:32:13Z", "aliases": [ "CVE-2024-42586" ], "details": "A Cross-Site Request Forgery (CSRF) in the component categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T13:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-mf3h-674w-gp32/GHSA-mf3h-674w-gp32.json b/advisories/unreviewed/2024/08/GHSA-mf3h-674w-gp32/GHSA-mf3h-674w-gp32.json index 173eb95298f..9607bf4447b 100644 --- a/advisories/unreviewed/2024/08/GHSA-mf3h-674w-gp32/GHSA-mf3h-674w-gp32.json +++ b/advisories/unreviewed/2024/08/GHSA-mf3h-674w-gp32/GHSA-mf3h-674w-gp32.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mf3h-674w-gp32", - "modified": "2024-08-20T15:32:12Z", + "modified": "2024-08-20T18:31:26Z", "published": "2024-08-20T15:32:12Z", "aliases": [ "CVE-2024-42569" ], "details": "School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T13:15:07Z" diff --git a/advisories/unreviewed/2024/08/GHSA-mg4j-48vm-fxmg/GHSA-mg4j-48vm-fxmg.json b/advisories/unreviewed/2024/08/GHSA-mg4j-48vm-fxmg/GHSA-mg4j-48vm-fxmg.json new file mode 100644 index 00000000000..504b3c04ae1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mg4j-48vm-fxmg/GHSA-mg4j-48vm-fxmg.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mg4j-48vm-fxmg", + "modified": "2024-08-20T18:31:26Z", + "published": "2024-08-20T18:31:26Z", + "aliases": [ + "CVE-2024-40743" + ], + "details": "The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40743" + }, + { + "type": "WEB", + "url": "https://developer.joomla.org/security-centre/946-20240805-core-xss-vectors-in-outputfilter-strip-methods.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T16:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ppwh-v8g5-pg9c/GHSA-ppwh-v8g5-pg9c.json b/advisories/unreviewed/2024/08/GHSA-ppwh-v8g5-pg9c/GHSA-ppwh-v8g5-pg9c.json index 84b0f17323b..27f741c6ae1 100644 --- a/advisories/unreviewed/2024/08/GHSA-ppwh-v8g5-pg9c/GHSA-ppwh-v8g5-pg9c.json +++ b/advisories/unreviewed/2024/08/GHSA-ppwh-v8g5-pg9c/GHSA-ppwh-v8g5-pg9c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ppwh-v8g5-pg9c", - "modified": "2024-08-19T18:32:07Z", + "modified": "2024-08-20T18:31:20Z", "published": "2024-08-19T18:32:07Z", "aliases": [ "CVE-2024-42633" ], "details": "A Command Injection vulnerability exists in the do_upgrade_post function of the httpd binary in Linksys E1500 v1.0.06.001. As a result, an authenticated attacker can execute OS commands with root privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-19T16:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-q677-7pjp-5hq5/GHSA-q677-7pjp-5hq5.json b/advisories/unreviewed/2024/08/GHSA-q677-7pjp-5hq5/GHSA-q677-7pjp-5hq5.json new file mode 100644 index 00000000000..d7d409f43ad --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q677-7pjp-5hq5/GHSA-q677-7pjp-5hq5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q677-7pjp-5hq5", + "modified": "2024-08-20T18:31:26Z", + "published": "2024-08-20T18:31:26Z", + "aliases": [ + "CVE-2024-27185" + ], + "details": "The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27185" + }, + { + "type": "WEB", + "url": "https://developer.joomla.org/security-centre/942-20240802-core-cache-poisoning-in-pagination.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-20T16:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qp2p-3fr2-8j54/GHSA-qp2p-3fr2-8j54.json b/advisories/unreviewed/2024/08/GHSA-qp2p-3fr2-8j54/GHSA-qp2p-3fr2-8j54.json index c48f366372b..2efdcecb59b 100644 --- a/advisories/unreviewed/2024/08/GHSA-qp2p-3fr2-8j54/GHSA-qp2p-3fr2-8j54.json +++ b/advisories/unreviewed/2024/08/GHSA-qp2p-3fr2-8j54/GHSA-qp2p-3fr2-8j54.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qp2p-3fr2-8j54", - "modified": "2024-08-19T18:32:07Z", + "modified": "2024-08-20T18:31:21Z", "published": "2024-08-19T18:32:07Z", "aliases": [ "CVE-2024-6348" ], "details": "Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection Sensor ECU in Nissan Altima (2022) allows attackers to predict the requested seeds and bypass security controls via repeated ECU resets and seed requests.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:D/RE:H/U:X" diff --git a/advisories/unreviewed/2024/08/GHSA-wqq8-c887-jc8m/GHSA-wqq8-c887-jc8m.json b/advisories/unreviewed/2024/08/GHSA-wqq8-c887-jc8m/GHSA-wqq8-c887-jc8m.json index 549a1982855..e413031e469 100644 --- a/advisories/unreviewed/2024/08/GHSA-wqq8-c887-jc8m/GHSA-wqq8-c887-jc8m.json +++ b/advisories/unreviewed/2024/08/GHSA-wqq8-c887-jc8m/GHSA-wqq8-c887-jc8m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wqq8-c887-jc8m", - "modified": "2024-08-20T15:32:13Z", + "modified": "2024-08-20T18:31:26Z", "published": "2024-08-20T15:32:13Z", "aliases": [ "CVE-2024-42617" ], "details": "Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_config.php?action=save&var_id=32", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T15:15:22Z" diff --git a/advisories/unreviewed/2024/08/GHSA-xg93-f9hr-8vjh/GHSA-xg93-f9hr-8vjh.json b/advisories/unreviewed/2024/08/GHSA-xg93-f9hr-8vjh/GHSA-xg93-f9hr-8vjh.json index 5f4b66642d8..034ec8e5660 100644 --- a/advisories/unreviewed/2024/08/GHSA-xg93-f9hr-8vjh/GHSA-xg93-f9hr-8vjh.json +++ b/advisories/unreviewed/2024/08/GHSA-xg93-f9hr-8vjh/GHSA-xg93-f9hr-8vjh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xg93-f9hr-8vjh", - "modified": "2024-08-20T15:32:12Z", + "modified": "2024-08-20T18:31:24Z", "published": "2024-08-20T15:32:12Z", "aliases": [ "CVE-2024-42554" ], "details": "Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_added.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-20T13:15:06Z"