From c76022df449f0017da40b014cda63dbea55d0e88 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 4 Oct 2024 21:33:09 +0000 Subject: [PATCH] Publish Advisories GHSA-3hcg-q7pg-7hmq GHSA-7q48-m9w3-vrpc GHSA-g8xq-w7g6-jc3v GHSA-w3gp-gprx-5vj8 GHSA-52p8-m5r2-c245 GHSA-69rg-jv6m-76wg GHSA-85hj-g8gj-8mxh GHSA-86v7-vj99-fqvm GHSA-8cpm-p3f3-45f7 GHSA-8wx5-f2gv-24cc GHSA-c49j-87c4-mmr5 GHSA-gv59-h7rc-cxvr GHSA-hmr6-x7h8-r5mp GHSA-j6px-w88f-j869 GHSA-mf33-2wpg-fv43 GHSA-mjg9-2fc5-7g27 GHSA-mwp3-45p3-xq9x GHSA-r25f-mfgv-vq97 GHSA-rwh5-jx2j-64h2 GHSA-vf2m-6wph-fchf GHSA-x22r-xgr5-23hh GHSA-xr9g-f9v2-9m3h --- .../GHSA-3hcg-q7pg-7hmq.json | 2 +- .../GHSA-7q48-m9w3-vrpc.json | 2 +- .../GHSA-g8xq-w7g6-jc3v.json | 6 ++- .../GHSA-w3gp-gprx-5vj8.json | 7 ++- .../GHSA-52p8-m5r2-c245.json | 39 +++++++++++++++++ .../GHSA-69rg-jv6m-76wg.json | 42 ++++++++++++++++++ .../GHSA-85hj-g8gj-8mxh.json | 39 +++++++++++++++++ .../GHSA-86v7-vj99-fqvm.json | 38 ++++++++++++++++ .../GHSA-8cpm-p3f3-45f7.json | 39 +++++++++++++++++ .../GHSA-8wx5-f2gv-24cc.json | 10 ++++- .../GHSA-c49j-87c4-mmr5.json | 43 +++++++++++++++++++ .../GHSA-gv59-h7rc-cxvr.json | 39 +++++++++++++++++ .../GHSA-hmr6-x7h8-r5mp.json | 42 ++++++++++++++++++ .../GHSA-j6px-w88f-j869.json | 10 ++++- .../GHSA-mf33-2wpg-fv43.json | 42 ++++++++++++++++++ .../GHSA-mjg9-2fc5-7g27.json | 35 +++++++++++++++ .../GHSA-mwp3-45p3-xq9x.json | 42 ++++++++++++++++++ .../GHSA-r25f-mfgv-vq97.json | 42 ++++++++++++++++++ .../GHSA-rwh5-jx2j-64h2.json | 10 ++++- .../GHSA-vf2m-6wph-fchf.json | 39 +++++++++++++++++ .../GHSA-x22r-xgr5-23hh.json | 42 ++++++++++++++++++ .../GHSA-xr9g-f9v2-9m3h.json | 42 ++++++++++++++++++ 22 files changed, 645 insertions(+), 7 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-52p8-m5r2-c245/GHSA-52p8-m5r2-c245.json create mode 100644 advisories/unreviewed/2024/10/GHSA-69rg-jv6m-76wg/GHSA-69rg-jv6m-76wg.json create mode 100644 advisories/unreviewed/2024/10/GHSA-85hj-g8gj-8mxh/GHSA-85hj-g8gj-8mxh.json create mode 100644 advisories/unreviewed/2024/10/GHSA-86v7-vj99-fqvm/GHSA-86v7-vj99-fqvm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8cpm-p3f3-45f7/GHSA-8cpm-p3f3-45f7.json create mode 100644 advisories/unreviewed/2024/10/GHSA-c49j-87c4-mmr5/GHSA-c49j-87c4-mmr5.json create mode 100644 advisories/unreviewed/2024/10/GHSA-gv59-h7rc-cxvr/GHSA-gv59-h7rc-cxvr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-hmr6-x7h8-r5mp/GHSA-hmr6-x7h8-r5mp.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mf33-2wpg-fv43/GHSA-mf33-2wpg-fv43.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mjg9-2fc5-7g27/GHSA-mjg9-2fc5-7g27.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mwp3-45p3-xq9x/GHSA-mwp3-45p3-xq9x.json create mode 100644 advisories/unreviewed/2024/10/GHSA-r25f-mfgv-vq97/GHSA-r25f-mfgv-vq97.json create mode 100644 advisories/unreviewed/2024/10/GHSA-vf2m-6wph-fchf/GHSA-vf2m-6wph-fchf.json create mode 100644 advisories/unreviewed/2024/10/GHSA-x22r-xgr5-23hh/GHSA-x22r-xgr5-23hh.json create mode 100644 advisories/unreviewed/2024/10/GHSA-xr9g-f9v2-9m3h/GHSA-xr9g-f9v2-9m3h.json diff --git a/advisories/unreviewed/2024/09/GHSA-3hcg-q7pg-7hmq/GHSA-3hcg-q7pg-7hmq.json b/advisories/unreviewed/2024/09/GHSA-3hcg-q7pg-7hmq/GHSA-3hcg-q7pg-7hmq.json index aac0331177e..9f48263060a 100644 --- a/advisories/unreviewed/2024/09/GHSA-3hcg-q7pg-7hmq/GHSA-3hcg-q7pg-7hmq.json +++ b/advisories/unreviewed/2024/09/GHSA-3hcg-q7pg-7hmq/GHSA-3hcg-q7pg-7hmq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3hcg-q7pg-7hmq", - "modified": "2024-09-27T09:30:30Z", + "modified": "2024-10-04T21:31:29Z", "published": "2024-09-27T09:30:30Z", "aliases": [ "CVE-2024-9049" diff --git a/advisories/unreviewed/2024/09/GHSA-7q48-m9w3-vrpc/GHSA-7q48-m9w3-vrpc.json b/advisories/unreviewed/2024/09/GHSA-7q48-m9w3-vrpc/GHSA-7q48-m9w3-vrpc.json index 7cf4d45e748..b75b80f41f8 100644 --- a/advisories/unreviewed/2024/09/GHSA-7q48-m9w3-vrpc/GHSA-7q48-m9w3-vrpc.json +++ b/advisories/unreviewed/2024/09/GHSA-7q48-m9w3-vrpc/GHSA-7q48-m9w3-vrpc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7q48-m9w3-vrpc", - "modified": "2024-09-27T09:30:30Z", + "modified": "2024-10-04T21:31:29Z", "published": "2024-09-27T09:30:30Z", "aliases": [ "CVE-2024-8991" diff --git a/advisories/unreviewed/2024/09/GHSA-g8xq-w7g6-jc3v/GHSA-g8xq-w7g6-jc3v.json b/advisories/unreviewed/2024/09/GHSA-g8xq-w7g6-jc3v/GHSA-g8xq-w7g6-jc3v.json index 50ee396538b..05139aaef7f 100644 --- a/advisories/unreviewed/2024/09/GHSA-g8xq-w7g6-jc3v/GHSA-g8xq-w7g6-jc3v.json +++ b/advisories/unreviewed/2024/09/GHSA-g8xq-w7g6-jc3v/GHSA-g8xq-w7g6-jc3v.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g8xq-w7g6-jc3v", - "modified": "2024-09-26T18:31:45Z", + "modified": "2024-10-04T21:31:28Z", "published": "2024-09-26T18:31:45Z", "aliases": [ "CVE-2024-47128" ], "details": "The goTenna Pro broadcast key name is always sent unencrypted and could reveal the location of operation.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/09/GHSA-w3gp-gprx-5vj8/GHSA-w3gp-gprx-5vj8.json b/advisories/unreviewed/2024/09/GHSA-w3gp-gprx-5vj8/GHSA-w3gp-gprx-5vj8.json index 619342987f0..d3a6193e831 100644 --- a/advisories/unreviewed/2024/09/GHSA-w3gp-gprx-5vj8/GHSA-w3gp-gprx-5vj8.json +++ b/advisories/unreviewed/2024/09/GHSA-w3gp-gprx-5vj8/GHSA-w3gp-gprx-5vj8.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w3gp-gprx-5vj8", - "modified": "2024-09-26T18:31:45Z", + "modified": "2024-10-04T21:31:28Z", "published": "2024-09-26T18:31:45Z", "aliases": [ "CVE-2024-47125" ], "details": "The goTenna Pro series does not authenticate public keys which allows an unauthenticated attacker to intercept and manipulate messages.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -28,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-923" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/10/GHSA-52p8-m5r2-c245/GHSA-52p8-m5r2-c245.json b/advisories/unreviewed/2024/10/GHSA-52p8-m5r2-c245/GHSA-52p8-m5r2-c245.json new file mode 100644 index 00000000000..5f7997e86cd --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-52p8-m5r2-c245/GHSA-52p8-m5r2-c245.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52p8-m5r2-c245", + "modified": "2024-10-04T21:31:29Z", + "published": "2024-10-04T21:31:29Z", + "aliases": [ + "CVE-2024-46077" + ], + "details": "itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46077" + }, + { + "type": "WEB", + "url": "https://github.com/n00bS3cLe4rner/CVE-s/blob/main/CVE-2024-46077.md" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-69rg-jv6m-76wg/GHSA-69rg-jv6m-76wg.json b/advisories/unreviewed/2024/10/GHSA-69rg-jv6m-76wg/GHSA-69rg-jv6m-76wg.json new file mode 100644 index 00000000000..9c790552ac5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-69rg-jv6m-76wg/GHSA-69rg-jv6m-76wg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69rg-jv6m-76wg", + "modified": "2024-10-04T21:31:30Z", + "published": "2024-10-04T21:31:30Z", + "aliases": [ + "CVE-2024-9054" + ], + "details": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Microchip TimeProvider 4100 (Configuration modules) allows Command Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9054" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + }, + { + "type": "WEB", + "url": "https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities/timeprovider-4100-grandmaster-rce-through-configuration-file" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-85hj-g8gj-8mxh/GHSA-85hj-g8gj-8mxh.json b/advisories/unreviewed/2024/10/GHSA-85hj-g8gj-8mxh/GHSA-85hj-g8gj-8mxh.json new file mode 100644 index 00000000000..41efe964507 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-85hj-g8gj-8mxh/GHSA-85hj-g8gj-8mxh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85hj-g8gj-8mxh", + "modified": "2024-10-04T21:31:29Z", + "published": "2024-10-04T21:31:29Z", + "aliases": [ + "CVE-2023-26771" + ], + "details": "Taskcafe 0.3.2 is vulnerable to Cross Site Scripting (XSS). There is a lack of validation in the filetype when uploading a SVG profile picture with a XSS payload on it. An authenticated attacker can exploit this vulnerability by uploading a malicious picture which will trigger the payload when the victim opens the file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26771" + }, + { + "type": "WEB", + "url": "https://bishopfox.com/blog/taskcafe-version-0-3-2-advisory" + }, + { + "type": "WEB", + "url": "https://github.com/JordanKnott/taskcafe" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-86v7-vj99-fqvm/GHSA-86v7-vj99-fqvm.json b/advisories/unreviewed/2024/10/GHSA-86v7-vj99-fqvm/GHSA-86v7-vj99-fqvm.json new file mode 100644 index 00000000000..1fe1eeace84 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-86v7-vj99-fqvm/GHSA-86v7-vj99-fqvm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86v7-vj99-fqvm", + "modified": "2024-10-04T21:31:30Z", + "published": "2024-10-04T21:31:30Z", + "aliases": [ + "CVE-2024-47911" + ], + "details": "In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint that allows SonarQube users with the administrator role to inject blind SQL commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47911" + }, + { + "type": "WEB", + "url": "https://sonarsource.atlassian.net/browse/SONAR-22340" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8cpm-p3f3-45f7/GHSA-8cpm-p3f3-45f7.json b/advisories/unreviewed/2024/10/GHSA-8cpm-p3f3-45f7/GHSA-8cpm-p3f3-45f7.json new file mode 100644 index 00000000000..5fdd1097007 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8cpm-p3f3-45f7/GHSA-8cpm-p3f3-45f7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cpm-p3f3-45f7", + "modified": "2024-10-04T21:31:30Z", + "published": "2024-10-04T21:31:30Z", + "aliases": [ + "CVE-2024-37868" + ], + "details": "File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the \"sendreply.php\" file, and the uploaded file was received using the \"$- FILES\" variable.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37868" + }, + { + "type": "WEB", + "url": "https://github.com/TERRENCE-REX/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://gist.github.com/TERRENCE-REX/bfca92171143e28899bb8511f311f9ed" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8wx5-f2gv-24cc/GHSA-8wx5-f2gv-24cc.json b/advisories/unreviewed/2024/10/GHSA-8wx5-f2gv-24cc/GHSA-8wx5-f2gv-24cc.json index a4d723d7b2d..d8f5252eddf 100644 --- a/advisories/unreviewed/2024/10/GHSA-8wx5-f2gv-24cc/GHSA-8wx5-f2gv-24cc.json +++ b/advisories/unreviewed/2024/10/GHSA-8wx5-f2gv-24cc/GHSA-8wx5-f2gv-24cc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8wx5-f2gv-24cc", - "modified": "2024-10-04T18:31:11Z", + "modified": "2024-10-04T21:31:29Z", "published": "2024-10-04T18:31:11Z", "aliases": [ "CVE-2024-41512" @@ -21,6 +21,14 @@ { "type": "WEB", "url": "https://piuswalter.de/blog/multiple-critical-vulnerabilities-in-cadclick" + }, + { + "type": "WEB", + "url": "http://cadclick.de" + }, + { + "type": "WEB", + "url": "http://kimweb.de" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-c49j-87c4-mmr5/GHSA-c49j-87c4-mmr5.json b/advisories/unreviewed/2024/10/GHSA-c49j-87c4-mmr5/GHSA-c49j-87c4-mmr5.json new file mode 100644 index 00000000000..e7cbdd42093 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c49j-87c4-mmr5/GHSA-c49j-87c4-mmr5.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c49j-87c4-mmr5", + "modified": "2024-10-04T21:31:30Z", + "published": "2024-10-04T21:31:30Z", + "aliases": [ + "CVE-2024-47910" + ], + "details": "An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing configuration of a GitHub integration to exfiltrate a pre-signed JWT.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47910" + }, + { + "type": "WEB", + "url": "https://community.sonarsource.com/t/sonarqube-github-integration-information-leakage/126609" + }, + { + "type": "WEB", + "url": "https://sonarsource.atlassian.net/browse/SONAR-21795" + }, + { + "type": "WEB", + "url": "https://sonarsource.atlassian.net/browse/SONAR-21813" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gv59-h7rc-cxvr/GHSA-gv59-h7rc-cxvr.json b/advisories/unreviewed/2024/10/GHSA-gv59-h7rc-cxvr/GHSA-gv59-h7rc-cxvr.json new file mode 100644 index 00000000000..eff29241853 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-gv59-h7rc-cxvr/GHSA-gv59-h7rc-cxvr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv59-h7rc-cxvr", + "modified": "2024-10-04T21:31:29Z", + "published": "2024-10-04T21:31:29Z", + "aliases": [ + "CVE-2023-26770" + ], + "details": "TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can change the password of that user.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26770" + }, + { + "type": "WEB", + "url": "https://bishopfox.com/blog/taskcafe-version-0-3-2-advisory" + }, + { + "type": "WEB", + "url": "https://github.com/JordanKnott/taskcafe" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T19:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hmr6-x7h8-r5mp/GHSA-hmr6-x7h8-r5mp.json b/advisories/unreviewed/2024/10/GHSA-hmr6-x7h8-r5mp/GHSA-hmr6-x7h8-r5mp.json new file mode 100644 index 00000000000..e8e0c313f16 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hmr6-x7h8-r5mp/GHSA-hmr6-x7h8-r5mp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmr6-x7h8-r5mp", + "modified": "2024-10-04T21:31:30Z", + "published": "2024-10-04T21:31:30Z", + "aliases": [ + "CVE-2024-7801" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProvider 4100 (Data plot modules) allows SQL Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7801" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + }, + { + "type": "WEB", + "url": "https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities/timeprovider-4100-grandmaster-unathenticated-sql-injection" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j6px-w88f-j869/GHSA-j6px-w88f-j869.json b/advisories/unreviewed/2024/10/GHSA-j6px-w88f-j869/GHSA-j6px-w88f-j869.json index 53ab29bb353..292d4a543f5 100644 --- a/advisories/unreviewed/2024/10/GHSA-j6px-w88f-j869/GHSA-j6px-w88f-j869.json +++ b/advisories/unreviewed/2024/10/GHSA-j6px-w88f-j869/GHSA-j6px-w88f-j869.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j6px-w88f-j869", - "modified": "2024-10-04T18:31:11Z", + "modified": "2024-10-04T21:31:29Z", "published": "2024-10-04T18:31:11Z", "aliases": [ "CVE-2024-41514" @@ -21,6 +21,14 @@ { "type": "WEB", "url": "https://piuswalter.de/blog/multiple-critical-vulnerabilities-in-cadclick" + }, + { + "type": "WEB", + "url": "http://cadclick.de" + }, + { + "type": "WEB", + "url": "http://kimweb.de" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-mf33-2wpg-fv43/GHSA-mf33-2wpg-fv43.json b/advisories/unreviewed/2024/10/GHSA-mf33-2wpg-fv43/GHSA-mf33-2wpg-fv43.json new file mode 100644 index 00000000000..6de19b72963 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mf33-2wpg-fv43/GHSA-mf33-2wpg-fv43.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf33-2wpg-fv43", + "modified": "2024-10-04T21:31:29Z", + "published": "2024-10-04T21:31:29Z", + "aliases": [ + "CVE-2024-43686" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (data plot modules) allows Reflected XSS.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Green" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43686" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + }, + { + "type": "WEB", + "url": "https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities/timeprovider-4100-grandmaster-reflected-xss-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T20:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mjg9-2fc5-7g27/GHSA-mjg9-2fc5-7g27.json b/advisories/unreviewed/2024/10/GHSA-mjg9-2fc5-7g27/GHSA-mjg9-2fc5-7g27.json new file mode 100644 index 00000000000..472f5b7c74b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mjg9-2fc5-7g27/GHSA-mjg9-2fc5-7g27.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjg9-2fc5-7g27", + "modified": "2024-10-04T21:31:29Z", + "published": "2024-10-04T21:31:29Z", + "aliases": [ + "CVE-2024-46078" + ], + "details": "itsourcecode Sports Management System Project 1.0 is vulnerable to SQL Injection in the function delete_category of the file sports_scheduling/player.php via the argument id.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46078" + }, + { + "type": "WEB", + "url": "https://github.com/n00bS3cLe4rner/CVE-s/blob/main/CVE-2024-46078.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T19:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mwp3-45p3-xq9x/GHSA-mwp3-45p3-xq9x.json b/advisories/unreviewed/2024/10/GHSA-mwp3-45p3-xq9x/GHSA-mwp3-45p3-xq9x.json new file mode 100644 index 00000000000..51efc15b303 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mwp3-45p3-xq9x/GHSA-mwp3-45p3-xq9x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwp3-45p3-xq9x", + "modified": "2024-10-04T21:31:29Z", + "published": "2024-10-04T21:31:29Z", + "aliases": [ + "CVE-2024-43685" + ], + "details": "Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43685" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + }, + { + "type": "WEB", + "url": "https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities/timeprovider-4100-grandmaster-session-token-fixation" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T20:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r25f-mfgv-vq97/GHSA-r25f-mfgv-vq97.json b/advisories/unreviewed/2024/10/GHSA-r25f-mfgv-vq97/GHSA-r25f-mfgv-vq97.json new file mode 100644 index 00000000000..e4b11294ea9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r25f-mfgv-vq97/GHSA-r25f-mfgv-vq97.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r25f-mfgv-vq97", + "modified": "2024-10-04T21:31:29Z", + "published": "2024-10-04T21:31:29Z", + "aliases": [ + "CVE-2024-43687" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner config modules) allows Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0 before 2.4.7.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Green" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43687" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + }, + { + "type": "WEB", + "url": "https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities/timeprovider-4100-grandmaster-stored-xss-vulnerability-in-banner" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T20:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rwh5-jx2j-64h2/GHSA-rwh5-jx2j-64h2.json b/advisories/unreviewed/2024/10/GHSA-rwh5-jx2j-64h2/GHSA-rwh5-jx2j-64h2.json index 0964127041e..69f7efff763 100644 --- a/advisories/unreviewed/2024/10/GHSA-rwh5-jx2j-64h2/GHSA-rwh5-jx2j-64h2.json +++ b/advisories/unreviewed/2024/10/GHSA-rwh5-jx2j-64h2/GHSA-rwh5-jx2j-64h2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rwh5-jx2j-64h2", - "modified": "2024-10-04T18:31:11Z", + "modified": "2024-10-04T21:31:29Z", "published": "2024-10-04T18:31:11Z", "aliases": [ "CVE-2024-41513" @@ -21,6 +21,14 @@ { "type": "WEB", "url": "https://piuswalter.de/blog/multiple-critical-vulnerabilities-in-cadclick" + }, + { + "type": "WEB", + "url": "http://cadclick.de" + }, + { + "type": "WEB", + "url": "http://kimweb.de" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-vf2m-6wph-fchf/GHSA-vf2m-6wph-fchf.json b/advisories/unreviewed/2024/10/GHSA-vf2m-6wph-fchf/GHSA-vf2m-6wph-fchf.json new file mode 100644 index 00000000000..964cfb6d08b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vf2m-6wph-fchf/GHSA-vf2m-6wph-fchf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vf2m-6wph-fchf", + "modified": "2024-10-04T21:31:30Z", + "published": "2024-10-04T21:31:30Z", + "aliases": [ + "CVE-2024-37869" + ], + "details": "File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the \"poster.php\" file, and the uploaded file was received using the \"$- FILES\" variable", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37869" + }, + { + "type": "WEB", + "url": "https://github.com/TERRENCE-REX/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://gist.github.com/TERRENCE-REX/7e5dfdd3583bf9fd81196f557a8b8879" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T21:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-x22r-xgr5-23hh/GHSA-x22r-xgr5-23hh.json b/advisories/unreviewed/2024/10/GHSA-x22r-xgr5-23hh/GHSA-x22r-xgr5-23hh.json new file mode 100644 index 00000000000..92a6f77acec --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-x22r-xgr5-23hh/GHSA-x22r-xgr5-23hh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x22r-xgr5-23hh", + "modified": "2024-10-04T21:31:29Z", + "published": "2024-10-04T21:31:29Z", + "aliases": [ + "CVE-2024-43683" + ], + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP Headers.This issue affects TimeProvider 4100: from 1.0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43683" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + }, + { + "type": "WEB", + "url": "https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T20:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xr9g-f9v2-9m3h/GHSA-xr9g-f9v2-9m3h.json b/advisories/unreviewed/2024/10/GHSA-xr9g-f9v2-9m3h/GHSA-xr9g-f9v2-9m3h.json new file mode 100644 index 00000000000..c3d93466f5e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xr9g-f9v2-9m3h/GHSA-xr9g-f9v2-9m3h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr9g-f9v2-9m3h", + "modified": "2024-10-04T21:31:29Z", + "published": "2024-10-04T21:31:29Z", + "aliases": [ + "CVE-2024-43684" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43684" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + }, + { + "type": "WEB", + "url": "https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-04T20:15:06Z" + } +} \ No newline at end of file